Add-On Services
SIEM & Identity Threat Detection
A combined package for organizations that need deeper visibility: security information and event management (SIEM) collects and analyzes the security logs that matter across your environment, while identity threat detection and response (ITDR) watches your cloud identities for takeover and abuse.
Pairs with Managed Detection and Response to extend coverage from endpoints into your logs and cloud identities — closing the gaps attackers count on.
What you get
What is included
- Smart log collection: Security event data from your endpoints and infrastructure is collected and filtered to surface what actually matters — without the noise and cost of hoarding every log.
- Detection and investigation: Collected events are analyzed for indicators of compromise, supporting faster investigations and compliance requirements.
- Identity takeover detection: Watches Microsoft 365 sign-in activity for credential theft, session hijacking, and logins that don’t add up.
- Rogue app and inbox rule detection: Catches the attacker tricks that follow a compromised login — malicious mail-forwarding rules, unauthorized app grants, and privilege changes.
- Around-the-clock monitoring: Detections are reviewed and escalated continuously, with verified incidents routed to the AIS team for action.
- Compliance support: Log retention and reporting that help satisfy cyber-insurance and regulatory requirements.
The platform behind it
Huntress SIEM and Huntress ITDR, from Huntress. This is our standard platform. Where you have an existing preference or a requirement of your own, we support alternatives.Add it to your plan
Add-on services extend Core, Shield+ or Total Shield+. Talk to us about what fits.