SOC Platform Setup

SOC Command Suite

A scoped route from current-state telemetry to a governed Microsoft Sentinel operating model. Detection engineering, automation, training, and handover are sized to the environment and confirmed in a written engagement plan.

Commercial model

Scoped

Timeline and deliverables confirmed after discovery

Review Engagement

Phase 1

Discovery & Setup

Data source inventory, workspace deployment, connector configuration

Phase 2

Detection Engineering

Analytics rules, playbooks, and dashboards deployment

Phase 3

Training & Handover

Analyst training, runbook delivery, and knowledge transfer

Defined

Detection catalogue

Tested

Automation playbooks

Scoped

Data connectors

Governed

Analyst handover

What's Included

Microsoft Sentinel Deployment

Workspace creation, Log Analytics configuration, and data retention settings for your requirements

Data Connector Design

Relevant cloud, identity, endpoint, and network sources selected during discovery

Analytics Rule Engineering

KQL detections mapped to the threat scenarios and telemetry agreed in scope

Automation Playbooks

Logic App playbooks scoped for agreed enrichment, notification, isolation, and ticketing use cases

Custom SOC Dashboards

Sentinel workbooks for incident management, metrics tracking, and ATT&CK coverage visualisation

Threat Hunting Library

KQL hunt queries shaped around the priority threat scenarios agreed in scope

SOC Analyst Training

Structured training covering Sentinel operations, KQL fundamentals, and incident-response procedures

Incident Runbooks

Documented response runbooks for the incident types prioritised during discovery

Deliverables

  • Configured Microsoft Sentinel workspace to the agreed scope
  • SOC operations handbook
  • Detection rule catalogue with MITRE ATT&CK mapping
  • Playbook documentation and maintenance guide
  • KQL threat hunting query library
  • SOC metrics dashboard (Sentinel workbook)
  • Training materials for ongoing analyst development
  • Post-deployment support period defined in the engagement scope

Technologies

Microsoft SentinelAzure Log AnalyticsAzure Logic AppsKQL (Kusto Query Language)Microsoft Defender XDRMITRE ATT&CK FrameworkPower BI (dashboards)

Ready to stand up your SOC?

Written scope, defined deliverables, and a handover model shaped to the engagement.