merlon
Log In
Pricing
Blue Team · Detection & Telemetry

The team that never stops watching.

Our Blue Team runs continuous, systematic telemetry across the entire merlon estate — turning raw signals from endpoints, logs, and the network into early, actionable detection. They are full-time, in-house engineers, not an outsourced alert queue, and they cover both regions around the clock.

Meet the Purple Team
24/7 coverage Real-time telemetry 100% endpoint coverage
SOC console — live telemetry
1,284
Events / min
100%
Endpoints reporting
<5m
Mean time to detect
Correlation rule triggered · analyst reviewing
Mission

See everything. Miss nothing.

"The Blue Team's mandate is simple and absolute: see everything, miss nothing."

As full-time, in-house engineers, they operate merlon's detection stack around the clock, correlating system telemetry to catch anomalies long before they become incidents. Because they work with confidential corporate data every day, their default posture is zero trust and total visibility. Every server, every workload, every identity, and every packet is in scope — and the moment something deviates from an established baseline, it surfaces on the console you can see above.

What they monitor

Four continuous streams of truth

Detection is only as good as the telemetry behind it. The Blue Team instruments four independent signal sources, then correlates across them so a weak signal in one becomes a strong detection overall.

Endpoints (EDR)

Every server and workload is instrumented with Endpoint Detection & Response tooling, streaming process, file, and behavioural telemetry in real time. Suspicious child-processes and unexpected binaries are flagged the instant they appear.

Logs & SIEM

Security logs from across the platform are centralised in a SIEM, where correlation rules and behavioural baselines surface suspicious activity. Related events are stitched into a single, contextual timeline for the analyst.

Network security

Ingress, egress, and lateral traffic are continuously inspected for anomalies, unexpected flows, and known malicious signatures. An outbound connection to an unfamiliar destination is a first-class alert, not a footnote.

Identity & access

Authentication events, privilege changes, and access patterns are monitored to catch credential misuse and privilege escalation early. A login from an unusual region or an out-of-hours privilege grant triggers review.

Toolchain

The detection stack, layer by layer

A defence-in-depth pipeline where each layer enriches the next — from raw agent telemetry to an enriched, prioritised alert.

SIEM correlation
The central nervous system: normalises events from every source, runs correlation rules, and maintains behavioural baselines so anomalies stand out against normal activity.
EDR agents
On every server and workload, streaming process, file, and behavioural telemetry with the ability to isolate a host in seconds if needed.
Centralised log aggregation
Tamper-evident collection of security logs from applications, infrastructure, and identity systems into a single searchable store.
Behavioural anomaly detection
Statistical and heuristic baselining that flags deviations — a service account acting like a human, a spike in egress, an impossible-travel login.
Threat-intelligence enrichment
Indicators and destinations are enriched against curated threat intelligence so analysts triage with context, not guesswork.
Detection lifecycle

From raw signal to precise response

Signals are collected continuously, correlated against baselines, triaged by severity, and escalated with full context so response is fast and precise.

Collect

Telemetry streams in from endpoints, logs, network, and identity — continuously, in real time.

Correlate

The SIEM stitches related events across sources against behavioural baselines.

Detect

Correlation rules and anomaly models surface activity that deviates from normal.

Alert

Enriched with threat intel and severity, the alert reaches an analyst with full context.

Respond

Contain, isolate, and remediate — then feed findings back into detection rules.

Response playbook

Every alert has a pre-agreed response

Analysts don't improvise under pressure. Each severity level maps to a defined action, an owner, and an escalation path — so the response is fast, consistent, and auditable no matter which shift is on the console.

