Home / Services / Protect

Grey Fox SOC

Managed detection and response. Security telemetry is only useful if someone is reading it. Grey Fox SOC collects the signals that matter from your endpoints, identity provider, network and cloud, and turns them into triaged alerts with a clear next action.

What we do

Services

Log collection & SIEM

Onboarding of endpoints, servers, firewalls, Microsoft 365 and cloud audit logs into a managed SIEM.

Detection engineering

Rules mapped to MITRE ATT&CK and tuned to your environment, so alerts mean something.

Alert triage

Human-reviewed, AI-assisted triage that separates real incidents from background noise.

Response playbooks

Agreed actions for common incidents: isolate a host, disable an account, block an indicator.

Threat hunting

Scheduled hunts for activity that rules do not catch.

Monthly reporting

What was seen, what was done, and what should change.

Questions

Before you ask

Is this a 24/7 service?

Coverage hours are agreed per client and stated in the contract. We will not describe a service as 24/7 unless it is staffed that way.

Which tools do you use?

We prefer open, well-understood platforms and will work with a tool you already own where it is fit for purpose.

Ready when you are

Email us the outcome you need. We will tell you honestly whether we are the right fit.