Be ready to detect, investigate and respond.
Good security records help you see what happened. A focused threat hunt tests for signs of the attacks that matter to your business. An incident response plan helps your people act when the evidence warrants it.
We use the exposure report and threat briefing to define the work around your priority threats and available evidence. We agree which parts will be most useful for your business before starting.
Has anyone already tried the door?
The threat briefing turns the forgotten portal into specific questions. The hunt tests each one against the records available, and reports plainly when the records are missing.
Hundreds of failed logins then one success. A former employee’s account signing in. An admin account nobody created.
We test each question against portal and hosting history. Missing records are a finding in their own right.
- Question / password guessing
Repeated failures, then a success?
Bursts of failed sign-ins from one source or many, followed by a successful login.
- Question / old accounts
Accounts that should be dormant?
Sign-ins by former staff, or by accounts unused since the portal was abandoned.
- Question / unpatched software
Changes nobody made?
New administrator accounts, unexplained settings or unexpected files that could indicate unauthorised access.
- Result / coverage gap
The portal history wasn’t available
No sign-in or administration records were supplied, so none of the three questions could be answered. Historical access remains unknown.
- Decision / action outstanding
Recover, restrict, record
Ask the hosting provider for any surviving logs, restrict the portal while it is reviewed, then retire it or turn on sign-in logging.
Logging that supports a security decision.
A log is a record of activity, such as a sign-in, permission change or remote connection. We identify which records are needed for your priority threats, then assess collection, completeness and retention.
Build and validate coverage
Configure agreed sources, timestamps, access controls and retention. Test that the expected events arrive and that your team can search them. Record missing sources and known blind spots.
Keep it useful and affordable
Choose collection and storage around the questions you need to answer. Document licensing, hosting, storage and maintenance needs, along with who owns the service and who responds to alerts.
A threat hunt with a reason behind every search.
A threat hunt is a structured investigation of available records for signs of compromise. We turn the earlier threat assessment into testable questions, then examine the available records for the agreed systems and time period.
- ExposurePublic staff information and a visible cloud sign-in service could support account targeting.
- Possible attackAn attacker may use a stolen account to access email or change payment instructions.
- Hunt and responseReview available sign-in, account-change and mailbox-rule records. Document the evidence and define escalation and containment steps.
This illustrates the method; the presence of an exposed service alone does not establish a compromise.
A response plan your team can follow.
People and decisions
Define incident contacts, deputies, escalation thresholds and authority to act. Clarify the roles of leadership, IT, security and external providers before an incident creates pressure.
Scenario-based procedures
Build procedures for the agreed priority incidents, including evidence preservation, containment decisions, communications and recovery checks. Account for the operational consequences of isolating systems or disabling accounts.
Handover and review
Walk through the procedures with the nominated owners and record dependencies or unanswered questions. A facilitated exercise can be scoped separately to test the plan with your team.
Evidence and a practical handover.
Your quote explains which services are included, what records we will use, which questions the hunt will test and what you will receive. Setup, storage, licensing and ongoing support costs are stated separately.
For a logging engagement
A list of record sources, how they are collected and kept, test results and any gaps. Operating instructions explain who checks collection is working, maintains the service and receives alerts.
For a threat hunt
The questions tested, systems and dates reviewed, supporting evidence and findings. We explain how certain we are, consider other explanations, identify missing records and recommend next steps. Significant findings are raised with your nominated contact.
For response planning
An incident response plan with contacts, responsibilities and procedures for the agreed scenarios. It explains when to review the plan, who owns any outstanding actions and how to confirm they are complete.
Build capability around what you need to protect.
Using existing tools where suitable avoids unnecessary replacement costs. Collecting purposeful records helps control storage spend. Documented procedures help your team begin an investigation with less delay and less duplicated effort.
Before you begin
What is your threat-hunting platform?
Our platform is Reaper, a temporary, contained investigation environment operated by QuirkyIT. It collects the agreed data and makes it searchable, allowing us to investigate activity and hunt for signs of the threats identified in your assessment.
The environment is temporary: it is set up for the engagement and retired when the work is complete. This lets us carry out a focused investigation without requiring you to buy and maintain a permanent security platform.
Do we have to use your platform?
No. Where your existing tools provide suitable records and search capabilities, we can work with those. We agree the approach, access requirements and any coverage gaps during scoping.
What happens to the data collected for a hunt?
Before collection begins, we agree which data is needed, where it will be processed and stored, who can access it, and how long it will be retained. Evidence handover and data removal arrangements are documented as part of the engagement. The temporary life of the investigation environment is separate from the agreed retention of reports and supporting evidence.
What if our logging is incomplete?
We assess the available evidence first. We may recommend improving collection before starting a hunt, or limit the hunt to the questions the records can support. New logging cannot recover historical activity that was never recorded.
Does a clean hunt prove there has been no compromise?
No. A hunt can only assess the agreed hypotheses using the systems, records and time period available. The report states what was tested, what was found and what remains unknown.
Is this a managed 24/7 monitoring service?
No. These are scoped engagements. Your team or nominated provider owns ongoing monitoring and response unless a separate agreement explicitly states otherwise. Alert destinations and responsibilities are documented at handover.
What happens if you find evidence of an incident?
Significant findings are escalated to your nominated contact under the agreed process, with supporting evidence and recommended next steps. Live incident response and remediation require an explicit scope; this service does not include a standing emergency response commitment. For a contained, out-of-band investigation, Reaper can be deployed for the case. Where an incident is confirmed you can report it to the Australian Signals Directorate through ReportCyber, though the decision to report stays with you.
Can you work with our current IT or security provider?
Yes. We agree access, responsibilities and handover with your nominated team. Collection changes and any actions that could affect business operations are agreed before implementation.
Build the visibility and readiness your business needs.
Tell us what your business needs to protect, what concerns you and which security tools you already use. We’ll help define a useful starting point and a clear scope.