Fully operated at the level your team needs
Extend your internal team, hand us the alert queue 24/7, or continuously advance your security program — with a 100% U.S.-based SOC.
Every package covers detection. Your package determines who owns everything after it.
Every package covers detection. Your package determines who owns everything after it.
BUILD
Extend the team
Keep daytime ownership. Hurricane Labs covers after-hours monitoring and response.
For capable teams with a coverage gap
OPERATE
most popular
Hand over the queue
A U.S.-based SOC runs 24×7 monitoring, triage, response, and operational cadence.
For teams that need full daily operations
EVOLVE
Advance the program
24×7 operations plus proactive hunting, engineering, and weekly improvement.
For mature programs pushing outcomes
BUILD
Extend the team
Keep daytime ownership. Hurricane Labs covers after-hours monitoring and response.
For capable teams with a coverage gap
OPERATE
most popular
Hand over the queue
A U.S.-based SOC runs 24×7 monitoring, triage, response, and operational cadence.
For teams that need full daily operations
EVOLVE
Advance the program
24×7 operations plus proactive hunting, engineering, and weekly improvement.
For mature programs pushing outcomes
Compare capabilities
Managed SIEM services
SIEM platform monitoring and administration
24x7 automated detection, correlation, and alerting
Included, with AI/ML-assisted
capabilities where enabled in
Splunk
Included, with AI/ML-assisted
capabilities where enabled in
Splunk
Included, with AI/ML-assisted
capabilities where enabled in
Splunk
In-scope data-source health monitoring
U.S.-based SOC
100% U.S.-based
100% U.S.-based
100% U.S.-based
Human SOC coverage
After hours, weekends, and holidays
24x7x365
24x7x365
Business-hours alert queue ownership
Customer-owned
Hurricane Labs-owned
Hurricane Labs-owned
Automated severity-based
notifications
Included during business hours based on configured escalation paths
Included 24x7
Included 24x7
Human alert validation
and investigation
Included during covered hours
Included 24x7
Included 24x7
Incident notification and
escalation
Included during covered hours
Included 24x7
Included 24x7
Business-hours human
assistance
Available through a separately
purchased block of hours
Veeries MDR™
Pre-authorized response
and containment actions
Not included; available through purchased hours where supported
Included through Veeries MDR
where technically supported and customer-approved
Included through Veeries MDR
where technically supported and customer-approved
Response coordination
Available through purchased
hours
Included
Included with enhanced
coordination and follow-through
Standard detection content
Threat-informed standard detection updates
Detection tuning and maintenance
Included for standard content
Included
Included
Custom detection engineering
Available through purchased hours
Up to 5 engineering actions per month
Up to 50 engineering actions per quarter
Detection engineering backlog
Not included
Prioritized during regular service reviews
Jointly managed through an
ongoing detection roadmap
Standard dashboards
Custom dashboard development
Available through purchased
hours
Up to two new or materially
modified dashboards per month
Up to five new or materially
modified dashboards per month
Threat intelligence integration
Proactive threat hunting
Not included
Available as an add-on
Included monthly and event-driven
Operational reporting
Standard monthly report
Customized monthly report
Customized weekly report
Service review cadence
Quarterly
Monthly
Weekly
Executive and strategic reporting
Standard quarterly executive summary
Included quarterly
Customized to stakeholder
requirements
Program improvement roadmap
Not included
Recommendations provided
during service reviews
Actively maintained and prioritized
Senior technical engagement
Limited, additional available
through purchased hours
Included through the assigned
delivery team
Expanded access to senior SOC and detection engineering leadership
Customer ownership of
SIEM content
BUILD
OPERATE
EVOLVE
Extend the team
Keep daytime ownership. Hurricane Labs covers after-hours monitoring and response.
For capable teams with a coverage gap
Compare capabilities
Managed Splunk services
Splunk platform monitoring and administration
24x7 automated detection, correlation, and alerting
Included, with AI/ML-assisted capabilities where enabled in
Splunk
In-scope data-source health monitoring
U.S.-based SOC
100% U.S.-based
Human SOC coverage
After hours, weekends, and holidays
Business-hours alert queue ownership
Customer-owned
Automated severity-based
notifications
Included during business hours based on configured escalation paths
Human alert validation
and investigation
Included during covered hours
Incident notification and
escalation
Included during covered hours
Business-hours human
assistance
Available through a separately
purchased block of hours
Veeries MDR™
Pre-authorized response
and containment actions
Not included; available through purchased hours where supported
Response coordination
Available through purchased
hours
Standard detection content
Threat-informed standard detection updates
Detection tuning and maintenance
Included for standard content
Custom detection engineering
Available through purchased hours
Detection engineering backlog
Not included
Standard Splunk dashboards
Custom dashboard development
Available through purchased
hours
Threat intelligence integration
Proactive threat hunting
Not included
Operational reporting
Standard monthly report
Service review cadence
Quarterly
Executive and strategic reporting
Standard quarterly executive summary
Program improvement roadmap
Not included
Senior technical engagement
Limited, additional available
through purchased hours
Customer ownership of Splunk content
$19,500
/ month