Skip to main content
Home/Services/Managed Detection & Response (MDR)
Security Testing

Managed Detection & Response (MDR)

Human-led detection and hands-on response across your environment

SOC 2 NIST CSF PCI-DSS HIPAA ISO 27001
engagement log Managed Detection & Response (MDR) testing
day 01scopetargets confirmed · rules of engagement signedagreed
day 01reconattack surface mappedcomplete
day 02findingCredential theft and session hijackingcritical
day 03findingLiving-off-the-land binary abusehigh
day 04triagereviewed and countersigned by a Lorikeet pentesterpublished
day 04delivertickets opened in your tracker201
afterretestfixes verified · included in scopeno charge
retest included human countersigned report your auditor accepts
Ongoing monthly servicetypical duration $4,500/monthfixed scope, from 8deliverables 7methodology stages
Scope

What this engagement covers

The service

Lorikeet Security MDR combines 24/7 monitoring, advanced analytics, and expert analyst triage to detect and contain threats across endpoints, identities, cloud, and network - so attacks get shut down in minutes, not weeks.

What we test

We ingest telemetry from your EDR, identity provider, cloud audit logs, email security, and network sensors. Every alert is triaged by a Tier 2+ analyst and either resolved, escalated, or actively contained on your behalf.

Method

How we run it

Continuous 24/7/365 coverage with custom detections tuned to your environment, behavioral analytics layered over signatures, and hands-on-keyboard response authorized up to our defined containment scope.

01

Telemetry onboarding and coverage mapping

02

Detection engineering and tuning

03

24/7 alert triage by analysts

04

Hands-on-keyboard containment

05

Threat intel enrichment

06

Retro / lessons-learned after each incident

07

Continuous coverage gap analysis

Deliverables

What you receive

Findings land in your tracker as you go, not only in a PDF at the end. Retest is in scope, not a change order.

  • 24/7 human-led alert triage
  • Active containment for confirmed threats
  • Detection content tuned to your stack
  • Monthly threat landscape briefing
  • Quarterly tabletop with your IR team
  • Integration with your ticketing (Jira, ServiceNow)
  • On-demand IR escalation
  • Retrospective reporting after every major incident
Typical results

What we usually find

The issues this engagement surfaces most often. Yours will differ, but this is the shape of it.

Credential theft and session hijacking Living-off-the-land binary abuse Malicious OAuth grants Business email compromise chains Cloud privilege escalation Ransomware precursors Initial access via unmanaged endpoints
Fit

Who this is for

Lean security teams carrying on-call
Companies with EDR but no 24/7 coverage
Cloud-first and SaaS-heavy environments
Regulated industries needing audit-ready response
Standards this supports

Findings are mapped to SOC 2, NIST CSF, PCI-DSS, HIPAA, ISO 27001, so the report drops into an audit package rather than needing to be translated first. If you need the readiness work behind one of those, that is a separate engagement.

Next

Scope it in one call

Tell us what is in scope and we come back with a fixed price and a start date. No discovery-call maze, no hourly estimate that moves.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!