Grey Fox SOC
Managed detection and response. Security telemetry is only useful if someone is reading it. Grey Fox SOC collects the signals that matter from your endpoints, identity provider, network and cloud, and turns them into triaged alerts with a clear next action.
Services
Log collection & SIEM
Onboarding of endpoints, servers, firewalls, Microsoft 365 and cloud audit logs into a managed SIEM.
Detection engineering
Rules mapped to MITRE ATT&CK and tuned to your environment, so alerts mean something.
Alert triage
Human-reviewed, AI-assisted triage that separates real incidents from background noise.
Response playbooks
Agreed actions for common incidents: isolate a host, disable an account, block an indicator.
Threat hunting
Scheduled hunts for activity that rules do not catch.
Monthly reporting
What was seen, what was done, and what should change.
Before you ask
Is this a 24/7 service?
Coverage hours are agreed per client and stated in the contract. We will not describe a service as 24/7 unless it is staffed that way.
Which tools do you use?
We prefer open, well-understood platforms and will work with a tool you already own where it is fit for purpose.
Ready when you are
Email us the outcome you need. We will tell you honestly whether we are the right fit.