Security-Stack-Tiefe plus die aktuellen Themen: welche Tools unsere Profile aus produktiver Praxis kennen. Welche Profile zu Ihrem konkreten Setup passen, klären wir im Erstgespräch.
SIEM- und SOAR-Plattformen
Splunk Enterprise Security, Microsoft Sentinel, Elastic Security, IBM QRadar, Chronicle Security Operations · SOAR-Automatisierung mit Palo Alto XSOAR, Splunk SOAR und Sentinel-Playbooks · Detection Engineering mit Sigma-Rules, MITRE ATT&CK-Mapping und Threat-Intel-Feed-Integration
Endpoint- und Cloud-Security
CrowdStrike, SentinelOne, Microsoft Defender, Cortex XDR · Wiz, Prisma Cloud, Defender for Cloud, AWS Security Hub, GCP SCC
Identity und Zero-Trust
Entra ID, Okta, Keycloak · CyberArk, BeyondTrust · Zscaler, Cloudflare Access, Netskope · FIDO2/Passkeys
Netzwerk- und Perimeter-Security
Next-Generation-Firewalls von Palo Alto, Fortinet, Cisco · Web Application Firewalls (Cloudflare, F5, Akamai) · DDoS-Schutz · Secure Access Service Edge (SASE) und Secure Web Gateway
Vulnerability- und Threat-Intel-Tools
Qualys, Tenable, Rapid7 Nexpose für Vulnerability Management · Recorded Future, Mandiant, ThreatConnect für Threat Intelligence · Bug-Bounty-Tools und Attack-Surface-Management mit Randori, Censys
Aktuelle Themen — wo unsere Profile vorn sind
NIS2-Umsetzung (Risk Assessments, Meldeprozesse, Governance-Setup) · Zero Trust (Netzwerk-Segmentierung, konditionaler Zugriff, Privileged Access) · SOC-Modernisierung (SOAR, KI-gestützte Detection, Follow-the-Sun-Coverage) · Ransomware-Resilienz (Segmentierung, Backup-Strategie, IR-Playbooks) · Supply-Chain-Security (Third-Party-Risk-Management, SBOM, Software Composition Analysis) · Cloud-Native-Security (Container-Sicherheit, Kubernetes-Härtung, IaC-Security-Scanning) · Post-Quantum-Kryptografie-Vorbereitung
Bestehende Stacks übernehmen wir, wo das sinnvoll ist. Wir empfehlen Tool-Wechsel nur dort, wo es echten Mehrwert bringt — nicht aus Marketing-Reflex.