SOC · SIEM & XDR · Detection engineering · Penetration testing
Cybersecurity & Security Operations Centre (SOC)
We build and run Security Operations Centres (SOC). Telemetry from endpoints, identities, networks, cloud and OT flows into a SIEM, is normalised, and runs through detections we write, test and map to MITRE ATT&CK. When one fires, a playbook enriches the alert and contains the threat through your EDR, identity provider and firewall APIs, with an analyst approving every action that affects the business.
Because we also engineer software, cloud platforms, ERP systems and connected devices, we secure them from the inside: threat models before design, static analysis, dependency and container scanning in the pipeline, hardened infrastructure as code, secure boot and signed firmware on devices, and penetration tests that prove the controls hold.
- SOC design, build and operation: in-house, managed or hybrid, with L1–L3 analyst tiers, runbooks and severity-based service levels
- SIEM and XDR engineering on Microsoft Sentinel, Splunk, Elastic or Wazuh: log onboarding, parsers and normalisation to ECS or OCSF
- Detection as code: Sigma, KQL and SPL rules in Git, tested in CI and proven with Atomic Red Team, mapped to MITRE ATT&CK
- SOAR playbooks that isolate hosts, revoke sessions and tokens and block indicators through EDR, identity and firewall APIs
- Threat hunting and threat intelligence: hypothesis-driven hunts, MISP and OpenCTI feeds, indicator sweeps across the fleet
- Incident response and forensics: triage, memory and disk acquisition with Velociraptor, root cause, eradication and recovery
- Penetration testing of web and mobile apps (OWASP WSTG, MASVS), APIs, Active Directory, networks and cloud tenants
- Vulnerability management ranked by CISA KEV, EPSS and exposure, with remediation deadlines and rescans that prove each fix
- Identity and zero trust: phishing-resistant MFA (FIDO2), conditional access, privileged access management and AD tiering
- Cloud and DevSecOps: CIS benchmarks, posture management, SAST, SCA, container and IaC scanning, secrets and SBOMs
- OT and embedded: IEC 62443 zones and conduits, passive Modbus, S7 and OPC UA monitoring, secure boot and signed firmware
- Preparing your organisation for its ISO/IEC 27001, NIS2, IEC 62443 or SOC 2 audit and GDPR: gap analysis, policies, evidence and awareness training
Interactive previews of systems we build where Cybersecurity plays a central role. Use them — every button works.
Choose a system — its live preview opens below
Cybersecurity · SOC · SIEM & SOAR
Copy linkSecurity operations centre console
The console a SOC analyst works in: alerts from the SIEM ranked by severity, every event of the intrusion mapped to MITRE ATT&CK, and a SOAR playbook that contains the threat through EDR, identity and firewall APIs once the analyst approves. Detection coverage and vulnerability exposure sit in the same tool.
- Alert queue, investigation timeline and entities enriched with threat intelligence
- SOAR playbooks with analyst approval before host isolation or account changes
- ATT&CK coverage map validated by purple-team simulations
- Vulnerability ranking by CISA KEV, EPSS and exposure, tracked to a verified fix
Try it: Watch the phishing alert stream in and approve the containment when the playbook asks. Then open the identity or OT alert, run a purple-team test or rank vulnerabilities by risk instead of CVSS.
Interactive preview with illustrative data. Client names and branding are omitted.
Five phases, each ending in something you can inspect: an inventory, a data pipeline, a rule repository, playbooks and a monthly report.
- 01
Assess
Threat model of the systems, identities and data an attacker would target. We inventory assets and log sources, map existing controls to MITRE ATT&CK and rank the coverage gaps by risk.
- Asset and identity inventory
- ATT&CK threat model
- Log-source gap analysis
- 02
Onboard
Sysmon and Windows event forwarding, Linux auditd, EDR, Entra ID and Active Directory, Microsoft 365, firewall, proxy, DNS, VPN, cloud audit trails and OT sensors flow into the SIEM, parsed, normalised to ECS or OCSF, time-synchronised and retained per your legal obligations.
