Co-managed
Your analysts keep ownership of the SIEM and incident decisions, while our SOC covers nights, weekends and overflow. Shared runbooks keep handovers clean.
Dark Pools runs a 24/7 Security Operations Center for your environment from operations centers in the United States and Southern Africa. Analysts triage alerts, investigate the ones that matter and coordinate containment with your team when an incident is confirmed. Run it co-managed alongside your own staff, or have Dark Pools carry the full watch.
Your analysts keep ownership of the SIEM and incident decisions, while our SOC covers nights, weekends and overflow. Shared runbooks keep handovers clean.
Dark Pools operates monitoring, triage, investigation and response end to end, and your team receives escalations and reports.
Endpoint, identity, network, email, cloud control-plane and application logs, depending on what your environment produces.
Containment, eradication support and recovery coordination for confirmed incidents, with evidence preserved for later review.
In a co-managed model your internal team keeps day-to-day ownership, and our analysts extend coverage to nights, weekends and peak periods using shared runbooks. In a fully managed model Dark Pools runs the watch end to end and escalates confirmed incidents to your named contacts.
Monitoring runs from operations centers in the United States and Southern Africa, which gives round-the-clock coverage across time zones. Data-residency requirements are agreed during onboarding.
No. The SOC works from the SIEM and security tools you already run, provided they produce the telemetry analysts need. Coverage gaps are documented during onboarding along with what it would take to close them.
Yes, within limits you set. During onboarding we agree which actions analysts may take on their own, such as isolating an endpoint or disabling a compromised account, and which need your approval first.
Scope soc-as-a-service with a security lead. We will tell you plainly what you need, and what you do not.