7x24 SOC Service
One of the most important benefits of SIEMs is to reveal the threats that cannot be detected from the logs in a single source but can be detected by evaluating the logs from more than one source together, by making correlations over these collected logs.
unicons Cyber Defense Services monitors the alarms that occur on the SIEM products of our customers 24×7, analyzes these alarms and reveals the real threats by eliminating the false positives. It informs its customers about the detected real threats with the methods decided in the communication guide. unicons develops new correlation rules about global threats that have a wide impact and affect many companies. Additionally, unicons ensures that existing correlation rules are kept up to date. unicons develops special use-cases requested by the customer. By delivering monthly reports unicons informs its customers about the current situation, what happened within the reporting period and suggestions if any. And finally, unicons continuously improves its service quality according to the customer feedback.
Supported Products: IBM Security QRadar, Microsoft Azure Sentinel, OpenText ArcSight
7x24 MDR Service
With its MDR (Managed Detection and Response) service, unicons monitors the EDR and NDR systems of its customers 24×7, analyzes the alarms, removes false positives, reveals real threats, and informs the customer to eliminate these threats. Based on the terms agreed, unicons takes threat-eliminating response actions*. These actions are provided by the capabilities offered by the EDR/NDR/XDR platforms used by our customers.
*: Response actions are taken depending on the permissions approved by our customer.
Supported Products: Microsoft Defender Family, Vectra AI NDR
SIEM Installation and Configuration Service
One of the most important benefits of SIEMs is to reveal the threats that cannot be detected from the logs in a single source but can be detected by evaluating the logs from more than one source together, by making correlations over these collected logs. Due to many corporate policies and regulations such as 5651, some logs need to be kept for certain periods and used in a way that can produce reports in reasonable time if requested by legal authorities. SIEM products also ensure compliance with such regulations by ensuring that the integrity of the logs is not compromised, thanks to their centralized log management capabilities.
unicons SIEM Installation and Configuration Service ensures that we design the appropriate topology for the SIEM products, determines the necessary system resources, installs and configures the SIEM products, ensures that the logs are integrated into the SIEM, and the collected logs are parsed correctly. It also includes configuring ntp, snmp settings, backup settings and installation of HA (high availability) environments depending on purchased licenses. The service is delivered by the completion of the initially agreed installation and configuration plan.
Supported SIEM products: IBM Security QRadar, Microsoft Azure Sentinel, OpenText ArcSight
SIEM Technical Support Service
Technology is developing very fast and SIEM products are updated at the same speed, and they gain new capabilities very frequently. It is becoming more and more difficult to manage all security products used by even a medium-sized company with internal human resources, to intervene in technical problems and to produce solutions. For this reason, SIEM Technical Support Service or Managed SIEM Service, stands out as a highly preferred services for our customers.
Supported SIEM products: IBM Security QRadar, Microsoft Azure Sentinel, OpenText ArcSight
Managed SIEM Service
Managed SIEM Service is a service that allows our customers to use SIEM systems using only read/only accounts, and all necessary SIEM management is done by unicons and reported to our customers monthly.
Supported SIEM products: IBM Security QRadar, Microsoft Azure Sentinel, OpenText ArcSight