Related commission
Anomaly detection reviews
A focused reading of alerts and outliers the client already collected, written as a review memo rather than a full incident chronology.
Who it is for
Teams that already run detectors and need a human reading of a batch of alerts, not a new detector.
What you receive
A review memo grouping alerts into worth-a-look, expected noise, and cannot-tell-from-this-export.
Scope
One agreed alert export or screenshot packet. No live tuning of production rules.
Included
- Classification of each alert in the packet
- Notes on missing context that would change the reading
- A short list of questions for the detector owner
Excluded
- Rewriting detection rules in the client's environment
- Guarantees that an alert is or is not an intrusion
Who writes it
Host Managerhub, Jackson, Georgia.
Process
- Packet receipt and a one-page scope note
- Line-by-line reading
- Memo delivery
Duration
Typically 3 to 5 business days for a single packet of up to a few hundred alerts.
Delivery
Remote memo. Optional follow-up call of 30 minutes.
Preparation
Export with timestamps, detector names, and any suppression notes already applied.
Constraints
A screenshot without timestamps is treated as incomplete evidence.
Pricing basis
Priced per packet. Volume beyond the stated band is quoted separately.
Next step
Email the packet description to contact@host-managerhub.digital before sending files.