How It Works

How BlackWall protects your practice.

The homepage covers what you get and why it matters, in plain English. This page is the detail underneath — the tools, the specific threats they catch, and the standards they map to — for the technical or compliance-minded reader who wants to look under the hood.

The Core Difference

We built the platform we watch you with.

Your security isn't watched through a black box you can't see into, and it isn't someone else's product with our name stuck on it. Most managed-security shops resell another company's stack and configure a dashboard. BlackWall is different: the SOC platform that monitors your environment — Sentinel — and the offensive engine that tests it — KAORS — were designed and written in-house, from the detection logic to the reporting pipeline. When you ask how a detection works or why an alert fired, you're talking to the person who wrote it. That's the clearest competency signal we can give you: we don't just operate security tooling — we engineer it.

Sentinel SOC — built in-house KAORS offensive engine — built in-house No off-the-shelf resell
Live example

What the monitoring sees.

A simulated event stream — demo data — showing the kinds of alerts Sentinel surfaces in real time.

blackwall-soc — event stream (demo) LIVE
Services

Two disciplines. One partner.

Most firms either watch your network or attack it. BlackWall does both — and each side makes the other sharper.

Blue Team · Defense

BlackWall SOC

Continuous monitoring across four critical layers.

We watch the four places attacks actually land — your Microsoft 365 logins, your computers, your DNS traffic, and your network edge — and alert you the moment something looks wrong.

  • Microsoft 365 logins — account takeover, impossible travel, MFA turned off, mail-forwarding rules
  • Endpoints — malicious PowerShell, credential theft, new admin accounts, cleared logs
  • DNS — malware command-and-control, data tunneling, known-bad domains
  • Firewall / network — port scans, internet-exposed services, data exfiltration
  • Tamper-evident log retention & continuous SOC self-health checks
  • Real-time email alerts & plain-language reports — mapped to MITRE ATT&CK
Red Team · Offense

KAORS Penetration Testing

Scoped, fully authorized testing — with your written consent.

Scoped, fully authorized engagements that probe your environment the way a real attacker would — then hand you a clear, prioritized path to fixing what we find.

  • Automated reconnaissance — nmap, nikto, gobuster
  • CVE correlation with CVSS severity scoring
  • Controlled exploitation behind strict safety gates
  • Signed scope & written authorization, always
  • Polished PDF report with prioritized findings
  • Concrete remediation guidance, not jargon
Detection Catalog

What Sentinel actually watches for.

Not "we monitor your logs." These are the specific adversary behaviors Sentinel is built to detect, grouped by where they land and mapped to MITRE ATT&CK — so for any alert, we can show you the technique that triggered it.

Identity & Microsoft 365
  • Impossible-travel & atypical-location sign-insATT&CK T1078 — Valid Accounts
  • Legacy-auth logins bypassing MFA (IMAP/POP)ATT&CK T1078 — Valid Accounts
  • MFA disabled or weakened on an accountATT&CK T1556 — Modify Auth Process
  • Malicious inbox / mail-forwarding rule creation (BEC)ATT&CK T1114 / T1564.008
  • New privileged / admin account addedATT&CK T1098 — Account Manipulation
Endpoints
  • Encoded or obfuscated PowerShell executionATT&CK T1059.001 — PowerShell
  • Credential dumping via LSASS accessATT&CK T1003.001 — LSASS Memory
  • Local admin / privileged account creationATT&CK T1098 — Account Manipulation
  • Event-log clearing & anti-forensic activityATT&CK T1070.001 — Clear Windows Logs
DNS
  • DNS tunneling & data exfiltration over DNSATT&CK T1048 / T1071.004
  • Queries to known-bad & C2 domainsATT&CK T1071.004 — DNS
  • Malware command-and-control beaconingATT&CK T1071 — App Layer Protocol
Firewall & Network Edge
  • Internet-exposed RDP / management portsATT&CK T1021.001 — Remote Desktop
  • Inbound port-scan & reconnaissance activityATT&CK T1046 — Network Service Scanning
  • Internet-exposed services & attack surfaceATT&CK T1133 — External Remote Services
  • Outbound data exfiltrationATT&CK T1041 — Exfiltration Over C2
Integrity & Platform Health
  • Tamper-evident log-ledger verificationSealed chain, integrity-checked
  • Continuous SOC self-health monitoringFail-loud component checks
Coverage & Validation
  • Every detection mapped to MITRE ATT&CKTechnique-level traceability
  • Key detections exercised against real attacker techniquesIncl. Atomic Red Team T1110 brute-force, on live Windows telemetry
  • Catalog expands as techniques are addedOnly shipped detections are listed

