Consulting Module

Module 11 — Blue/Purple Team Foundation

Most organisations own a Ferrari-grade security stack and drive it like a rental car. The tools are not the problem. This module builds the operating rhythm, detection rules, and hunting playbooks that turn security telemetry into security outcomes.

What It Delivers

⚙️

Capability Audit

The engagement begins by assessing not the tools, but the team's ability to use them. Defender for Endpoint alert coverage, Sentinel analytic rule quality, Defender for Office 365 review process, identity protection response time — each assessed against what the tool is capable of versus what is actually happening. The gap is almost always process, not technology.

🔔

Alert Tuning and Tiered Triage

High-fidelity alerts separated from noise. A tiered triage model deployed so analysts know which alerts require immediate response, which require investigation, and which are informational. The "200 alerts per day with no triage process" configuration — which produces analyst burnout and missed detections equally — replaced with something workable.

📐

Detection Engineering

Custom detection rules built against the specific attack techniques relevant to your environment — not the vendor's default rules covering all industries, but rules tuned to your crown jewels, your identity topology, and the kill chain your Diagnostic identified. Rules are tested against real activity before deployment to verify they fire without drowning the queue.

🎯

Threat Hunting Playbooks

Structured hunt hypotheses and execution playbooks for the techniques most likely to succeed against your environment. Analysts stop waiting for alerts and start looking for evidence of compromise that has not yet triggered one. The hunt is repeatable and scheduled, not ad-hoc and occasional.

🔄

Continuous Improvement Loop

Every alert, every hunt, and every incident feeds a tuning cycle. Detection misses produce new rules. False positives are suppressed with scope, not silence. The SIEM improves over time rather than drifting toward irrelevance as the environment changes around it.

Scope and Prerequisites

Duration45–90 days
EnvironmentMicrosoft Defender stack and/or Sentinel
PrerequisitesPULSAR deployed for audit log intelligence; initial kill chain from Module 0 to anchor detection scope
Natural follow-onModule 10 (Red Team & Validation) to test whether detection catches simulated attacks

Make your existing tools work

The tooling you already own can detect the attacks you actually face. Module 11 builds the capability to use it.