top of page
  • Home
  • Platform
  • Chevalier — managed detection and response, in four tiers.

    CyberTI®'s Managed Detection and Response (MDR) platform goes beyond existing MDR services by addressing the whole attack life cycle and aligning protection to the MITRE ATT&CK model. From a first, autonomous prevention engine connected through the cloud, attacks are halted right at the entrance, and security is reinforced with kernel-level data gathering and processing to make it more resilient to attacker manipulation.

  • Threat intelligence (IOC/IOA)
  • Broad visibility
  • 24/7 monitoring
  • Advanced threat detection
  • Automated threat detection
  • Threat isolation
  • Canary detection
  • Chevalier — Managed Detection & Response tiers

    All delivered from CyberTI®'s single MDR platform, so you can take advantage of layered security.

    Chevalier

    Log retention
    7 days
    Targeted threat hunting
    Quarterly
    Remote incident response
    10 hr/qtr
    Touchpoint meetings
    Quarterly

    Chevalier Vanguard

    Log retention
    7 days
    Targeted threat hunting
    Quarterly
    Remote incident response
    15 hr/qtr
    Touchpoint meetings
    Quarterly

    Chevalier Hunter

    Log retention
    30 days
    Targeted threat hunting
    Fortnightly
    Remote incident response
    20 hr/qtr
    Touchpoint meetings
    Monthly

    Chevalier Elite

    Log retention
    90 days
    Targeted threat hunting
    Weekly
    Remote incident response
    30 hr/qtr
    Touchpoint meetings
    Monthly
    Capability comparison across the four Chevalier Managed Detection and Response tiers Capability Chevalier Chevalier Vanguard Chevalier Hunter Chevalier Elite Advanced Analytics Threat isolation Log Retention 7 days 7 days 30 days 90 days 24/7 Monitoring Endpoint, Network and Cloud AWS, Azure and Microsoft 365 Global Threat Intelligence Response Action Execution Targeted Threat Hunting Frequency Quarterly Quarterly Fortnightly Weekly Artifact-Driven and Hypothesis-Driven Hunting Custom Rule Action and Orchestrated Response Attack Surface Monitoring AI Machine Learning Threat Detection Canary Detection Remote Incident Response 10 hr/qtr 15 hr/qtr 20 hr/qtr 30 hr/qtr Incident Response Service Optional Optional Optional Optional Log Retention up to 100 months Optional Optional Optional Optional Customer Touchpoint Meetings Quarterly Quarterly Monthly Monthly

    Which tier, and how to read the table

    The four tiers are cumulative rather than alternative: each one is the tier below it plus the rows the table adds. So the question is not which product to buy but where the line falls between what your own people will do and what you would rather hand over, and the table is arranged to make that line visible.

    Chevalier is the base — prevention, detection and canary tripwires on the endpoint, monitored around the clock. Vanguard adds attack surface monitoring, which is the outside-in view of what an attacker can reach without credentials; that capability is a product in its own right and is described in full on the U-ASM page. Hunter adds proactive threat hunting — analysts going looking rather than waiting for a rule to fire. Elite adds the remote incident response hours that turn a confirmed detection into somebody else's night.

    Two things sit outside the tiers and are worth knowing before you choose one. If you are not yet sure what you should be logging or where your coverage stops, that is an advisory engagement rather than a subscription, and it is usually the cheaper place to start. If the constraint is your SIEM — its cost, its licence model, or the effort of maintaining detections in it — that is the SIEM services practice, which runs alongside any tier rather than replacing one.

    Every tier is delivered from the same platform and by the same team; there is no separate organisation behind the higher ones. The full catalogue is on the services page, and the people and the registered entity behind it are on the about page.

    Unified Attack Surface Management (U-ASM)

    U-ASM continuously discovers and monitors your digital assets for vulnerabilities and weaknesses, which helps you gain the attacker's point of view, resulting in a proactive and effective approach to security.

    Ready to see your attack surface the way an attacker does?

    Book a walkthrough with an Australian-based security engineer. No scripted demo, no obligation.

    Both forms deliver to info@cyberti.com.au.

    bottom of page