Fully operated at the level your team needs

Extend your internal team, hand us the alert queue 24/7, or continuously advance your security program — with a 100% U.S.-based SOC.

Every package covers detection. Your package determines who owns everything after it.

Every package covers detection. Your package determines who owns everything after it.

BUILD

Extend the team

Keep daytime ownership. Hurricane Labs covers after-hours monitoring and response.

For capable teams with a coverage gap

OPERATE

most popular

Hand over the queue

A U.S.-based SOC runs 24×7 monitoring, triage, response, and operational cadence.

For teams that need full daily operations

EVOLVE

Advance the program

24×7 operations plus proactive hunting, engineering, and weekly improvement.

For mature programs pushing outcomes

BUILD

Extend the team

Keep daytime ownership. Hurricane Labs covers after-hours monitoring and response.

For capable teams with a coverage gap

OPERATE

most popular

Hand over the queue

A U.S.-based SOC runs 24×7 monitoring, triage, response, and operational cadence.

For teams that need full daily operations

EVOLVE

Advance the program

24×7 operations plus proactive hunting, engineering, and weekly improvement.

For mature programs pushing outcomes

Compare capabilities

Managed SIEM services

SIEM platform monitoring

and administration

24x7 automated detection, correlation, and alerting

Included, with AI/ML-assisted
capabilities where enabled in
Splunk

Included, with AI/ML-assisted
capabilities where enabled in
Splunk

Included, with AI/ML-assisted
capabilities where enabled in
Splunk

In-scope data-source health monitoring

U.S.-based SOC

100% U.S.-based

100% U.S.-based

100% U.S.-based

Human SOC coverage

After hours, weekends, and holidays

24x7x365

24x7x365

Business-hours alert queue ownership

Customer-owned

Hurricane Labs-owned

Hurricane Labs-owned

Automated severity-based
notifications

Included during business hours based on configured escalation paths

Included 24x7

Included 24x7

Human alert validation
and investigation

Included during covered hours

Included 24x7

Included 24x7

Incident notification and
escalation

Included during covered hours

Included 24x7

Included 24x7

Business-hours human
assistance

Available through a separately
purchased block of hours

Veeries MDR™

Pre-authorized response
and containment actions

Not included; available through purchased hours where supported

Included through Veeries MDR
where technically supported and customer-approved

Included through Veeries MDR
where technically supported and customer-approved

Response coordination

Available through purchased
hours

Included

Included with enhanced
coordination and follow-through

Standard detection content

Threat-informed standard detection updates

Detection tuning and maintenance

Included for standard content

Included

Included

Custom detection engineering

Available through purchased hours

Up to 5 engineering actions per month

Up to 50 engineering actions per quarter

Detection engineering backlog

Not included

Prioritized during regular service reviews

Jointly managed through an
ongoing detection roadmap

Standard dashboards

Custom dashboard development

Available through purchased
hours

Up to two new or materially
modified dashboards per month

Up to five new or materially
modified dashboards per month

Threat intelligence integration

Proactive threat hunting

Not included

Available as an add-on 

Included monthly and event-driven

Operational reporting

Standard monthly report

Customized monthly report

Customized weekly report

Service review cadence

Quarterly

Monthly

Weekly

Executive and strategic reporting

Standard quarterly executive summary

Included quarterly

Customized to stakeholder
requirements

Program improvement roadmap

Not included

Recommendations provided
during service reviews

Actively maintained and prioritized

Senior technical engagement

Limited, additional available
through purchased hours

Included through the assigned
delivery team

Expanded access to senior SOC and detection engineering leadership

Customer ownership of
SIEM content

BUILD

OPERATE

EVOLVE

Extend the team

Keep daytime ownership. Hurricane Labs covers after-hours monitoring and response.

For capable teams with a coverage gap

Compare capabilities

Managed Splunk services

Splunk platform monitoring

and administration

24x7 automated detection, correlation, and alerting

Included, with AI/ML-assisted capabilities where enabled in
Splunk

In-scope data-source health monitoring

U.S.-based SOC

100% U.S.-based

Human SOC coverage

After hours, weekends, and holidays

Business-hours alert queue ownership

Customer-owned

Automated severity-based
notifications

Included during business hours based on configured escalation paths

Human alert validation
and investigation

Included during covered hours

Incident notification and
escalation

Included during covered hours

Business-hours human
assistance

Available through a separately
purchased block of hours

Veeries MDR™

Pre-authorized response
and containment actions

Not included; available through purchased hours where supported

Response coordination

Available through purchased
hours

Standard detection content

Threat-informed standard detection updates

Detection tuning and maintenance

Included for standard content

Custom detection engineering

Available through purchased hours

Detection engineering backlog

Not included

Standard Splunk dashboards

Custom dashboard development

Available through purchased
hours

Threat intelligence integration

Proactive threat hunting

Not included

Operational reporting

Standard monthly report

Service review cadence

Quarterly

Executive and strategic reporting

Standard quarterly executive summary

Program improvement roadmap

Not included

Senior technical engagement

Limited, additional available
through purchased hours

Customer ownership of Splunk content

Not sure where to start?

Answer three quick questions about your coverage, engineering needs, and operating cadence. We’ll recommend the Hurricane Labs package that fits your team.
Question 1 of 3/Business-hours coverage
Who reviews and investigates alerts during your business hours?