Log sources
Firewall, servers, directory, mail, endpoints, remote access and exposed applications. We start with the sources that tell the story of an intrusion, not with the ones that are easiest to connect.
The gap between an attacker getting in and somebody noticing is rarely measured in hours. More often the discovery comes from a client, a bank or a ransom note, several weeks later. Monitoring exists precisely to shorten that gap: gather the logs in one place, write detection scenarios that match what your business actually does, and settle in advance who does what when the alert lands at six on a Sunday morning.
Monitoring is judged on three things: what it can see, what it knows how to recognise, and what happens after the alert. A platform missing the third produces mostly statistics.
Firewall, servers, directory, mail, endpoints, remote access and exposed applications. We start with the sources that tell the story of an intrusion, not with the ones that are easiest to connect.
A period chosen with you against cost and against your obligations. Intrusions often surface after several weeks, so seven days of retention makes reconstruction impossible.
A successful sign-in from two countries ten minutes apart, an administrator account created outside the process, a protection switched off, an unusual extract from a database, a forwarding rule added to a director's mailbox.
The first weeks are spent removing things that look like an attack without being one, a nightly backup or an inventory tool. An alert that keeps firing with no consequence ends up ignored, including on the day it is real.
Isolating a machine, disabling an account, killing a session, then tracing the origin and the traces left elsewhere. Which actions we may take without calling you first is agreed beforehand and written down.
A factual account, the material you need for a report to the competent authorities, and a list of corrections so that the same route does not serve again three months later.
Commissioning proceeds one source at a time, because connecting thirty at once produces a volume nobody manages to sort out afterwards.
What genuinely matters to you, the scenarios you fear most and the response times expected under the plan you choose.
The first sources wired in, timestamps verified and a check that no feed can stop without somebody being told.
Scenarios written and adjusted week by week, until every alert is worth opening.
Monitoring under the agreement, response to incidents, periodic rule reviews and new sources added as your systems change.
The first instinct after an attack is often the worst one. Rebooting the servers, reimaging the machines, clearing the traces: what gets destroyed is exactly what would have shown how the attacker got in, and therefore how to stop them coming back the same way a fortnight later. The first line of our procedure is to isolate without erasing.
Not always. On a modest estate, an EDR driven from a central console with well-tuned alerts already covers a great deal of ground. Full monitoring becomes interesting when an hour of downtime is expensive, when your clients or your sector impose response times, or when the data you hold is particularly sensitive.
EDR only sees the machines it is installed on. Monitoring also gathers the firewall, the directory, mail and applications, which lets events be joined up that trigger nothing on their own: a foreign sign-in, then a forwarding rule, then a change of bank details.
The logs stay in European regions, inside your own subscription where the solution allows it. They contain personal data, account names and addresses, so they belong in the record of processing with a retention period set. We supply the technical description your DPO needs.
Notification is yours to make: to the CNIL for a personal data breach, and under NIS2 if your entity is in scope. We provide the factual material, timeline, what was affected, technical evidence, and we stay available for questions from CERT-FR. The decision and the responsibility to report remain with you.
Yes, and that is what we recommend. Three or four well-chosen sources, the directory, mail and the firewall, already catch the most frequent scenarios. Further sources are added afterwards, at the pace you are genuinely able to act on them.
Describe your environment and the scenarios that worry you most. We will propose the first sources to connect and a suitable plan.
Message received
An answer follows inside one working day. Report an outage that is stopping people working and it moves ahead of everything else.
Nothing here under that name. Check the spelling, or simply choose the nearest large city instead. Since every engagement runs remotely, whichever you pick changes nothing about what we do for you.