SecurePeakService data sheet · 04 of 05
Defensive operations · SP-SVC-04

Detection Engineering & DFIR Readiness

Detection trained on your telemetry rather than a 1998 benchmark, delivered as code under version control, with a forensics and incident-response team that has handled the intrusions the rules are written for.

Duration
12 weeks + retained
Team
2 named + DFIR lead
From
€72,000
Containment plan
4 hours
How it runs
01
Telemetry baseline — ingest audit across EDR, auth, cloud and network; gaps against ATT&CK data sources; NMF behavioural baselines fitted.
02
Detection engineering — transformer sequence models and sketch-based streaming thresholds at 10⁹+ events/day; Sigma and vendor-native rules under CI.
03
Validation — coverage measured against red-team emulation, not a public dataset; false-positive budget agreed and enforced.
04
DFIR readiness — acquisition playbooks, chain-of-custody procedures, tabletop exercise, and a retained response agreement.
What you get
  • ATT&CK coverage map measured against live emulation
  • Detection-as-code repository with tests and deployment pipeline
  • Behavioural baseline models retrained on your traffic
  • DFIR playbooks and evidence-handling procedures your counsel will accept
  • Retained incident response with a 4-hour containment-plan commitment
Methodology
MITRE ATT&CK v17 · D3FEND
Sigma · OTLP · Zeek
NIST SP 800-61r3
ISO/IEC 27037 evidence handling
Typical scope
SIEM / data lake, EDR, identity and cloud audit logs, network sensors, OT-adjacent telemetry, SOC processes and escalation paths.
Not included
24×7 monitoring as a managed SOC (separate agreement). Replacement of your SIEM or EDR. Legal representation during an incident.
Each is a separate engagement — they need separate authorisation.
A time-boxed assessment establishes what was found within the agreed scope and window. It does not certify the absence of vulnerabilities, and we will never say that it does.
securepeak.com
engagements@securepeak.com