MetisShield
MenuClose

Identity

Most small-firm losses start with a mailbox, not a movie-style breach.

Managed ITDR watches the identities people use to read mail and open files. We collect sign-in and audit logs from Microsoft 365 or Google Workspace into the stack we run. On Microsoft 365, an account takeover can trigger an automatic response: revoke the session and remove a malicious inbox rule. Those logs can lag 60 to 90 minutes. We do not call that instant.

Bundles
Pro and Complete. Not included in Essentials.
Coverage
Continuous automated monitoring, with on-call response
Price status
Proposed — pending validation of hosting and staffing cost

What we watch

  • Sign-ins that the logs can show as unusual: a new country, an impossible pair of locations, a burst of failures followed by success.
  • Inbox rules that hide, delete, or forward mail. Wiring-instruction fraud often looks like this.
  • New OAuth grants and enterprise applications.
  • Legacy authentication, if the tenant still allows it, plus MFA gaps, guest users, and admin role changes.

What runs it

  • The tenant’s own audit and sign-in logs, through Vector into Wazuh. We do not resell another company’s identity product under our logo.
  • Shuffle for the automatic Microsoft 365 actions, and DFIR-IRIS for the case.
  • MISP when an indicator from a real case is worth keeping.

What a person does

  • Reviews what the automation already did, and calls when a person should hear it during published hours.
  • Does not promise to see the event before Microsoft’s audit log does. That lag is often 60 to 90 minutes.
  • Disables an account outright only with scoped access and written authority. Session revoke and malicious-rule removal are the automatic pair, and only on Microsoft 365.

What you decide

  • Grant the scoped write that those two automatic actions need, or strike them from the order. Broader write access is still a separate line.
  • Keep a break-glass admin that is not the same account we use every day.
  • Tell us when someone is traveling, or when a contractor should have access, so we do not treat ordinary work as an attack.

Limits

  • We see what the tenant logs, when Microsoft or Google emits them. A 60–90 minute Microsoft audit lag is normal. We will not write “real time” into a proposal for that tenant.
  • Okta, Duo, or another identity provider as the system of record is a separate conversation. It is not silently included.
  • We are not Microsoft support and we are not Google support.
  • ITDR is not a full copy of every mailbox. We are not reading client matter files or patient charts as a routine.

We are not affiliated with or endorsed by the open-source projects named on this page.

The other services

Tell us how the firm is set up.

An assessment is a conversation and a short written note. It is not a penetration test, and it is not a contract. Nothing on this site takes payment.

Book an assessment