Detection engineering and SOC support
Hunting finds the gap once. Detection engineering makes sure you never have to find it again.
Turning hunts into permanent coverage
Every hunt that finds something is a detection waiting to be written. Every hunt that finds nothing is still a query worth keeping. The work here is converting one-off investigation into durable coverage your team runs without me.
Where I help
Coverage mapping
Your current detections plotted against MITRE ATT&CK, so gaps are visible and prioritisation is an evidence-based conversation rather than a guess.
Rule development and tuning
New detections written for your estate, and existing ones tuned down where they are generating noise nobody reads any more.
Log source onboarding
Getting the telemetry that matters into the platform, parsed correctly and actually usable in a query — which is frequently where the real gap turns out to be.
Alert triage improvement
Reducing the volume your analysts wade through so the alerts that survive are the ones worth their attention.
Incident-driven improvement
Investigation support during and after an incident: adversary behaviour analysis, scoping what was actually touched, and the detection work that stops a repeat. Not a retained IR service — specialist help alongside the team already handling it.
SOC readiness
For organisations standing up monitoring for the first time: what to collect, what to detect first, and what a realistic first year looks like.
A note on honesty
Plenty of organisations are sold a SOC when what they need is three log sources onboarded properly and a dozen good detections. If that is your situation, I will tell you, and the engagement will be smaller than you expected.
Start with a conversation, not a proposal
Tell me what you are running and what is worrying you. If I am not the right fit I will say so, and point you at what is.