Critical
Confirmed active compromise or cross-tenant risk. Immediate containment, host isolation, incident commander engaged, and customer notification path opened per our breach process.
High
Strong indicator of malicious activity. Triaged within minutes, contained, and escalated to the on-call lead; a Purple Team review is scheduled to confirm the control gap is closed.
Medium
Suspicious but unconfirmed. Investigated in-shift with full context; baseline tuned if benign, escalated if the picture changes.
Low / informational
Noise or expected deviation. Logged, correlated for pattern analysis, and used to refine detection rules so real signals stand out.
Metrics band

Detection, measured

<5min
Mean time to detect
critical alert triage
100%
Endpoint coverage
every server & workload
24/7
Monitoring
follow-the-sun
Real-time
Telemetry ingestion
no batch delay
Threat scenarios

The behaviours that put us on alert

Detection is driven by behaviour, not just signatures. These are representative patterns our correlation rules and baselines are tuned to catch — the early signs of an intrusion in progress.

Credential misuse

Impossible-travel logins, out-of-hours privilege grants, and service accounts behaving like humans — classic signs of stolen or misused credentials.

Anomalous process activity

Unexpected child-processes, unknown binaries, or a workload suddenly reaching for tools it has never used before.

Unusual data egress

Spikes in outbound volume, connections to unfamiliar destinations, or transfers that don't match a workload's normal pattern.

Defense tampering

Attempts to disable logging, clear indicators, or alter security controls — often the first move once an attacker is inside.

Lateral movement

East-west traffic that crosses segments it shouldn't, hinting at an attacker trying to expand a foothold.

Rate & abuse patterns

Brute-force attempts, credential-stuffing bursts, and API abuse that trip rate baselines before they succeed.

Follow-the-sun SOC

The console is never dark

Coverage doesn't pause for a time zone. As the working day ends in one region, the shift hands over to the next — with full context, open cases, and live baselines carried across.

Zürich

The European HQ hosts R&D and security. During CET hours, Zürich analysts own the console, monitor the Swiss region, and run the day's threat-intel review.

CET coveragech-eu-1

United States

As Europe signs off, the US shift takes the handover. During ET hours, US analysts own the console and monitor the US region — a seamless 24-hour loop.

ET coverageus-east-1

Structured shift handover

Every handover follows a checklist: open cases, active baselines, in-flight investigations, and any Purple Team simulations scheduled. Nothing falls through the gap between shifts.

A day in the life

What a detection actually looks like

An illustrative walk-through of a single low-severity anomaly — from first signal to closed case — as the analyst would see it.

08:14 — Signal

An EDR agent reports a service account spawning an unexpected child-process on an app node.

08:14 — Correlation

The SIEM links it to a slightly elevated egress flow from the same host seconds earlier.

08:15 — Triage

Enriched with threat intel, the analyst confirms the destination is a known internal CI endpoint — benign, but out of pattern.

08:19 — Close & tune

Case closed as expected behaviour; the baseline is tuned so the same pattern won't page an analyst again.

Case #SOC-4821
edr.process.start 08:14:02 · user=svc-app child=curl
net.flow.egress 08:13:58 · bytes=2148 dst=ci.internal
intel.enrich 08:14:40 · dst=known-good
case.close 08:19:11 · disposition=benign
SeverityLow → resolved
MTTD2 min
Baselinetuned
The other half of the loop

Detection only matters if the defences work

That's where our Purple Team comes in — validating every control the Blue Team relies on through controlled attack simulation, and gating every release before it ships. Detect, test, harden — a continuous loop.

Questions

Blue Team questions

Is the Blue Team in-house or outsourced?
Entirely in-house. They are permanent merlon engineers — not an outsourced managed-detection queue. Security is a department we run, not a vendor we hire.
Do they monitor both regions?
Yes. The SOC is follow-the-sun across Zürich and the US, monitoring both the Swiss and US regions with a structured handover between shifts.
How fast do you detect a critical event?
Our target is mean-time-to-detect under five minutes for critical alerts, with real-time telemetry ingestion and 100% endpoint coverage.
How do you know the detections actually fire?
That's the Purple Team's job. They run controlled attack simulations to verify the Blue Team's detections trigger as intended — a continuous closed loop. See Purple Team.

Talk to the team that watches your data

Bring your security questions. We'll walk your team through our detection stack, coverage, and response process in a 30-minute session.

Talk to Sales