SERVICE
Threat hunting
Three simultaneous paths: hypotheses from your sector's actor TTPs, indicators from our own intelligence and the FIRST network, and anomaly analytics over your baseline. The agent sweeps 90 days of history; the human hunter formulates, interprets and confirms.
The methodology, step by step
Threat model
Hypotheses prioritized by the groups attacking your sector: "if an adversary did X here, what trace would it leave?"
Agentic sweep
✦ AI AGENTThe agent sweeps 90 days of telemetry in minutes, enriches each candidate and dismisses the explainable with logged reasoning.
Human validation
The L3 hunter reconstructs the activity and separates real findings from legitimate behavior.
Containment or closure
Confirmed findings go to response with a runbook; risk that isn't an incident is documented and accepted in writing.
New detection
✦ AI AGENTEvery finding becomes a deployed rule: next time it will be an alert, not a hunt.
Pick the tier that answers your question
The price is fixed in writing after a 30-minute scoping and does not change during the contract.
Hunting within the CROC
Directed campaign
Continuous + retroactive
Thirty minutes and we tell you frankly what you need.
Sometimes the answer is "you don't need us yet." We prefer that to selling you something you won't use.