Every detection here is built, mapped to MITRE ATT&CK, and validated by Sentinel's automated test suite — not an aspirational feature grid. Several have been exercised end-to-end against genuine attacker techniques on live Windows telemetry, including credential brute-force (Atomic Red Team, T1110) and unauthorized admin-account creation. Monitoring of your own Microsoft 365, DNS, and firewall feeds is wired up and verified during onboarding. As new detections are added and tested, they appear here.

Incident Response

How we respond when something fires.

Detection is only half the job. Here's exactly what happens between an alert and a resolved incident — the same chain, every time, from first signal to your notification.

01

Detect

02

Validate

03

Contain

04

Eradicate

05

Recover

06

Notify

Containment actions the response playbook can take

On a validated threat, and with your authorization, the response can:

  • Isolate a compromised endpoint from the network
  • Disable a compromised Microsoft 365 account
  • Disable or lock a compromised local/AD account
  • Kill a malicious process
  • Block a malicious IP address or domain
  • Revoke active sessions & tokens
  • Preserve forensic evidence & timeline
  • Escalate to you with a plain-language brief

Who's watching at 2 AM? 24/7 automated detection, with human response when it matters. Sentinel runs continuously — correlation and real-time alerts are built to fire the moment something matters, whatever the hour. When an alert escalates, a named practitioner — the person who built the platform — personally reviews and responds to it. There's no overnight analyst desk, and I won't pretend there is. Automated detection around the clock plus direct practitioner response is the model, and that direct access is exactly the point.

How It Works

Protected in three steps.

No rip-and-replace projects. No weeks of professional services. Onboarding is designed to be hands-off for your team.

Scope & Sign

We define the engagement

A short scoping call, a signed authorization, and a clear statement of work. Every engagement — monitoring or testing — starts with explicit, written consent.

Deploy in Minutes

Run one installer

Your team runs a single installer per machine. The agent runs silently in the background, auto-starts on boot, and immediately begins forwarding events over HTTPS.

> blackwall-agent install --client=yourco ✓ done
We Take It From Here

Monitoring, alerts, reports

Real-time alerts the moment something matters, automated triage with step-by-step containment playbooks for high-confidence threats, and client-ready PDF reports — incident summaries and pentest findings alike.

The Deliverables

See what you actually get.

Not stock photos — these are real covers from BlackWall's reporting pipeline, shown here with representative data. Every engagement is delivered with documents like these.

BlackWall SOC incident report cover (representative example)
BLACKWALL SOC — incident report · generated automatically · representative example
Download Sample Report (PDF)
KAORS penetration test report cover (representative example)
KAORS — penetration test report · CVSS-scored findings · representative example
Download Sample Report (PDF)
Examples

The kind of gaps an assessment uncovers.

Illustrative examples — not client results. These show the kinds of findings a small practice typically has, drawn from BlackWall's detection library. As engagements complete, real anonymized case studies will replace them.

