Platform capability
OperationalSIEM and XDR: centralised detection across your estate
Collects security telemetry from servers, endpoints, network devices and cloud workloads into one correlated detection engine.
Overview
Most organisations already generate the evidence of an intrusion. The problem is that the evidence sits in a dozen places nobody reads: a firewall log that rotates weekly, a domain controller nobody has audited, an application server whose disk fills with events that are never correlated with anything else.
Vanguard consolidates that telemetry into a single detection layer. Events are normalised, enriched and correlated against a maintained ruleset, so a failed login on one host, a privilege change on another and an outbound connection to a known-bad destination are assessed as one sequence rather than three unrelated lines.
Every custom detection is mapped to MITRE ATT&CK technique identifiers at the point it is written. That mapping is what lets us tell you not just that something fired, but what stage of an attack it represents.
What this identifies
- Brute-force and password-spraying against exposed services
- Suspicious PowerShell, WMI and living-off-the-land binary execution
- Privilege escalation and unexpected administrative group changes
- Persistence via scheduled tasks, services and registry run keys
- Command-and-control beaconing to known malicious infrastructure
- Log source silence, which is frequently the first sign of tampering
Delivery status: Operational - deployed and in production service.
Capabilities
What siem & xdr does
Unified log collection
Windows, Linux and macOS hosts, network appliances, firewalls and cloud workloads report into one pipeline with a consistent schema.
Correlation and rule engine
A maintained detection ruleset, extended with rules written for your environment and for threats observed against organisations in this region.
MITRE ATT&CK mapping
Detections carry technique identifiers, so coverage gaps are measurable rather than assumed.
A single severity ladder
One canonical severity scale governs dashboards, alerting and reporting. A critical alert means the same thing in every surface you look at.
Retention you choose
Index lifecycle policy is set per tenant at onboarding, so retention matches your investigative and regulatory needs rather than a default.
Under the hood
The engineering underneath
How this capability is actually engineered and operated. The specific detection tooling behind the security operations centre is shared with customers under agreement rather than published, for the same reason you would not publish yours.
- Agent-based collection across the estate, with the manager and indexing tier sized to your telemetry volume rather than a default.
- Decoders and correlation rules are version-controlled and reviewed before deployment; suppression rules are treated as first-class objects, not ad-hoc edits.
- Index lifecycle policy is configured at onboarding, so retention and storage growth are predictable.
- Every detection change is recorded in an append-only changelog with the method used to verify it.
The full platform architecture is documented on the architecture page.
Services
Services delivered on this capability
The platform provides the capability. These are the engagements in which Tech49Originals operates it on your behalf.
- Operational
Managed SOC
A staffed security operations centre in Windhoek monitoring your endpoints, servers and network around the clock, so you do not have to build one.
Explore - Operational
SIEM-as-a-Service
A fully operated SIEM for Namibian organisations, covering collection, retention, correlation and detection, without the infrastructure cost of running one yourself.
Explore - Operational
Incident Response
Structured response to confirmed security incidents for Namibian organisations: investigation, scope, containment guidance and a written post-incident account.
Explore
Related
Capabilities that work with this one
- Operational
Endpoint Detection & Response
Agent-based visibility into process execution, persistence, configuration drift and vulnerability state on every monitored host.
Explore - In deployment
Network Detection
Signature-based intrusion detection combined with protocol metadata, giving visibility into traffic that never touches a monitored endpoint.
Explore - Operational
Security Reporting
Monthly reporting generated from case records, written for both the technical team and the people who approve the budget.
Explore
Get started
Find out what is actually happening on your network
A short conversation is usually enough to establish whether monitoring would tell you something you do not already know. There is no obligation and no sales script.