Service · Cybersecurity

SOC monitoring

The gap between an attacker getting in and somebody noticing is rarely measured in hours. More often the discovery comes from a client, a bank or a ransom note, several weeks later. Monitoring exists precisely to shorten that gap: gather the logs in one place, write detection scenarios that match what your business actually does, and settle in advance who does what when the alert lands at six on a Sunday morning.

Logs
gathered in a single place
Scenarios
written around your business
Retention
agreed with you at the outset
Response times
written into the agreement

Where this service reaches

Monitoring is judged on three things: what it can see, what it knows how to recognise, and what happens after the alert. A platform missing the third produces mostly statistics.

Put your scope to an engineer

Log sources

Firewall, servers, directory, mail, endpoints, remote access and exposed applications. We start with the sources that tell the story of an intrusion, not with the ones that are easiest to connect.

Retention

A period chosen with you against cost and against your obligations. Intrusions often surface after several weeks, so seven days of retention makes reconstruction impossible.

Detection scenarios

A successful sign-in from two countries ten minutes apart, an administrator account created outside the process, a protection switched off, an unusual extract from a database, a forwarding rule added to a director's mailbox.

Cutting the noise

The first weeks are spent removing things that look like an attack without being one, a nightly backup or an inventory tool. An alert that keeps firing with no consequence ends up ignored, including on the day it is real.

Response

Isolating a machine, disabling an account, killing a session, then tracing the origin and the traces left elsewhere. Which actions we may take without calling you first is agreed beforehand and written down.

After the incident

A factual account, the material you need for a report to the competent authorities, and a list of corrections so that the same route does not serve again three months later.

The way an engagement runs

Commissioning proceeds one source at a time, because connecting thirty at once produces a volume nobody manages to sort out afterwards.

01

Scoping

What genuinely matters to you, the scenarios you fear most and the response times expected under the plan you choose.

02

Connection

The first sources wired in, timestamps verified and a check that no feed can stop without somebody being told.

03

Tuning

Scenarios written and adjusted week by week, until every alert is worth opening.

04

Operation

Monitoring under the agreement, response to incidents, periodic rule reviews and new sources added as your systems change.

The first instinct after an attack is often the worst one. Rebooting the servers, reimaging the machines, clearing the traces: what gets destroyed is exactly what would have shown how the attacker got in, and therefore how to stop them coming back the same way a fortnight later. The first line of our procedure is to isolate without erasing.

Questions and answers

Not always. On a modest estate, an EDR driven from a central console with well-tuned alerts already covers a great deal of ground. Full monitoring becomes interesting when an hour of downtime is expensive, when your clients or your sector impose response times, or when the data you hold is particularly sensitive.

EDR only sees the machines it is installed on. Monitoring also gathers the firewall, the directory, mail and applications, which lets events be joined up that trigger nothing on their own: a foreign sign-in, then a forwarding rule, then a change of bank details.

The logs stay in European regions, inside your own subscription where the solution allows it. They contain personal data, account names and addresses, so they belong in the record of processing with a retention period set. We supply the technical description your DPO needs.

Notification is yours to make: to the CNIL for a personal data breach, and under NIS2 if your entity is in scope. We provide the factual material, timeline, what was affected, technical evidence, and we stay available for questions from CERT-FR. The decision and the responsibility to report remain with you.

Yes, and that is what we recommend. Three or four well-chosen sources, the directory, mail and the firewall, already catch the most frequent scenarios. Further sources are added afterwards, at the pace you are genuinely able to act on them.

See attacks while they are still happening

Describe your environment and the scenarios that worry you most. We will propose the first sources to connect and a suitable plan.

When we are around
Weekdays, 8:00 to 18:00 CET; answers land inside one working day
Talking it through
A call on Teams or Google Meet, whenever writing is not enough

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.