TechDetechtives

Every attack leaves evidence. We find it.

TechDetechtives is one security platform that watches your systems, analyses your network traffic, finds your vulnerabilities and turns every serious alert into a case your team can work.

TechDetechtives logo: a detective in a fedora examining a malware bug through a magnifying glass, set on a red shield

Four jobs, one platform

Most teams run a separate tool for each of these and stitch the results together by hand. TechDetechtives keeps them in one place, so an alert, the traffic behind it and the weakness that allowed it sit side by side.

Security monitoring

Logs from your servers, endpoints and network sensors are collected centrally and checked against detection rules around the clock.

  • Detection on incoming logs as well as on files
  • Dashboards for hunting through past activity
  • Alerts ranked by severity

Incident response

An alert is only useful if someone picks it up. Each one at medium severity or above opens its own case, with the evidence already attached.

  • One case per alert, so nothing is merged or lost
  • Notes, tasks and timeline kept with the case
  • A record of what was done and when

Vulnerability analysis

Your systems are scanned for known weaknesses, so you can fix what is exposed before someone else finds it.

  • A dashboard of open findings by severity
  • Reports you can hand to system owners
  • Serious findings raised as cases to track the fix

Network traffic analysis

Sensors inspect traffic as it crosses your network and keep a record of who talked to whom, so an analyst can go back and see what happened.

  • Intrusion detection on live traffic
  • Connection records for every conversation
  • Traffic evidence linked to the alert it explains

How a case runs

An example of what happens between the first odd signal and a closed case.

  1. A sensor notices something

    A workstation starts sending data to an address it has never contacted before, outside working hours.

  2. A detection rule matches

    The activity fits a known pattern. An alert is raised and rated high severity.

  3. A case opens on its own

    Because the alert is above the threshold, a case is created with the alert details attached. Nobody has to copy anything across.

  4. An analyst investigates

    From the case, the analyst pulls the related logs and traffic records, and checks whether the workstation has known vulnerabilities.

  5. The case is closed

    The workstation is contained and fixed. What was found and what was done stays on record for the next investigation.

This is an illustration of the workflow, not a record of a real incident.

Tell us what you need to watch

Send a short note about your network and what worries you most. We will reply with how TechDetechtives would fit.

Prefer email? Write to tech@techdetechtives.com