← Managed SOCSIEM

Managed SIEM

MICROSOFT SENTINEL · ELASTIC · CROWDSTRIKE

Managed SIEM is our platform scope: log source onboarding, parsing and normalisation, detection engineering, rule lifecycle, retention tiering and platform operations. Example stacks are Elastic Security, Microsoft Sentinel or CrowdStrike.

What sets this service apart: the detection pipeline itself is part of the deliverable. We build and maintain use cases and playbooks, keep MITRE ATT&CK coverage traceable and report data gaps openly.

Typical detections

  • Cross-source correlation rules, prioritised against MITRE ATT&CK gaps
  • Tampering with, disabling or truncating audit logs
  • Silent log sources and ingest failures as a detection of their own
  • Suspicious admin activity on systems without an EDR agent
  • Access to regulated data and other compliance-relevant events
  • Anomalies in legacy and line-of-business applications without standard telemetry

Response actions within mandate

  • SIEM is the detection and evidence layer: the actual action runs through connected tools (EDR, identity, firewall) per mandate
  • Immediate deployment of new detections and parser fixes during a live incident
  • Evidence package with timeline and raw logs for IR, insurers and regulators
  • Query and hunting support for your IT team or an external IR partner

Limits of this service

  • Without connected response tools, SIEM stays detection without action, that needs Managed EDR or Managed IDR
  • Detection quality is capped by data quality, missing sources are reported as gaps
  • No substitute for behavioural visibility at segment level, that is Managed NDR

SLAs

< 5 business days
New log source onboarding
< 48 hours
New detection deployment
< 60 min (24/7)
Critical incident response time (contractual)

Included

  • Use case and playbook development and management: use cases, correlation rules and playbooks are built, versioned and tuned
  • Log source integration and management: onboarding, parsing, normalisation, retention tiering and ingest monitoring
  • Detection coverage management against MITRE ATT&CK including a prioritised gap backlog

Not included

  • Platform and agent licences (yours, or passed through at cost)
  • Anti-ransomware (e.g. Halcyon) as a separate add-on module
  • Eradication and recovery inside your systems, executed by your IT with our coordination
  • On-prem hardware, collectors and network taps

Process

  1. Assess

    Log source inventory, coverage gap analysis against MITRE ATT&CK, platform and retention health check.

  2. Integrate

    Priority-based log onboarding with out-of-the-box integrations and custom parsers, baseline detections live within the onboarding phase.

  3. Automate

    Playbook per detection, SOAR enrichment and automated queries, response actions pre-authorised in the mandate matrix.

Deliverables

  • Use case and playbook catalogue with documented analysis steps
  • Log source inventory with retention and data quality status
  • MITRE ATT&CK coverage board with a prioritised detection backlog

FAQ

Can we keep our existing SIEM?

Yes, we are vendor-agnostic and work on your platform. If none exists yet, we propose one based on log volume, retention needs and budget, for example Elastic Security hosted in Switzerland.

What happens to our existing rules?

We inventory them, measure hit quality and keep what works. Rules with no signal or a chronic false positive rate get tuned or replaced, documented in the detection backlog.

Included in every ANOMAL managed service

  • 24/7 threat monitoring: every alert is picked up, enriched with context and documented in the ticket system
  • Incident triage on every severity from low to critical, classified as false positive, benign true positive or true positive
  • Further analysis on every suspected true positive, including log, telemetry and asset context
  • Incident response along NIST: containment and first response within your mandate. A full IR engagement for a major incident is billed separately.
  • SOC platform operations: backend, updates and health monitoring of the SOC stack
  • Automated incident response: SOAR enrichment, automated queries, pre-authorised response actions per mandate
  • Threat hunting and threat intelligence (e.g. MISP plus external feeds) feeding back into detections
  • Effectiveness testing once a year, e.g. together with an external purple team
  • Service management: monthly service efficiency report, quarterly optimisation meeting, live view in ANOVIEW
  • Ongoing operations: continuous tuning, detection maintenance and quarterly service optimisation

Scope, service level (e.g. business hours for low to high, 24/7 for critical) and volumes differ per environment. That is why there is no list price: every customer gets a dedicated quote with defined scope, service level and response mandate. With Managed SIEM and Managed NDR the scope additionally covers use case and playbook development as well as log source integration and management.

Let's talk about Managed SIEM.

30 minutes with our SOC team. You describe your situation, we tell you clearly whether and how we can help.