MetisShield
MenuClose

Stack

The software we will run. Named, including the exception.

This is the chosen set. It is not running for a client today. The first install is internal: our own mail, our own laptops, a restore test, then a client. We are not affiliated with or endorsed by these projects.

Three limits that stay on this page

Windows blocking antivirus is Microsoft Defender

We manage Defender on Windows endpoints in the order. No open-source product is standing in for a blocking antivirus. Defender is Microsoft software, on the firm’s Microsoft license. If that license cannot do what we need, we say so before we pretend it can.

Microsoft 365 detection is not instant

Audit logs can lag 60 to 90 minutes. We do not promise to see an account takeover the moment it happens. Automatic response means: when the log shows a takeover, revoke the session and remove the malicious inbox rule. It does not rewind the lag, and it does not disable every account we feel uneasy about. Broader containment still follows the responsibility matrix. Google Workspace does not get that automatic pair of actions until we have built it.

Scanners, decoys, and tests stay inside a scope

OpenVAS, Nuclei, OpenCanary, and Atomic Red Team can look like an attack if they are pointed at the wrong place. Atomic Red Team stays in our lab unless a written test window says otherwise. Scans and decoys happen only where the order allows them.

Endpoint, logs, and detections

  • Wazuh

    Endpoint monitoring and the SIEM. The index is OpenSearch-based, the one Wazuh ships.

    Before any client. On our own machines first.

  • Vector

    The pipeline that carries logs into that index. Endpoint agents are not the only way data arrives.

    With the first log source that is not the Wazuh agent.

  • Sigma and YARA-X

    Detections we maintain: Sigma for log behavior, YARA-X for files and malware we choose to name.

    Tested in the lab before they page a client.

  • Microsoft Defender

    The blocking antivirus on Windows. We manage it. It is not open source. We will not pretend an open-source AV does this job.

    On every Windows machine in the order, using the Microsoft license the firm already has.

  • Velociraptor

    Investigation and response on a specific machine: collect, hunt, and contain when the case needs more than the alert.

    Server ready early. Used when a case calls for it.

Cases, automation, and intel

  • DFIR-IRIS

    Case management. What we saw, what ran automatically, what a person did, and who authorized it.

    Before the first client, because the first alert needs a file.

  • Shuffle

    Automation for steps we have already decided, including the Microsoft 365 responses below. If Shuffle is down, a person still owns the case.

    With the Microsoft 365 response, not as a toy workflow.

  • MISP

    Threat intelligence we actually use. An empty intel server is not something we advertise.

    After real indicators are worth keeping.

Identity and posture

  • Microsoft 365 account takeover

    Detection of a mailbox takeover, then an automatic response: revoke the session and remove a malicious inbox rule. Microsoft audit logs can lag 60–90 minutes, so this is not instant. The same automatic actions are not promised on Google Workspace until we have built and tested them.

    With Managed ITDR, and only if the order leaves this authority in place.

  • ScubaGear and Maester

    Microsoft 365 and Entra posture checks. They are baselines and tests, not a certification.

    With the M365 posture review.

  • Prowler

    Cloud posture, and the Google Workspace side of the review. ScubaGear does not cover Google.

    When the firm has Google Workspace or a cloud account in scope.

Exposure

  • Greenbone OpenVAS and Nuclei

    Vulnerability scanning inside a written scope. Not part of the free assessment, and not a surprise scan.

    After the scanners work in the lab, on the cadence the order names.

  • Falco

    Runtime detection for Linux and cloud workloads the firm actually runs. A Windows-only office does not get a pretend Falco deployment.

    Only where those workloads exist.

  • OpenCanary

    Decoys placed with the firm: something that should never be touched, and that opens a case when it is.

    When the firm agrees to a place to put one.

  • CrowdSec

    Reputation and blocking on paths we operate, starting with our own edge.

    With the first public host we run.

  • AdGuard Home

    DNS filtering where the firm’s DNS actually points at us. We cannot filter a resolver we do not sit on.

    Only when the order moves DNS.

  • Coraza and OWASP CRS

    A web application firewall on traffic that passes through something we operate. A site hosted entirely at someone else’s vendor is not behind this WAF unless we are placed there.

    Only when we are in that path.

Practice

  • GoPhish fork

    Phishing training on a fork we maintain, on its own host and sending domain. Upstream GoPhish has not endorsed us.

    Before the first simulation. Never on the detection servers.

  • CISO Assistant

    Compliance-oriented reports from findings we actually have. A report is not a certification, and it does not make the firm compliant.

    When the monthly letter needs that shape. Not before we have findings.

  • Atomic Red Team

    How we test our own detections in a lab. Not an unscheduled attack on a client.

    In the lab, before those detections are trusted.

The stack is not the contract.

An assessment names what the firm already has. The order names which of these tools actually get installed, and which authorities we do not have.

Book an assessment