Managed operations
Remote SOC
Security event correlation, threat detection, incident response and reporting.
Architecture
Architecture
- 01CollectEndpoint, network, application
- Wazuh agent
- syslog
- NetFlow
- 02Normalise
- Vector
- Graylog pipeline
- 03CorrelateDetection rules
- SIEM rules
- MITRE ATT&CK
- 04TriageFalse-positive filtering
- 05RespondContain and recover
- Playbook
- Forensics
Operator consoles
Operator consoles
These exact systems run on the group's own infrastructure — the screenshots are processed before publication.
The firewall — policy, sessions and load
A FortiGate in production: thousands of concurrent sessions, SPU load, security-fabric state and per-interface throughput on one screen. A firewall is not a separate box to us — it is designed and operated together with routing, segmentation and logging, by certified engineers.
public/media/proof/paloalto-firewall.webpnpm run proof:blurPalo Alto — policy at the application layer
The PAN-OS platform: App-ID and User-ID level policy, logging and threat prevention. We have engineers certified on it; a deployment screen goes up here once a specific production environment is cleared for publication.
Capabilities
Capabilities
Every item is marked: verified production experience, or engineering capability.
24/7 network monitoring
ProvenThe group's own ISP and datacenter run continuously — same processes, same tooling.
- Zabbix
- Prometheus
- Grafana
Severity-based incident response
Proven- Runbooks
- On-call rota
SOC — event correlation
CapabilitySIEM rules, detection content and incident response playbooks.
- Wazuh
- Graylog
- OpenSearch
Co-managed mode
CapabilityYour team keeps control; we cover the shifts and the escalation path.
ITSM integration
CapabilityTwo-way sync with your ticketing system.
- Webhooks
- REST API
Telegram / PagerDuty escalation
Proven- Telegram Bot API
- Alertmanager
Path monitoring and loss detection
ProvenLatency and packet loss to every critical destination — including cache servers hosted inside individual operators. That is how you tell whether the fault is in our network, in transit, or at the content provider.
- OpenPath
- ICMP / TCP probes
- per-ASN
Technology stack
Technology stack
- Monitoring
- ZabbixLibreNMSPrometheusGrafanaBlackbox
- In-house tooling
- OpenPathnoc.com.ge
- Logging
- GraylogOpenSearchLokiVector
- Security
- WazuhFortiGateSuricata
- Alerting
- AlertmanagerTelegramPagerDuty
Engagement model
Engagement model
Co-managed
NetWizard and your in-house team together, with split responsibility.
Fully managed
We own the agreed operational scope end to end.
Critical operations
24/7 monitoring, response and severity-based escalation.
Retainer
Monthly engineering hours — specialist access on demand.
FAQ
FAQ
How do you access our infrastructure?
Named accounts only, with MFA, logged sessions and agreed change windows. Details are in the Trust Center.
What SLA do you offer?
The SLA is defined per service plan: severity-based acknowledgement, response and escalation targets are fixed in the contract.
Can you work with our existing tools?
Yes. If you already run Zabbix, Prometheus, Grafana or a SIEM we operate on it, correcting the configuration where needed.