24/7 MANAGED SOC & MDR

A human analyst on every alert, day and night

Managed SOC and MDR for mid-market companies in Israel, Mexico and Europe. Detection on Huntress, SentinelOne and Splunk, triage in under 15 minutes, and a named analyst who calls you.

SOC in numbers

What you get, stated plainly

Alert triage target, day and night
< 15 min
Monitoring, weekends and holidays included
24/7/365
Detection on Huntress, SentinelOne and Splunk
3 platforms
Default location for your security data
EU

Response times are operating targets, not contractual SLAs. Contractual terms are set in your service agreement.

When we detect something

What happens in the first minutes

  1. 1Any hour

    Detect

    An alert fires on Huntress, SentinelOne or Splunk: an endpoint, an identity or a log source. It reaches the SOC at any hour.

  2. 2Within 15 min

    Triage

    A human analyst reviews it and separates noise from a real intrusion.

  3. 3Once confirmed

    Contain

    We take the containment steps you approved at onboarding, such as isolating a host or disabling an account.

  4. 4Straight after

    Tell you

    Your named analyst calls the contact you designated, then follows up in writing: what happened, what we did, and what you should do next.

Read a real timeline: 12 minutes to containment

Response targets

What happens, who does it, who gets called

Alert triage
A human analyst within 15 minutes, 24/7/365
Confirmed threat
Containment steps you approved at onboarding, started by the analyst on shift
Who gets called
Your designated contact, by phone, from your named analyst
Written follow-up
What happened, what we did and what you should do next
Reporting
Monthly report on alerts, incidents and open risks

Escalation path

  1. 1

    Analyst on shift

    Triages the alert and starts the approved containment steps.

  2. 2

    Your named analyst

    Owns the incident and calls your team.

  3. 3

    Your designated contact

    Gets the call, day or night, and agrees on next steps with us.

  4. 4

    Cybool incident lead

    Joins when an incident needs deeper investigation or recovery.

These are operating targets, not contractual SLAs. Your service agreement sets the contractual terms.

Who watches your alerts

People, not a ticket queue

Detection runs 24/7 on Huntress, SentinelOne and Splunk. Cybool analysts in Raanana, Israel, handle triage, escalation and every conversation with your team. You get a named analyst who knows your environment.

Detection platforms

Huntress, SentinelOne and Splunk across endpoints, identities and logs. IRONSCALES for email.

Coverage

24/7/365. Cybool analysts in Israel with round-the-clock detection on our partner platforms.

Your data

Stored in the EU by default.

Languages

We work in English, Spanish and Hebrew.

Platforms we run

  • Huntress
  • SentinelOne
  • Splunk
  • IRONSCALES

What we monitor

What is included in CyberSOC 24/7

Real-Time Threat Detection

Continuous monitoring of endpoints, networks and cloud environments, with detections tuned to your infrastructure.

Endpoint & Identity Security

EDR/XDR with identity threat detection and response (ITDR) to stop credential-based attacks.

SIEM Log Correlation

Centralized logging and correlation across your infrastructure for threat hunting.

Incident Response Workflow

Pre-agreed containment playbooks and analyst-led investigation when a threat is confirmed.

Monthly Reporting

Threat summaries, incident history and security posture metrics every month.

24/7/365 Coverage

Round-the-clock monitoring, weekends and holidays included.

"We already have Defender."

Good. Keep it.

Microsoft Defender, like any EDR, is a control. It raises alerts. It does not decide which one is an attacker at 3am, and it does not call anyone.

That is the part we run: people reading the alerts around the clock, confirming what is real, containing it and telling you.

  • Every alert triaged by a person within 15 minutes
  • Containment steps agreed upon with you in advance
  • A named analyst who calls you, not an automated ticket

FAQ

The questions buyers actually ask

We already have Microsoft Defender. Why do we need you?

Defender raises alerts. Someone still has to read them at 3am, decide which one is an attacker and act. That is the service: a human analyst triages every alert within 15 minutes, takes the containment steps you approved in advance, and calls you.

Are we too small to be a target?

Ransomware groups do not filter by company size. Our live ransomware map shows hundreds of new victims every month across every sector. Size mostly decides how long an attacker goes unnoticed.

What does it cost?

Essential and Business are quoted per endpoint after a short call, and Enterprise is priced to scope.

How long is the contract, and can we leave?

The minimum term is 12 months, billed monthly. You can leave with 60 days' notice, and we hand over a full export of your data with no exit fee.

Who actually watches our alerts?

Detection runs 24/7 on Huntress, SentinelOne and Splunk. Cybool analysts handle triage, escalation and every conversation with your team, and you get a named analyst who knows your environment.

Where is our data stored?

In the EU by default.

How fast do you respond?

Our target is human triage of every alert within 15 minutes, 24/7/365. It is an operating target, not a contractual SLA. Contractual terms are set in your service agreement.

Is Cybool ISO 27001 certified?

No, Cybool is not ISO 27001 certified today. Our team holds ISO 27001 Lead Auditor certification and runs ISO 27001 programs for clients.

Are you local to us?

Our analysts are based in Raanana, Israel, and we work with companies in Israel, Mexico and Europe, in English, Spanish and Hebrew.

Put an analyst on your alerts

Talk to a Cybool analyst about your environment, or start with a free external exposure scan.