Detection & Response Validation
Is an attack detected and followed up?
We carry out agreed attack activities and compare them with logging, alerts and follow-up. This shows where your detection and response work and where improvements are needed.
From activity to follow-up
Three questions we answer
- Which activities are logged?
- Which signals lead to investigation and escalation?
- Which steps are missing between detection and response?
When is this relevant?
An alert becomes useful when someone acts on it properly.
Your security products and security team process signals from the environment. Using targeted scenarios, we test which activities are detected, who assesses the alerts and what happens next.
- You have configured new detection rules, log sources or security products.
- You want to test arrangements with your internal or external SOC in practice.
- An incident has raised questions about detection or escalation.
- You want to demonstrate the improvements delivered by a change.
The assessment
What do we assess?
Your environment and assessment question determine the content. We agree in advance which elements we will examine.
01
Scenarios and expectations
We choose activities that fit your risks and environment. We document in advance the logging, detection and follow-up you expect for them.
02
Execution and evidence
We carry out the agreed activities in a controlled way and record the time and outcome. That timeline forms the basis for comparison with signals from your security environment.
03
Detection and assessment
Together with the administrators or SOC involved, we assess which log entries, alerts and investigations resulted. We distinguish between missing logging, missing detection and signals that received no follow-up.
04
Escalation and response
We examine how signals reach the right people and what they do with them. We consider context, handover and the agreed next steps.
Defining the scope together
A scope that fits your question.
This validation requires arrangements for scenarios, access to evidence and the teams involved. We determine who knows in advance and which follow-up actions will actually be carried out.
What do we agree in advance?
- Systems, scenarios and expected detection for each activity.
- Testing period, teams' prior knowledge and contacts.
- Available logging, alerts and timestamps from the SOC or administrators.
- Permitted response actions, evaluation and outcome criteria.
If we do not have access to internal logs, your administrators or SOC provide the evidence. Without that information, we cannot give a full assessment of what was observed internally.
The result
Insight you can act on.
01
A shared timeline
The activities carried out alongside the available log entries, alerts and follow-up.
02
Insight for each scenario
What was logged, detected, investigated and escalated, with the limitations of the available evidence.
03
Targeted improvements
Advice on logging, detection rules, alert assessment, communication and any follow-up test.
Our approach
From the initial question to follow-up.
01
Defining objectives
We choose scenarios and agree on what you want to test.
02
Carrying out activities
We work in a controlled way and record a clear timeline.
03
Comparing evidence
Together with the teams involved, we compare the activities, alerts and follow-up.
04
Validating improvements
We discuss measures and can retest modified elements.
Frequently asked questions
What you need to know in advance.
Does the SOC need to know about the test in advance?
We decide that together. An announced exercise may be appropriate for technical coordination. Assessing day-to-day follow-up may require different arrangements about prior knowledge.
Does this also provide permanent monitoring?
This service is a defined validation assessment. Ongoing monitoring and incident response have their own services and arrangements.
What if no alert appears?
We examine where the chain stops: logging, detection, assessment or follow-up. For this, we need evidence from the environment as well as our own timeline.
Does a successful test prove that all attacks are detected?
The result applies to the scenarios carried out, the configuration tested and the agreed period. It helps target improvements and does not assess every possible attack.
Our approach
From assessment to clear next steps.
Read how we define the scope, carry out the assessment and discuss the results with you. With a dedicated secure data room and evidence-based reporting.
Discuss your situation
Test what happens after an attack signal.
Discuss your environment and the scenarios you want clarity on. We make the desired outcome specific.