SOC / SOC-07
Threat intelligence and external exposure monitoring
Identify threats and exposed assets relevant to the organisation and turn information into action. The service distinguishes contextual intelligence, external attack-surface inventory and technical vulnerability validation.

WHEN IT HELPS
A focused response
to a defined need.
Forgotten domains and services, brand impersonation, hard-to-interpret sector alerts or a need to prioritise internet-visible assets.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Organisational scope
- attributable domains and assets
- lawful open or licensed sources
- validation
- relevant threats
- notifications
- links to remediation and detection
Deliverables
- Validated external inventory
- targeted briefings
- exposure records
- confidence levels
- recommendations
- alert procedure
- tracking of unknown assets
Acceptance evidence
Assets are attributed with confidence levels; alerts are validated and assigned; incorrect matches are corrected; actions are tracked; visibility and frequency limitations are stated.
DELIVERY
How the work is structured.
Approach
Scope service and roles; connect and validate data; test scenarios; start operations; measure and improve.
Prerequisites & responsibilities
Customer: assets, logs, contacts and response authority. Provider: collection/analysis as contracted. Business decisions and recovery are explicitly allocated.
Scope factors
Assets, sources, events, volume, retention, integrations, hours and response level. Separate onboarding, licenses, consumption and recurring service.
Questions to clarify
Which domains, brands and subsidiaries are in scope? Who can confirm asset ownership? Who remediates or contacts the provider when exposure is identified?
IMPORTANT BOUNDARIES
Attribution of an asset or actor may remain uncertain. No intrusion, unlawful collection, purchase of stolen data or guarantee of complete internet coverage is included.
Hours and response times only after contractual approval. No guaranteed detection rate or resolution; collection gaps and failed sources remain visible in reporting.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A company discovers an old subdomain hosted by a supplier. Project: confirm ownership and arrange closure or takeover. Target outcome: controlled exposure with resolution evidence rather than merely a screenshot in a report.
Scenario 02
A company receives generic threat alerts. Project: relate them to its technologies and operations. Target outcome: contextual monitoring or remediation decisions; uncorroborated information remains clearly labelled.
Technology and reference context
Examples: institutional sources, public registries and authorised CTI/EASM platforms; coverage and licensing specified in the contract.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
