Services
Detection engineering
Detections written, tested and versioned like code, for the tools you already run.
Detections are code.
Every rule and policy is reviewed, tested against recorded events, and rolled out and rolled back like any other change. Noise is measured and cut, not tolerated.
Tetragon TracingPolicies
Policy design for detection and enforcement, with staged rollout and rollback.
Falco rules
Custom rule sets, exception management and regression tests against recorded events.
KubeArmor policies
Workload policy generation and tuning, starting in audit mode before anything is blocked.
Cilium network policy
Policy derived from observed flows, with drop verdicts turned into detections.
WAF rules
Custom rule authoring and tuning, tested against logged traffic before anything blocks. The WAF platforms themselves are under Pentesting and AppSec.