Services

Lepteer can assist your business and provide consulting services related to Security Engineering, Security Operations and Incident Response.


Security Engineering

With my experience, from the security engineering perspective I can assist you with SIEM, SOAR and XDR solutions.

A deployment of a SIEM Solution within an organization is a long process, made of different phases:

  1. Planning and Scoping
  2. Architecture and Infrastructure Design
  3. Data Ingestion and Pipeline Engineering
  4. Parsing and Normalization
  5. Detection Engineering and Use Cases
  6. Alert Tuning and Noise Reduction
  7. SOAR Integration

With the Planing and Scoping phase, the goal is to define the business needs and understand compliance requirements. With this information, an initial estimation of the (daily) log volume can be calculated. Crucial information for sizing the architecture that will be desinged and implemented within the next steps.

With the Architecture and Infrastructure Design, we start defining how the architecture will look like, based on the needs and requirements identified in the previous phase. As you may now, a SIEM platform is made of different type of components, each of them fulfilling different purposes. We can have indexers, collectors, search heads, etc. In this phase we analyze and define how many indexers we will need, how many collectors we will need, where they will be located, what are the hardware and software specification that the systems will have, etc.

With the Data Ingestion and Pipepline Engineering phase, we start thinking about from which systems/assets we want to collect the data and send it to our SIEM. Do we need Active Directory logs? For sure, to properly perform account monitoring and detect potential threats. Do we need Firewall logs? Of course, to detect potential scanning, initial phase of an attack, and understand if somebody is knocking on our door. But do we need all the events from the AD and from the Firewalls? We try to answer all these questions within this phase.

Within the Parsing and Normalization phase, we have a closer look to the data that we have decided to ingest in the previous step. With Parsing we refer to the phase related to data extraction from the logs. Is the relevant information being parsed properly as expected? Are the values properly extracted? With Normalization phase we ensure that information that is being extracted is stored and named in a proper way, so that can be found, and used for detection purposes.

With the Detection Engineering and Use Case Deployment, we identify what we want threats we want to detect, and we build related detection rules, that leverages the data we decided to ingest in the earliest phases. Do we want to detect brute force attempts on our accounts? do we want to detect outgoing ssh connections toward internet?

With the Alert Tuning and Noise Reduction phase we improve our detection rules, we work on reducing false positives, adjusting the thresholds, configuring exceptions, and filtering out unnecessary noise.

Now, we have detection rules, working properly, detecting potential threats, generating alerts, but we do not have the resources (manpower) to handle them within the desired timeframe. Thats why we need to leverage Automation, otherwise our security team will drawn in the sea of alerts, and burnout, and leave the organization. A natural evolution of a mature SIEM, is to pair it with a SOAR solution. SOAR platforms allow to create playbooks, that can take care of different phases of the alert handling process, from triage, to active response, depending on our needs and use cases. That is what we do within the SOAR Integration phase.

We have done this in the past, we know what are the pain points, we have learned the hard way, we have invested the time for you. Lets focus on delivering.

As for SIEM, a deployment of a SOAR platform is a long process made of different phases, each of them targeting specific questions, finding answers, and building a tailored solution for the environment.

Usually a SOAR deployment consists of the following phases:

  1. Process Standardization
  2. API Integration and Environment Setup
  3. Use Case Selection
  4. Playbook Development & Testing
  5. Deployment
  6. Monitoring

Solutions like SOAR need as input working already optimized processes. It cannot automate broken processes. Thats why the first phase is about Process Standardization. Defining the processes, their structure, decision trees, necessary approvals, etc. Once this is set, we can start looking for the best way to automate it.

Once we have identifed what process(es) we want to automate, we need to identify which systems are involved in the process. If for example we are trying to automate the account disable process, we will definitely have to deal with the Active Directory. And once the account is disabled we will likely want to update our case with the action taken, etc. Thats why the API Integration and Environment Setup phase is needed. Now that we know the systems involved in the process, we need to understand the best way to connect them to our SOAR platform. Usually this is done via API, or using service accounts.

After we have successfully connected the necessary systems, we need to choose what use case we want to tackle. This is the Use Case Selection phase. What is the most repetitive, time consuming task that we could automate and save precious time of our analysts? Start with low-hanging fruits.