- Parsers and normalisation
- Alerts for silent sources
- Hot and cold retention
- 03
Detect
Sigma, KQL or SPL rules in Git, peer-reviewed, unit-tested against recorded logs and validated with Atomic Red Team before they go live. Each rule carries its technique ID, severity, false-positive notes and a runbook.
- Rule repository with CI
- ATT&CK coverage map
- Purple-team report
- 04
Respond
SOAR playbooks enrich alerts with asset owner, user risk and threat intelligence, then contain through EDR, identity-provider and firewall APIs. Destructive actions wait for approval; tabletop exercises test the plan with management.
- SOAR playbooks
- Response runbooks and RACI
- Tabletop exercise
- 05
Operate
L1 triage, L2 investigation and L3 hunting and forensics against agreed service levels, weekly threat hunts, monthly tuning of noisy rules and reporting on time to detect, time to contain, true-positive rate and coverage.
- Service levels per severity
- Monthly KPI report
- Continuous tuning
Each telemetry source is onboarded for the attacks it can reveal. Rules are code: reviewed, tested against recorded logs and proven by simulating the technique.
Endpoint telemetry (EDR, Sysmon)
Malicious scripts and macros, LSASS credential dumping, process injection, ransomware encryption behaviour
- T1059
- T1003.001
- T1055
- T1486
Identity provider (Entra ID, Active Directory)
Password spraying, MFA fatigue, impossible travel, Kerberoasting, new privileged role assignments
- T1110.003
- T1621
- T1558.003
- T1098
Network metadata (DNS, proxy, Zeek)
Command-and-control beaconing, algorithm-generated domains, DNS tunnelling, large uploads to new destinations
- T1071
- T1568.002
- T1567
Microsoft 365 and SaaS audit logs
Malicious inbox rules, OAuth consent phishing, mass downloads from SharePoint and OneDrive
- T1564.008
- T1528
- T1530
Cloud audit trails (CloudTrail, Azure Activity)
Use of leaked access keys, logging switched off, storage made public, crypto-mining instances
- T1078.004
- T1562.008
- T1496
OT network sensors (Modbus, S7comm, OPC UA)
Unauthorised PLC writes and program downloads, unknown engineering stations, scans of the control network
- T0855
- T0843
- T0846
1title: Encoded PowerShell started by an Office application2id: 5c0b2a8e-7d41-4f3e-9b6a-1e2d3c4f5a603status: stable4description: Word, Excel or Outlook starting PowerShell with an5 encoded command, the usual first stage of a macro payload.6tags:7 - attack.execution8 - attack.t1059.0019 - attack.initial-access10 - attack.t1566.00111logsource:12 product: windows13 category: process_creation14detection:15 office_parent:16 ParentImage|endswith:17 - '\winword.exe'18 - '\excel.exe'19 - '\outlook.exe'20 powershell:21 Image|endswith:22 - '\powershell.exe'23 - '\pwsh.exe'24 encoded:25 CommandLine|contains|windash:26 - ' -e '27 - ' -ec '28 - ' -enc '29 condition: office_parent and powershell and encoded30falsepositives:31 - Signed add-ins, allow-listed by hash after review32level: high- sigma check · valid · 0 warnings
- convert · Sentinel KQL · Splunk SPL · Elastic ES|QL
- replay 14 days of process logs · 0 false positives
- atomic T1059.001 #3 · alert raised in 4.2 s
- 01 /
Coverage first
We start from a threat model of your critical systems, list the ATT&CK techniques that reach them and onboard the log sources that can see those techniques first. Coverage is measured per technique, not assumed from a licence.
- 02 /
Detections as code
Rules live in Git with a review, unit tests on recorded logs and a CI job that converts them for your SIEM. Each one carries its technique ID, severity, known false positives and the runbook an analyst follows.
- 03 /
Automated containment
Playbooks enrich each alert with asset owner, user risk and threat intelligence, then isolate the host, revoke tokens and push block rules through vendor APIs. Actions with business impact wait for an analyst's approval.
- 04 /
Proven by attack
Penetration tests follow OWASP WSTG and PTES; purple-team runs replay real attacker techniques on test hosts. Every finding comes with CVSS, proof of exploitation, a concrete fix and a retest.
