Service data sheet · 04 of 05Defensive operations · SP-SVC-04
Detection Engineering & DFIR Readiness
Detection trained on your telemetry rather than a 1998 benchmark, delivered as code under version control, with a forensics and incident-response team that has handled the intrusions the rules are written for.
Duration
12 weeks + retained
How it runs
01
Telemetry baseline — ingest audit across EDR, auth, cloud and network; gaps against ATT&CK data sources; NMF behavioural baselines fitted.
02
Detection engineering — transformer sequence models and sketch-based streaming thresholds at 10⁹+ events/day; Sigma and vendor-native rules under CI.
03
Validation — coverage measured against red-team emulation, not a public dataset; false-positive budget agreed and enforced.
04
DFIR readiness — acquisition playbooks, chain-of-custody procedures, tabletop exercise, and a retained response agreement.
What you get
- ATT&CK coverage map measured against live emulation
- Detection-as-code repository with tests and deployment pipeline
- Behavioural baseline models retrained on your traffic
- DFIR playbooks and evidence-handling procedures your counsel will accept
- Retained incident response with a 4-hour containment-plan commitment
Methodology
MITRE ATT&CK v17 · D3FEND
Sigma · OTLP · Zeek
NIST SP 800-61r3
ISO/IEC 27037 evidence handling
Typical scope
SIEM / data lake, EDR, identity and cloud audit logs, network sensors, OT-adjacent telemetry, SOC processes and escalation paths.
Not included
24×7 monitoring as a managed SOC (separate agreement). Replacement of your SIEM or EDR. Legal representation during an incident.
Each is a separate engagement — they need separate authorisation.
A time-boxed assessment establishes what was found within the agreed scope and window. It does not certify the absence of vulnerabilities, and we will never say that it does.
securepeak.com
engagements@securepeak.com