Example · Dental Practice
Common gaps in a dental office
  • Microsoft 365 accounts without enforced MFA
  • RDP exposed directly to the internet
  • Missing DMARC — domain spoofable
HIPAA-alignedExample
Example · Legal Practice
Common gaps in a law office
  • Legacy auth bypassing MFA on mailboxes
  • Local admin rights on staff endpoints
  • No tamper-evident logging in place
Confidentiality-criticalExample
Example · Medical Practice
Common gaps in a medical office
  • Inbox forwarding rule to an external address
  • Unpatched service with a known CVE
  • Shared credentials across workstations
PHI environmentExample
Why BlackWall

Built differently, on purpose.

BlackWall was engineered from day one for the things most providers bolt on later.

True multi-tenant isolation

Each client gets a fully isolated database. Your security data never shares a table, a query, or a report with anyone else's. Zero cross-contamination, by architecture.

Authorized, in writing, always

Every engagement starts with explicit written authorization and a signed scope — targets, timing, and techniques agreed up front. Exploitation runs only against what you approve, behind strict safety gates.

Client-ready reporting

Polished PDF deliverables you can hand to leadership, auditors, or insurers — prioritized findings, plain-language impact, and concrete remediation steps.

Hands-off onboarding

One installer. No appliances, no network re-architecture, no agents fighting your endpoints. You're streaming events within minutes of signing.

Compliance

Built for the frameworks you answer to.

Our testing and reporting map to the standards your business and your insurers require, so an engagement doubles as documented evidence for auditors and carriers. We help you meet these requirements and prove it — compliance itself remains your organization's responsibility.

PCI DSS 4.0.1

Card-payment security

Requirement 11.4 mandates human-led internal and external penetration testing at least annually. Our reports follow PTES and NIST SP 800-115 and are structured to meet it.

HIPAA Security Rule

Healthcare & PHI

Requires regular technical evaluation of the safeguards protecting electronic PHI. Our testing and findings support that evaluation for healthcare organizations and their business associates.

FTC Safeguards Rule · GLBA

CPAs, tax & insurance firms

Covers accountants, tax preparers, and insurance agencies — requiring a written security program with penetration testing and periodic vulnerability assessments. We deliver the testing and documentation it calls for.

Cyber-Insurance

Coverage & claims

Carriers increasingly require evidence of penetration testing, MFA, and patch management to issue policies and pay claims. Our reports provide the documentation underwriters ask for.

Frameworks the service maps to

Beyond testing, the monitoring service is built around recognized security frameworks. Detections map to MITRE ATT&CK at the technique level; our coverage and controls align to the NIST Cybersecurity Framework (Identify, Protect, Detect, Respond, Recover) and the CIS Controls. For dental, medical, and legal practices, monitoring, tamper-evident logging, and incident response are structured to support HIPAA Security Rule safeguards for electronic PHI. We help you align to these frameworks and document it — we don't claim certification against them; compliance itself remains your organization's responsibility.

NIST CSF CIS Controls MITRE ATT&CK HIPAA-aligned
FAQ

Questions buyers actually ask.

Does BlackWall SOC replace our antivirus or firewall?

No — it complements them. Your antivirus blocks known malware; BlackWall SOC watches the bigger picture across four layers — your Microsoft 365 logins, your endpoints, your DNS traffic, and your network edge — catching account takeovers, privilege changes, malware command-and-control, and exposure your point tools miss. Keep your existing stack; we make it observable.

Who can see our security data?

Only you and BlackWall. Each client gets a fully isolated database — your events, alerts, and reports never share storage or queries with another client's. Data travels exclusively over encrypted HTTPS.

Is the penetration testing safe for production?

Engagements are scoped in writing before anything runs. Exploitation is gated behind explicit safety controls and only executed against targets you've authorized. You define what's in scope and out of scope — we never test beyond it.

What does it cost?

Engagements are scoped per environment — machine count for monitoring, target scope for testing. Request a consultation and you'll get a clear, fixed quote with no surprise line items.

Get started

Ready to see where you stand?

Start with an External Security Check — an outside-in look at what's exposed, with a plain-English report. No access to your systems needed.

Get My Security Check →
or email contact@blackwallsecurity.net · call (402) 819-9517 · Omaha, NE