Managed Threat Response
MITG detects, investigates, and responds to threats across your endpoint, identity, email, cloud, and network environments, working directly with your team through containment and remediation.
Investigation across all alert severities
MITG investigates alerts across all severity levels, including low and medium. An attack can leave several low-severity signals that reveal a larger threat when correlated across endpoint, identity, email, cloud, and network.
MITG follows the evidence across these systems to establish the scope of the attack.
Illustrative investigation. Correlating signals across environments can reveal a wider attack.
Coverage
AI investigation and automated containment, continuously tuned by MITG, run at all hours. MITG analysts review every alert and automated action. Analysts and engineers are staffed through extended weekday hours and on call at all other times. Response commitments are stated in the service description.
Through containment and remediation
MITG hunts for other users and systems affected by the same attack and tracks the work needed to resolve it. Every incident closes with a lessons-learned review.
When cyber insurance is involved, MITG helps select legal and forensic specialists from the carrier’s panel and works alongside them to help lead the response. Insurer-panel services are separate from MITG’s own forensic investigation and response work.
MITG delivers MTR as one program, with analysts, an incident lead, AI, and automation working together.
Accountable end to end
MITG’s analysts and incident lead carry the response through forensic investigation, containment, remediation, and review.
AI correlates signals and investigates at machine speed. Automated isolation runs around the clock.
CrowdStrike Falcon Complete
Relationship managed by MITGContinuous collaboration
MITG works directly with your security and IT leaders and their teams through Teams, Slack, or your preferred platform. We share investigation progress, discuss findings, and coordinate response decisions.
Weekly threat detection reviewsEach week, we review detections across all severity levels with your team, discuss findings in the context of your environment, and agree on next steps.Specialist support when needed
MITG coordinates with your insurer and its specialists through resolution.
Coordinated by MITGResponse leadership and coordination
MITG sets response priorities, coordinates your teams and providers, and tracks agreed actions through completion.
Swipe to see all responsibilities →
leadership
coordination
follow-up
MITG MTR teamAccountable end to end
CrowdStrike Falcon CompleteSupplemental provider
Your security and IT teamsWorks with MITG
Insurer & counselWhen warranted
Select a symbol for activity details.
Responsibilities shown are for an MITG-led engagement.
Your security team, working with your MDR
Through day-to-day work with your security and IT teams, MITG learns your environment, business processes, and normal activity. That understanding informs our investigations and response decisions. If you retain an MDR provider, MITG manages the relationship and uses its findings and response capabilities as part of the program.
- Environment knowledge
- Our analysts use knowledge of your systems, normal activity, and business processes to investigate alerts and involve the right people.
- Day-to-day collaboration
- Your team works directly with MITG through shared investigation channels and weekly detection reviews.
- Incident leadership
- MITG opens and leads the response bridge for significant incidents, directs containment, and coordinates your teams and specialists.
- Detection and control improvements
- MITG tunes detections, updates the controls it operates, and tracks agreed corrective actions through completion.
Technical delivery by MITG
MITG delivers the technical work with analysts, an incident lead, AI, and automation.
Swipe to see all activities →
MITG MTR teamDirect technical delivery
AI & automationContinuously tuned by MITG
CrowdStrike Falcon CompleteSupplemental technical delivery
Built into MITG MTR
Detection engineering in your environment
MITG configures and continuously tunes your SIEM detections, tripwires, and response workflows around your environment.
Every alert reviewed by analysts and AI
Every alert in the MTR program receives AI investigation and individual analyst review, including low-severity activity.
Remediation follow-up
MITG updates the controls it operates and tracks client-owned actions through completion, with assigned owners and agreed completion dates.
When an incident extends beyond MDR coverage
An incident can span covered endpoints, unconnected systems, and actions your MDR cannot perform. MITG leads the response across those boundaries—investigating within the agreed MTR scope, bringing together provider findings, and coordinating your teams and specialists as needed.
Delivery and scope
Your environment, your assets
MTR is delivered in your tenant. Your telemetry, configurations, and tuning remain your assets.
Response and recovery
Technical delivery covers the systems and integrations in scope. MITG coordinates system rebuilding and data restoration with your IT team and providers, who carry out that work.
Getting started
We begin by understanding your environment, connecting your security platforms, and establishing how we’ll work with your team. Monitoring starts while we complete the initial security assessment.
We assess your existing platforms during onboarding and identify any changes needed to support the service.
Request an introductory meeting