What It Delivers
Capability Audit
The engagement begins by assessing not the tools, but the team's ability to use them. Defender for Endpoint alert coverage, Sentinel analytic rule quality, Defender for Office 365 review process, identity protection response time — each assessed against what the tool is capable of versus what is actually happening. The gap is almost always process, not technology.
Alert Tuning and Tiered Triage
High-fidelity alerts separated from noise. A tiered triage model deployed so analysts know which alerts require immediate response, which require investigation, and which are informational. The "200 alerts per day with no triage process" configuration — which produces analyst burnout and missed detections equally — replaced with something workable.
Detection Engineering
Custom detection rules built against the specific attack techniques relevant to your environment — not the vendor's default rules covering all industries, but rules tuned to your crown jewels, your identity topology, and the kill chain your Diagnostic identified. Rules are tested against real activity before deployment to verify they fire without drowning the queue.
Threat Hunting Playbooks
Structured hunt hypotheses and execution playbooks for the techniques most likely to succeed against your environment. Analysts stop waiting for alerts and start looking for evidence of compromise that has not yet triggered one. The hunt is repeatable and scheduled, not ad-hoc and occasional.
Continuous Improvement Loop
Every alert, every hunt, and every incident feeds a tuning cycle. Detection misses produce new rules. False positives are suppressed with scope, not silence. The SIEM improves over time rather than drifting toward irrelevance as the environment changes around it.
Scope and Prerequisites
| Duration | 45–90 days |
| Environment | Microsoft Defender stack and/or Sentinel |
| Prerequisites | PULSAR deployed for audit log intelligence; initial kill chain from Module 0 to anchor detection scope |
| Natural follow-on | Module 10 (Red Team & Validation) to test whether detection catches simulated attacks |
Make your existing tools work
The tooling you already own can detect the attacks you actually face. Module 11 builds the capability to use it.