Managed Detection Engineering
A detection engineer on tap, billed by the day. You send the gap — a log source nobody has parsed, a technique a customer asked about after reading the news, an alert that fires every night at 02:00 and is never real — and it comes back as reviewed rules, parsers and dashboards that belong to you.
$517.50USDengineer days / month
List $690 — what your customer pays. You keep the difference. · 25% off list
- Priced by
- engineer days / month
- Delivered as
- Your brand, your template
- Client access
- Scoped, granted by your customer
- Runs on
- zcrSIEM
Scoped before you quote, not after you have sold it
Rules are authored as Sigma wherever the technique allows it, then compiled to the backend you run, so the detection logic outlives any one platform.
Parsers and field mappings are normalised to ECS, so a rule written once matches on every customer you onboard afterwards.
Everything ships as code into your repository with a change note — you can read the diff, review it, and roll it back.
New detections are mapped to MITRE ATT&CK techniques, so your coverage is a list you can show a customer instead of a claim you have to make.
Detections are tested against replayed log data before release, with the expected false-positive profile written down next to the rule.
Tuning is part of the work, not an extra: a noisy rule gets fixed at the source rather than muted and forgotten.
You quote it, we operate it, you deliver it
Your price is the published list price minus 25%, on every line in the catalogue. You decide what your customer pays and keep the difference, so your margin is settled before the quotation leaves your office.
Our engineers work it from Bangkok on UTC+7, against a methodology that is written down rather than improvised per customer. A senior engineer reads every finding before it leaves the building, because you are the one who has to defend it.
Findings, reports and escalations reach you in your template with your logo on them. Your customer talks to you, and our name is not on the ticket.
What a partner checks before putting this on their price list
Which platform do you write for?
zcrSIEM and Elastic are the backends we work in every day, and Sigma is the source format, so a rule can be compiled for any backend that accepts it. If you run something else, ask before you commit days and we will tell you honestly whether it is a good use of them.
Who owns the rules you write?
You do — the rules are delivered as code into your repository and stay yours if the engagement stops. There is no rule library you lose access to when you leave.
What is an engineer day?
A day of a detection engineer working on scope you set. A typical unit of work is one new log source parsed with its first detections written, or a tuning pass across a rule set that has become noisy.
Can we send you a specific threat and get a rule back?
Yes — a technique, an IOC set, a customer question or somebody else's incident write-up all work as input, and the output is a tested rule with its false-positive profile documented.
What happens to unused days?
Days are booked by month and do not roll forward, because the engineer's time was reserved for you. Tell us early in the month if your queue is empty and we will schedule tuning or coverage work against your existing rule set instead.
Do you need access to our customers' data?
We work at the rule layer of your platform, and where a detection has to be tested we use replayed or sanitised samples that you provide. There is no direct contact with your end customer at any point.
Pick one customer. We will run it for 60 days.
Choose a customer you already serve. We deliver Managed Exposure on their domain for two months, in your template, at no cost — so you can see exactly what your customer would receive before you sign anything.
Apply as a partner