Defend · Service 03

Detection & response

Monitoring is only useful if somebody acts on it. We watch endpoint, identity and cloud around the clock, and we have written authority to contain a threat at 2am without waiting for you to wake up.

Analysts monitoring security dashboards in an operations centre
The gap

An alert nobody triages is just a log entry

Most organisations we assess already generate detections. Defender is licensed, the EDR console is populated, the sign-in logs are there. What is missing is the person who looks at an impossible-travel alert at 11pm on a Saturday and decides whether it is a VPN or an intrusion.

The industry average for dwell time — how long an intruder is inside before anyone notices — is still measured in days. Almost all of that is triage latency, not detection failure.

We close that gap with people, on a roster, with delegated authority and a documented playbook. Not an email alert forwarded to your operations manager.

Telemetry

What we watch, and what we are watching for

Four signal sources, correlated. An event that looks unremarkable on its own often is not once you can see the other three.

Identity
Entra ID sign-in and audit logs. Impossible travel, unfamiliar sign-in properties, MFA fatigue patterns, token replay indicators, new OAuth application consent, privileged role assignment, and mailbox rule creation — still the clearest early signal of business email compromise.
Endpoint
EDR telemetry across workstations and servers: credential access attempts, suspicious parent-child process chains, script interpreter abuse, defence evasion, persistence mechanisms and ransomware pre-cursors such as shadow copy deletion.
Cloud & SaaS
Microsoft 365 and Azure activity: mass file download or deletion, sharing-link anomalies, conditional access policy changes, tenant configuration drift, and administrative actions performed outside change windows.
Network & perimeter
Firewall and VPN logs, command-and-control indicators, exposed service changes, and alerting on the external attack surface when something appears that was not there last week.
When it happens

Six stages, in this order, every time

The sequence is not negotiable. You cannot eradicate before you contain, and you cannot notify before you know what left the building.

  1. Detect

    An alert fires, or a user reports something. Both routes reach the same queue, and a user report is treated with the same urgency as a machine detection.

  2. Triage

    A human establishes whether it is real within the response target. False positives are tuned out permanently rather than dismissed nightly.

  3. Contain

    Under pre-agreed authority: isolate the device, revoke the sessions, disable the account, block the sender. We act first and inform you immediately — the alternative costs hours you do not have.

  4. Investigate

    Initial access, scope, dwell time, lateral movement and data accessed. This is the stage that determines whether you have a notification obligation.

  5. Eradicate & recover

    Remove persistence, rotate credentials, rebuild rather than clean where there is any doubt, restore from verified backup, and confirm the environment is clean before returning it to service.

  6. Report

    A written incident record: timeline, root cause, what we did, what you must decide, OAIC notifiability assessment, and the control changes that stop it recurring.

Containment authority is agreed in writing during onboarding, including which systems we may isolate without consultation and who we escalate to when we may not.

Honest limits

What MDR does not do

Detection and response is a safety net. It is not a substitute for the controls that stop the incident happening.

  • It does not replace the Essential Eight. We will not sell you MDR while your patching is twelve months behind — that is treating the symptom.
  • It cannot see what it is not fed. Unmanaged devices and unmonitored SaaS are blind spots, and we will tell you exactly where yours are.
  • It does not eliminate downtime. Containing ransomware quickly means fewer machines encrypted, not zero.
  • It is not legal or insurance advice. We provide the technical facts your lawyers and insurer need, and we work alongside them.
Questions

What people ask

Is this a real 24/7 service or an on-call phone?

Rostered coverage with defined escalation, backed by the response targets in your agreement and reported against monthly. If a provider will not put a P1 response target in writing, that tells you what their after-hours arrangement actually is.

Do you use our existing tools or your own?

Yours where they are adequate — most organisations with Microsoft 365 Business Premium or E5 already have the telemetry. We add what is genuinely missing rather than replacing a working stack so it fits our preferred console.

What if you isolate a machine we needed?

It happens, and it is the right trade. Isolation is reversible in minutes; a domain controller encrypted while somebody sought approval is not. The systems where we must consult first — a production line, a clinical system — are named in your containment authority during onboarding.

Where is our data stored?

Onshore in Australia. Telemetry retention periods are stated in the agreement, and we will tell you which components of the platform process data offshore so you can assess it against your own obligations.

Already in an incident

Call us. We take incident response engagements for organisations who are not clients, and the first conversation costs nothing.