PUBLIC · securepeak.comAS216096 · L-717869-S
SecurePeak
Practice 04

Defensive Operations

Detection engineering trained and re-trained on your telemetry, not on NSL-KDD. Sub-5-minute alert latency at < 1% false positive rate, 95%+ ATT&CK technique coverage measured against emulation, and a DFIR team that has handled the intrusions the detections are written for.

Engagement parameters
IngestOTLP · Sysmon · Zeek · NetFlow · auth · cloud auditModelsNMF baselines · transformer sequence · CMS / HLL / t-digestThroughput10⁹+ events/day · < 5 min to alertDeliverablesDetection-as-code · Sigma rules · ATT&CK coverage map · IR report
Data sheet · A4 · SP-SVC-04Open PDF sheet
Baselines · SP-SVC-04.01

Matrix factorisation for behavioural baselines

Non-negative matrix factorisation with temporal decay over authentication and access logs. Lateral movement surfaces as a residual against the learned user–host matrix, without a labelled attack set.

Sequences · SP-SVC-04.02

Transformer sequence models on network telemetry

Self-attention over flow and process-event sequences captures multi-stage patterns: beaconing with jitter, staged exfiltration, credential use out of order. Trained on your traffic; evaluated against red-team ground truth, not a public benchmark.

Scale · SP-SVC-04.03

Sketch-based streaming inference

Count-Min Sketch for frequency, HyperLogLog for cardinality, t-digest for streaming percentiles. Adaptive thresholds at 10⁹+ events/day in bounded memory, so a burst does not become a backlog.

DFIR · SP-SVC-04.04

Digital forensics & incident response

Memory and disk acquisition, timeline reconstruction from EDR, cloud audit and network telemetry, malware analysis and implant reverse engineering. Containment plan within 4 hours of a confirmed critical; evidence handled to a chain of custody that survives regulator and counsel.

Hunting · SP-SVC-04.05

Hypothesis-driven threat hunting

Hunts derived from current CTI — identity-infrastructure abuse after the 2026 AD FS and SharePoint zero-days, living-off-the-land in OT networks — converted into detection-as-code with Sigma and vendor-native rules under version control.

Caution · SP-SVC-04.06

Dataset limitations, stated

NSL-KDD is derived from 1998 traffic. CICIDS-2017 contains invalid flow features. Papers reporting 99%+ accuracy on either should be read as benchmark artefacts. Adversarial ML attacks in the problem space (Pierazzi et al.) evade classifiers that look excellent on paper.

Operators · identities withheld
Named to clients under NDA at scoping
OP-03
Principal · vulnerability research
Name withheld · active CVD embargoes
Firmware
Browser
HSM
OP-07
Lead · detection engineering
Name withheld · client SOC placement
Streaming ML
Sigma
DFIR
OP-11
Senior · cryptographic engineering
Name withheld · government PKI programme
HSM ceremonies
PQC
Formal verification
OP-14
Network engineer · AS216096
Name withheld · NOC rotation
BGP
RPKI
Dark fibre
< 5 min
Detection to alert latency
< 1%
False positive rate
95%+
ATT&CK coverage
4h
Critical incident to containment plan
Operators · identities withheld
Named to clients under NDA at scoping
OP-03
Principal · vulnerability research
Name withheld · active CVD embargoes
Firmware
Browser
HSM
OP-07
Lead · detection engineering
Name withheld · client SOC placement
Streaming ML
Sigma
DFIR
OP-11
Senior · cryptographic engineering
Name withheld · government PKI programme
HSM ceremonies
PQC
Formal verification
OP-14
Network engineer · AS216096
Name withheld · NOC rotation
BGP
RPKI
Dark fibre
References

What this practice is currently working against.

Papers and public CVEs · updated Sep 2026
ReferenceFinding / paperSource
CVE-2026-56164SharePoint Server zero-day exploited in the wild; KEV deadline 17 Jul 2026Microsoft · Jul 2026
CVE-2026-32202Incomplete patch for CVE-2026-21510, weaponised by TA422 within days of disclosureMicrosoft · 2026
Pierazzi et al.Intriguing Properties of Adversarial ML Attacks in the Problem SpaceIEEE S&P / ACM TOPS · 2020/2024
Sommer & PaxsonOutside the Closed World: on using ML for network intrusion detectionIEEE S&P · 2010
Engelen et al.Troubleshooting an intrusion detection dataset: the CICIDS2017 case studyIEEE S&P Workshops · 2021
Next: Edge Infrastructure