Okay, we have identified the use case that we want to automate, and now we need to get our hands dirty, and start developing it. We are in the Playbook Development and Testing phase. We first need to design a high level structure of the SOAR playbook that we want to implement. Its a good practice to start with basic functions, working with “versions”. Once we have a high level structure we start using actions and building blocks to achieve the logic that we need. What we want is a first working and tested version.

We have finished the implementation, and tested, and we feel confident enough to deploy in production. Thats what we do in the Deployment phase. We move our playbook from staging/development to Production.

Once its in production, we cannot just forget about it. We need to monitor the playbook and notice if any strange behavior is observed. Thats what is for the Monitoring phase. Its a good practice having a more intense monitoring, for the first weeks, and later to rely on automated monitoring tools.

And this high level, and as we all know, the devil its in the details, but no worries, we know how to handle them.


Security Operations

With regard to Security Operations Lepteer can offer wide range of services such as

  • People and Team Leadership Services
  • Process Optimization and Operational Excellence
  • Technology and Automation Engineering

People Management is one of the most complex, if not the most complex thing within a security team / departement. Quite often, teams suffer from burnout, poor onboarding, high turnover, and other issues.

Lepteer can provide Interim Leadership service. Step in to lead and mentor Tier 1 to Tier 3 analysts and/or engineers during company transitions, rapid growth, or leadership changes. Lepteer can also provide support for designing Shift and Rotation Architectures, keeping in mind that business interest and people wellbeing.

Within the security teams, unfortunately the turnover is quite a common thing, due to demanding nature of industry. People coming, and people departing is a normal dynamic within security teams nowadays. Lepteer provides services to navigate these moments, such as creation of technical hiring frameworks, and/or candidate vetting. We build tailored technical assessment to be used during the hiring process, to ensure all candidates are assessed in a standardized way and to allow your business to identify the best candidate for the role, and we can step in as technical interviewer during the process. We are there to support you, wherever you need it.

Once we have identify the perfect candidate to join your organization, and have the candidate signed the contract, we move to the next step. Ensuring that your organizations has well-documented, structured, efficient on-boarding process. Lepteer can build 30-60-90 Day Onboarding Process for you, with the goal in mind of reducing the time necessary for the onboarding, improving the efficiency, and the business benefiting as soon as possible from the new resource.

For a team to deliver its best, having the best candidates is not enough, its one part of the equation, the other half is reppresented by efficient, structured, well-tested processes, designed to minize time and resource wasting, and increase efficiency. Lepteer can suppor with the development of proccesses such as Ticket Hygiene and Queue Governance, Operational Handover and Workflow Design, Metrics and Reporting.

The team works with tools on daily basis, and we want those tools to be configured and tailored in the best possible way to match the business needs and security requirements. This is where Lepteer can support, stepping in, assessing your tools, such as SIEM, SOAR, XDR, EmailSec, WAF, etc, suggesting improvements where deemed necessary, and ensuring that you get out the most of your (pricely payed) tools.


Incident Response

We can do all the homework, have the best team, best processes, optimized tools, however we will never be 100% risk free from a cyber security attack. Thats why we need to be ready. Hope for the best, prepare for the worst. Lepteer can help you with services such as Incident Readiness and Playbook Engineering, Tabletop Exercises & Simulation and Incident Lead-as-a-service.

This service ensure that you are ready before the incident happens. It focues on

  • devevloping a custom IR (incident response) plan, tailored to your organization;
  • the creation of (IR) playbooks (actionable step-by-step technical playbooks for most common threats)

Even the best plan is useless if the team hasn’t practiced it. The best way is to test the plan through simulations, and evalute how well the team/organization performs. The simulation can be done at different levels

  • Technical SOC Simulation
  • Executive Tabletop Exercises

The technical SOC simulation simulates a breach, and evaluates how well the security team detects, triages, and escalated an incident.

The executive tabletop exercise its a non-technical workshop with C-level executives, legal, PR, and other relevant departments. Its meant to train, test and ensure that different functions at differet levels within the org know how to behave during a major crisis.

If you need extra support, or you dont have internal resources for handling an incident, Lepteer can step in and act as central incident commander, and take care of the incident handling and ensure threat is succesfully contained, and countermeasures are put in place to prevent another occurence.