Capability

The full spectrum, at a depth others don’t reach.

Compromise assessment, digital forensics and incident response, threat hunting, SOC assessment and OT security, run from Switzerland for organizations across Europe and the Gulf. Whatever the engagement, the standard is the same: bespoke scope, senior delivery, and the rigor to go deeper than the brief requires.

Read this as a range of capabilities, not a list of products. Most engagements draw on several of them, in full or in part, assembled into one scope that answers the question actually being asked. A compromise assessment that becomes an investigation, a readiness review with a threat hunt inside it, a retainer that carries forensic capacity: that is the normal shape of the work.

HOW ENGAGEMENTS RUN

  • Scoped, never templated Every engagement is shaped to the organization’s profile, technology and threat landscape, not fitted to a standard package.
  • Senior hands only A principal-level operator leads the work, not a junior analyst learning on the account.
  • Capability left behind Knowledge transfer and clear documentation mean the team is stronger after the engagement than before it.
[ 01 / PROACTIVE ]

Anticipate and strengthen.

Find and close the weaknesses before an adversary does, and prove the organization is ready for the day one gets through. SOC assessment, incident response planning and tabletop exercises.

01

A SOC assessment done as a deep technical review, service by service, not a maturity checklist. Ten SOC services, each measured across four axes, for a precise and defendable picture of how effectively each one delivers and where to invest.

Scope & method
Service-centric assessment across strategy, coverage, integration and continuous improvement; configuration-level validation of SIEM, EDR, logging and IR tooling; executive and technical reporting, with a prioritized capability-uplift roadmap.
Two-page brief (PDF) →
02

What an organization needs to do the right things when an incident hits: contain fast, allocate resources where they matter, and avoid the costly missteps. Built on hundreds of real incidents rather than a template.

Scope & method
Incident response plan and handling guides matched to the organization’s profile; tabletop exercises for technical and executive audiences; DFIR functional exercises that pressure-test the team against realistic, evidence-based scenarios.
Two-page brief (PDF) →
[ 02 / MANAGED ]

Continuous defense.

Senior expertise kept on tap and calibrated to a moving threat, so protection does not decay between point-in-time engagements. Managed threat hunting and a continuous cyber defense program.

03 FLAGSHIP

A multi-year, threat-informed program that keeps defenses calibrated to the adversaries most likely to target the organization, and proves they work. The client’s team operates; principal-level experts design, engineer and advise at a depth an internal SOC cannot self-supply.

Scope & method
Continuous compromise assessment and monthly penetration testing; detection and threat-hunting engineering; hardening and identity or perimeter reduction; IR readiness; every finding carried to verified closure, with an embedded Virtual Principal Consultant.
Two-page brief (PDF) →
04

Hunts designed and run by DFIR consultants where a compromise would hurt most, in IT and OT. Every detection is investigated forensically to a verdict, and each monthly cycle states whether the critical systems show signs of compromise.

Scope & method
Monthly hunts on AlexSta’s own Velociraptor fork and your SIEM and EDR, with collected data kept on premises; deliverables include the assurance statement, new real-time detection use-cases and a detection coverage map; three-year minimum.
Two-page brief (PDF) →
[ 03 / REACTIVE ]

When it counts.

Fast, expert answers to incidents and the questions they raise, including the cases another team has already closed. Emergency incident response, digital forensics and compromise assessment.

05

Where the hard cases land. The work reconstructs what happened even when the evidence is cold, degraded or was written off as gone, then contains, eradicates and recovers with the calm of people who have done it before. When another team has already closed the case, this is often the second call, and the one that solves it.

Scope & method
Emergency response for ransomware, APT and insider cases; disk, memory and cloud forensics; root-cause and timeline reconstruction; daily client updates and regulatory or legal support documentation.
Two-page brief (PDF) →
06

More than a hunt for intruders. The assessment examines the environment for active compromise and, in the same pass, for the gaps between existing controls and best practice that would let an attacker move laterally, escalate privilege or persist. Run over time, one of the most effective ways to drive down high-severity incidents.

Scope & method
Collection across endpoints, Active Directory, DNS, proxy and firewall, and cloud identity, using Velociraptor-based tooling; threat-intelligence-led triage; findings, impact assessment and a prioritized remediation plan.
Two-page brief (PDF) →
[ 04 / OFFENSIVE ]

Exposure, found first.

Proof of what an attacker could reach, found and closed before anyone uses it. The identity review traces the paths to control of Active Directory and Entra ID, and the credentials already exposed.

07

Which paths lead from an ordinary account to control of Active Directory and Entra ID, and which of the organization’s credentials are already exposed. Every path comes with its evidence and root cause, and each exposed account is read against the paths it would open.

Scope & method
Attack-path mapping and configuration review across Active Directory, Entra ID and the trust between them: tiering, delegation, certificate services, legacy protocols and trusts; leaked-credential research by the principal consultant; controlled validation where agreed; findings mapped to MITRE ATT&CK.
Two-page brief (PDF) →
08

Controlled attack at the depth the question needs, from an external penetration test to an intelligence-led red team run against live production. Nineteen services in eight categories, each showing what an adversary could reach and whether the defenders would stop them.

Scope & method
Infrastructure, cloud, identity, application, API, wireless and container testing; phishing and social engineering; assumed breach, purple team, red team and threat-led red teaming; vulnerability scanning and management. Findings carry impact and step-by-step remediation, with ATT&CK-mapped detection guidance on adversary work.
Three-page brief (PDF) →

Flagship program

CDAP / MULTI-YEAR

Cyber Defense Assurance Program

A multi-year, threat-informed program that keeps defenses calibrated to the adversaries most likely to target the organization, and proves they work. The client’s team operates; principal-level experts design, engineer and advise at a depth an internal SOC cannot self-supply.

It is still scoped bespoke. What changes is continuity: the same senior lead, the same understanding of your estate, and every finding carried through to verified closure rather than handed over as a report.

TYPICAL SHAPE OF ONE CYCLE

  • Continuous compromise assessment, estate-wide
  • Monthly penetration testing against the live estate
  • Detection and threat-hunting engineering
  • Hardening and identity or perimeter reduction
  • Incident readiness, exercised not assumed
  • Embedded Virtual Principal Consultant

Cadence, systems in scope and the mix of engagements are set per client. Every finding is carried to verified closure rather than logged and left.

NEXT / DEPTH

Approach

How these engagements are actually run, and what the evidence looks like.

NEXT / SCOPING

Engage

Consultant availability is limited by design. Describe the situation. The call is with the consultant who would run the assessment, not a salesperson.