- 05 /
From pipeline to PLC
We harden the chain we also build: signed build artefacts and SBOMs, containers and Kubernetes against CIS benchmarks, IT and OT segmentation per IEC 62443, secure boot and hardware-backed keys on devices.
- 06 /
Evidence, not slides
We map your controls to ISO/IEC 27001 Annex A, NIS2 Article 21 and IEC 62443 and collect the evidence your auditor asks for from the systems themselves: access reviews, log retention, patch deadlines and restore tests.
Technology
Tools we trust
We work with proven security platforms and current attack and defence techniques, and bring in specialist partners where a task calls for them. You keep one point of contact and one plan, from assessment to operation.
- Microsoft Sentinel
- Microsoft Defender XDR
- Splunk
- Elastic Security
- Wazuh
- CrowdStrike Falcon
- Sysmon
- osquery
- Suricata
- Zeek
- Security Onion
- Sigma
- YARA
- MISP
- OpenCTI
- TheHive
- Shuffle
- Velociraptor
- Atomic Red Team
- MITRE Caldera
- MITRE ATT&CK
- Burp Suite
- BloodHound
- Nmap
- Metasploit
- Nessus
- Prowler
- Trivy
- Semgrep
- Falco
- HashiCorp Vault
- Keycloak
- … and more
A selection of our tools and frameworks. We choose what fits your requirements, integrations and team.
Straight answers about how we work. Can't find yours? Ask us directly.
Can you build a SOC for us?
Yes. We deliver the operating model and escalation matrix, a SIEM and XDR platform sized for your events per second and retention, log onboarding with parsers, a detection library in Git mapped to MITRE ATT&CK, SOAR playbooks, a runbook per alert type and dashboards for time to detect, time to contain, true-positive rate and coverage. We then operate it as a managed SOC, run it with your team or hand it over with training.
In-house, managed or hybrid SOC — which fits us?
It depends on your risks, budget and team. Staffing one analyst seat around the clock takes five to six people once shifts, holidays and training are covered, which is the main cost of an in-house SOC. A managed SOC gives round-the-clock coverage fastest; in a hybrid model your team covers business hours and we cover nights, weekends and L3 escalations. In every model the SIEM, the rules and the data stay in your tenant.
Do you carry out penetration tests?
Yes. We test web and mobile apps (OWASP WSTG and MASVS), APIs (OWASP API Security Top 10), Active Directory (Kerberoasting, ADCS misconfigurations, delegation abuse), internal and external networks, cloud tenants (IAM, storage, exposed keys) and devices (debug interfaces, firmware extraction). Every test runs under a signed scope and rules of engagement; the report gives each finding with CVSS, proof, business impact and a concrete fix, and we retest after you fix them.
What should we do if we are under attack right now?
Contact us straight away and do not power off affected machines: memory holds evidence. We contain first by isolating hosts through your EDR or switch ports, revoking sessions and blocking indicators, then preserve memory and disk images, establish how the attacker got in and how long they were present, rebuild from known-good backups and help you meet notification deadlines such as the 72 hours under the GDPR and the 24-hour early warning under NIS2.
Can you help us prepare for ISO 27001 or NIS2?
Yes. We run a gap analysis against ISO/IEC 27001:2022 Annex A, the NIS2 Article 21 measures, IEC 62443 or SOC 2, then implement what is missing: risk assessment and register, Statement of Applicability, policies, access reviews, logging and retention, backup and restore tests, supplier security and response procedures. Evidence is collected from the systems themselves. We are not a certification body: your certificate is issued by an accredited certification body after its own audit, and we prepare you for it.
Do you secure industrial systems and connected devices?
Yes. Because we build embedded systems, robots and automation, we secure them too: IT and OT networks split into IEC 62443 zones and conduits, industrial protocols (Modbus/TCP, S7comm, OPC UA, PROFINET) monitored passively from SPAN ports so nothing is injected into the control network, hardened engineering workstations, and on devices secure boot, signed firmware updates and hardware-backed keys.
Cybersecurity
Ready to move from idea to a working system?
Tell us about your goals and constraints. We'll come back with a clear technical direction and next steps.
