The team that never stops watching.
Our Blue Team runs continuous, systematic telemetry across the entire merlon estate — turning raw signals from endpoints, logs, and the network into early, actionable detection. They are full-time, in-house engineers, not an outsourced alert queue, and they cover both regions around the clock.
See everything. Miss nothing.
"The Blue Team's mandate is simple and absolute: see everything, miss nothing."
As full-time, in-house engineers, they operate merlon's detection stack around the clock, correlating system telemetry to catch anomalies long before they become incidents. Because they work with confidential corporate data every day, their default posture is zero trust and total visibility. Every server, every workload, every identity, and every packet is in scope — and the moment something deviates from an established baseline, it surfaces on the console you can see above.
Four continuous streams of truth
Detection is only as good as the telemetry behind it. The Blue Team instruments four independent signal sources, then correlates across them so a weak signal in one becomes a strong detection overall.
Endpoints (EDR)
Every server and workload is instrumented with Endpoint Detection & Response tooling, streaming process, file, and behavioural telemetry in real time. Suspicious child-processes and unexpected binaries are flagged the instant they appear.
Logs & SIEM
Security logs from across the platform are centralised in a SIEM, where correlation rules and behavioural baselines surface suspicious activity. Related events are stitched into a single, contextual timeline for the analyst.
Network security
Ingress, egress, and lateral traffic are continuously inspected for anomalies, unexpected flows, and known malicious signatures. An outbound connection to an unfamiliar destination is a first-class alert, not a footnote.
Identity & access
Authentication events, privilege changes, and access patterns are monitored to catch credential misuse and privilege escalation early. A login from an unusual region or an out-of-hours privilege grant triggers review.
The detection stack, layer by layer
A defence-in-depth pipeline where each layer enriches the next — from raw agent telemetry to an enriched, prioritised alert.
- SIEM correlation
- The central nervous system: normalises events from every source, runs correlation rules, and maintains behavioural baselines so anomalies stand out against normal activity.
- EDR agents
- On every server and workload, streaming process, file, and behavioural telemetry with the ability to isolate a host in seconds if needed.
- Centralised log aggregation
- Tamper-evident collection of security logs from applications, infrastructure, and identity systems into a single searchable store.
- Behavioural anomaly detection
- Statistical and heuristic baselining that flags deviations — a service account acting like a human, a spike in egress, an impossible-travel login.
- Threat-intelligence enrichment
- Indicators and destinations are enriched against curated threat intelligence so analysts triage with context, not guesswork.
From raw signal to precise response
Signals are collected continuously, correlated against baselines, triaged by severity, and escalated with full context so response is fast and precise.
Collect
Telemetry streams in from endpoints, logs, network, and identity — continuously, in real time.
Correlate
The SIEM stitches related events across sources against behavioural baselines.
Detect
Correlation rules and anomaly models surface activity that deviates from normal.
Alert
Enriched with threat intel and severity, the alert reaches an analyst with full context.
Respond
Contain, isolate, and remediate — then feed findings back into detection rules.
Every alert has a pre-agreed response
Analysts don't improvise under pressure. Each severity level maps to a defined action, an owner, and an escalation path — so the response is fast, consistent, and auditable no matter which shift is on the console.
- Critical
- Confirmed active compromise or cross-tenant risk. Immediate containment, host isolation, incident commander engaged, and customer notification path opened per our breach process.
- High
- Strong indicator of malicious activity. Triaged within minutes, contained, and escalated to the on-call lead; a Purple Team review is scheduled to confirm the control gap is closed.
- Medium
- Suspicious but unconfirmed. Investigated in-shift with full context; baseline tuned if benign, escalated if the picture changes.
- Low / informational
- Noise or expected deviation. Logged, correlated for pattern analysis, and used to refine detection rules so real signals stand out.
Detection, measured
The behaviours that put us on alert
Detection is driven by behaviour, not just signatures. These are representative patterns our correlation rules and baselines are tuned to catch — the early signs of an intrusion in progress.
Credential misuse
Impossible-travel logins, out-of-hours privilege grants, and service accounts behaving like humans — classic signs of stolen or misused credentials.
Anomalous process activity
Unexpected child-processes, unknown binaries, or a workload suddenly reaching for tools it has never used before.
Unusual data egress
Spikes in outbound volume, connections to unfamiliar destinations, or transfers that don't match a workload's normal pattern.
Defense tampering
Attempts to disable logging, clear indicators, or alter security controls — often the first move once an attacker is inside.
Lateral movement
East-west traffic that crosses segments it shouldn't, hinting at an attacker trying to expand a foothold.
Rate & abuse patterns
Brute-force attempts, credential-stuffing bursts, and API abuse that trip rate baselines before they succeed.
The console is never dark
Coverage doesn't pause for a time zone. As the working day ends in one region, the shift hands over to the next — with full context, open cases, and live baselines carried across.
Zürich
The European HQ hosts R&D and security. During CET hours, Zürich analysts own the console, monitor the Swiss region, and run the day's threat-intel review.
United States
As Europe signs off, the US shift takes the handover. During ET hours, US analysts own the console and monitor the US region — a seamless 24-hour loop.
What a detection actually looks like
An illustrative walk-through of a single low-severity anomaly — from first signal to closed case — as the analyst would see it.
08:14 — Signal
An EDR agent reports a service account spawning an unexpected child-process on an app node.
08:14 — Correlation
The SIEM links it to a slightly elevated egress flow from the same host seconds earlier.
08:15 — Triage
Enriched with threat intel, the analyst confirms the destination is a known internal CI endpoint — benign, but out of pattern.
08:19 — Close & tune
Case closed as expected behaviour; the baseline is tuned so the same pattern won't page an analyst again.
net.flow.egress 08:13:58 · bytes=2148 dst=ci.internal
intel.enrich 08:14:40 · dst=known-good
case.close 08:19:11 · disposition=benign