安全方案 · Decripte
最受欢迎

事件响应

通过24x7专业团队保护您的企业,检测、遏制和消除网络威胁

为什么需要事件响应?

网络事件不可避免。区分成功企业的是响应的速度和效果。

快速响应

关键事件SLA最长1小时

24x7防护

专业团队持续监控和响应

取证分析

深入调查根本原因

清晰沟通

为管理层提供易懂的报告

本计划如何为您的企业服务

我们的事件响应服务远不止"灭火"。

获得多学科专家团队的即时访问。

使用最先进工具进行持续监控。

响应流程如何运作

基于NIST和SANS框架的方法论

1

检测

通过24x7监控立即识别。

2

遏制

快速隔离威胁。

3

分析

完整的取证调查。

4

清除

彻底消除威胁。

5

恢复

安全恢复系统。

6

文档

完整报告和建议。

认识保护您企业的团队

高管团队

拥有超过15年经验

协调响应策略。

高管团队
专业技术团队

专业技术团队

分析师在SOC中24x7轮班。

持有CISSP、CEH、GCIH、GCIA认证。

我们服务的竞争优势

减少损失

快速响应显著减少财务和声誉影响。

持续改进

每次事件都增强安全态势。

合规保障

满足所有监管要求。

主动预防

主动识别漏洞。

12个阶段每周4项服务

执行时间表

Plan focused on preparing, detecting, responding to, and learning from incidents, going far beyond just 'putting out fires', including preparation, governance, runbooks, training, and continuous improvement.

自动化 · 由 DMS 驱动

自动化管理工作流

DMS 自动执行完整闭环:监控、检测、开单、调查、关闭、报告 — 关键节点保留人工监督。

01

监控

Client triggers 24x7 retainer

02

检测

Fast triage and severity

03

开启事件

War-room opened in DMS

04

调查

Forensics + containment + legal

05

关闭

Eradication validated

06

告警与报告

Communication and DPA if applicable

DMS 管理
由 DMS 驱动

循环管理周期

本方案以持续项目模式运行,按日、周、月、季、年五大周期交付可审计成果 — 全部由 DMS 编排。

  1. 实时· 自动化
    • War-room activation in ≤ 1h
    • Initial triage and emergency containment
    • Forensic evidence collection
    • Communication with critical stakeholders
  2. 每日· 自动化
    • Active incident status report
    • Timeline and IOC analysis
    • IT/Legal sync
    • Root cause hypothesis updates
  3. 每周· 自动化
    • Lessons learned
    • IR playbook review
    • Internal team training
    • Assisted remediation plan
  4. 每月· 自动化
    • Simulated IR drill
    • Response plan update
    • C-Level and legal meeting
    • Readiness review
  5. 每季· 自动化
    • Tabletop with real scenarios
    • Retainer and SLA review
    • Stored evidence audit
    • Contact and RACI update
  6. 每年· 自动化
    • Annual incident response plan
    • Full forensic audit
    • Regulatory review (GDPR)
    • Contract and scope renewal
可审计

可审计交付物

每个周期产出具体交付物,含 SLA、定义格式和责任人。全部记录在 DMS 中,可随时审计。

Emergency Activation

War-room activated in ≤ 1h with forensics, legal and comms aligned.

格式
会议
频率
实时
SLA
≤ 1h

Daily Incident Status Report

Formal report with timeline, actions taken and next steps.

格式
报告
频率
每日
SLA
24/24h during crisis

Full Forensic Dossier

Evidence, chain of custody, IOCs and signed technical report.

格式
报告
频率
每月
SLA
≤ 30 days after containment

Custom IR Playbooks

Per-incident playbooks, versioned in the DMS.

格式
Playbook
频率
每季
SLA
Quarterly

Quarterly Drill / Tabletop

Realistic simulation to test the company's response capability.

格式
会议
频率
每季
SLA
Quarterly

Annual Incident Response Plan

Master document reviewed annually with C-Level and legal.

格式
报告
频率
每年
SLA
Annual
DMS 管理

集成与编排技术栈

DMS 集中管理客户全部网络安全技术栈。您无需操作分散工具 — 我们整合一切。

SIEM

Accelerated client log ingestion for timeline reconstruction.

EDR

Remote containment of compromised endpoints and network isolation.

XDR

Unified view to identify lateralization and propagation.

SOAR

Emergency containment playbooks executed in minutes.

MDR

Decripte team takes over operations during crisis.

IAM

Immediate revocation of compromised credentials and tokens.

PAM

Real-time blocking of suspicious privileged sessions.

密码保险库

Emergency rotation of exposed passwords and keys.

MCP · Machine Learning · 由 DMS 驱动

活跃 AI Agent

100% AI 服务,Agent 通过 MCP + 机器学习训练,按职能专精。秒级响应,无需排队。

Levi

安全分析师

Initial 24x7 triage and immediate war-room opening.

TriageSeverityComms

Shlomo

威胁猎人

Hunting attacker lateral movement and persistence.

MITRE ATT&CKPersistenceLateral

Dvorah

数字取证

Deep forensics, chain of custody and technical report.

ForensicsMemoryDisk

Asa

合规与审计

Regulatory notification, communication and legal dossier.

GDPRLegalDPA

计划中包含的所有内容

即时威胁遏制
详细取证分析
完全根除
高管沟通
关键SLA 1小时内

常见问题

关于事件响应的常见问题

开始

准备好保护您的企业了吗?

联系我们的团队获取定制方案。

事件响应 · Decripte

在线签约,几分钟完成

适合各种规模的企业 — 从个体到大型企业
无最低承诺
专属入职培训
24x7支持
月度报告
立即订购查看所有计划

无锁定 · 随时取消