SIEM & Monitoring
OTel, metrics, alerts, incident response.
Early detection
Forensic capability
Compliance
Scope of work
- Log pipelines & normalization
- Use cases/detections
- Dashboards/runbooks
- IR playbooks & exercises
Approach
- 1PlanData sources/use cases.
- 2BuildParse, correlate, alert.
- 3OperateTuning and threat hunting.