Each profile is mobilized on a precise scope of your security operations, with its own level of responsibility and autonomy.
The monitoring chain is organized across three levels, each with a distinct role in handling alerts.
Receiving and first-pass sorting of alerts, filtering out obvious false positives, escalating uncertain cases to N2.
In-depth analysis of escalated alerts, correlation across sources, deciding whether to qualify as an incident and escalating to N3 when needed.
Proactive hunting for threats not caught by existing rules, tuning detection rules, handling the most complex incidents.
They design and maintain the detection capability day to day.
They assess the organizational and technical security posture of a given scope.
They run penetration tests to identify exploitable vulnerabilities.
They support the structuring of security governance and regulatory compliance.
They secure public and hybrid cloud environments end to end.