All penetration tests / Detection & Response Validation

Detection & Response Validation

Is an attack detected and followed up?

We carry out agreed attack activities and compare them with logging, alerts and follow-up. This shows where your detection and response work and where improvements are needed.

From activity to follow-up

Three questions we answer

  • Which activities are logged?
  • Which signals lead to investigation and escalation?
  • Which steps are missing between detection and response?

When is this relevant?

An alert becomes useful when someone acts on it properly.

Your security products and security team process signals from the environment. Using targeted scenarios, we test which activities are detected, who assesses the alerts and what happens next.

  • You have configured new detection rules, log sources or security products.
  • You want to test arrangements with your internal or external SOC in practice.
  • An incident has raised questions about detection or escalation.
  • You want to demonstrate the improvements delivered by a change.

The assessment

What do we assess?

Your environment and assessment question determine the content. We agree in advance which elements we will examine.

01

Scenarios and expectations

We choose activities that fit your risks and environment. We document in advance the logging, detection and follow-up you expect for them.

02

Execution and evidence

We carry out the agreed activities in a controlled way and record the time and outcome. That timeline forms the basis for comparison with signals from your security environment.

03

Detection and assessment

Together with the administrators or SOC involved, we assess which log entries, alerts and investigations resulted. We distinguish between missing logging, missing detection and signals that received no follow-up.

04

Escalation and response

We examine how signals reach the right people and what they do with them. We consider context, handover and the agreed next steps.

Defining the scope together

A scope that fits your question.

This validation requires arrangements for scenarios, access to evidence and the teams involved. We determine who knows in advance and which follow-up actions will actually be carried out.

What do we agree in advance?

  • Systems, scenarios and expected detection for each activity.
  • Testing period, teams' prior knowledge and contacts.
  • Available logging, alerts and timestamps from the SOC or administrators.
  • Permitted response actions, evaluation and outcome criteria.

If we do not have access to internal logs, your administrators or SOC provide the evidence. Without that information, we cannot give a full assessment of what was observed internally.

The result

Insight you can act on.

01

A shared timeline

The activities carried out alongside the available log entries, alerts and follow-up.

02

Insight for each scenario

What was logged, detected, investigated and escalated, with the limitations of the available evidence.

03

Targeted improvements

Advice on logging, detection rules, alert assessment, communication and any follow-up test.

Our approach

From the initial question to follow-up.

01

Defining objectives

We choose scenarios and agree on what you want to test.

02

Carrying out activities

We work in a controlled way and record a clear timeline.

03

Comparing evidence

Together with the teams involved, we compare the activities, alerts and follow-up.

04

Validating improvements

We discuss measures and can retest modified elements.

Frequently asked questions

What you need to know in advance.

Does the SOC need to know about the test in advance?

We decide that together. An announced exercise may be appropriate for technical coordination. Assessing day-to-day follow-up may require different arrangements about prior knowledge.

Does this also provide permanent monitoring?

This service is a defined validation assessment. Ongoing monitoring and incident response have their own services and arrangements.

What if no alert appears?

We examine where the chain stops: logging, detection, assessment or follow-up. For this, we need evidence from the environment as well as our own timeline.

Does a successful test prove that all attacks are detected?

The result applies to the scenarios carried out, the configuration tested and the agreed period. It helps target improvements and does not assess every possible attack.

Discuss your situation

Test what happens after an attack signal.

Discuss your environment and the scenarios you want clarity on. We make the desired outcome specific.