Skip to content
Cyber Security

Managed Detection & Response (MDR) & SOC

A 24×7 security operations centre with SIEM and XDR, threat hunting, incident response and telecom-specific detection for SIP, SMS and signalling fraud - so threats are found and contained in minutes, not months.

Managed Detection & Response (MDR) & SOC - Dollu
  • 24×7

    Analyst-staffed SOC

  • ≤ 15 min

    Critical alert triage

  • SIP · SMS · SS7

    Telecom detection content

Overview

What is Managed Detection & Response (MDR) & SOC?

Dollu Managed Detection & Response gives you a fully staffed 24×7 security operations centre without building one. Telemetry from endpoints, servers, cloud accounts, identity providers, firewalls, SASE, email, network sensors and - uniquely - carrier voice, messaging and signalling platforms is collected into a SIEM and XDR platform, correlated against detection content and threat intelligence, and triaged by analysts on a follow-the-sun rota across our Noida, London and Ashburn operations. Confirmed threats are contained under agreed playbooks, and every incident is documented from first alert to closure.

Detection is engineered, not just enabled. Our detection engineering team maintains content mapped to MITRE ATT&CK for Windows, Linux, macOS, Microsoft 365, Google Workspace, AWS, Azure, Google Cloud, Kubernetes and network infrastructure, tuned per customer to suppress noise. Threat hunters run hypothesis-driven hunts across your telemetry weekly, looking for tradecraft that signatures miss. Threat intelligence from commercial feeds, industry sharing groups and Dollu's own carrier network - which sees attack infrastructure, phishing domains and fraud sources at scale - enriches every alert.

Because Dollu is a carrier, the SOC understands telecom threats that generic providers do not. Detection content covers SIP registration and INVITE anomalies, toll fraud and IRSF, PBX compromise, Wangiri and traffic-pumping patterns, SMS grey routes, SIM-box activity, smishing and OTP interception, SMPP account abuse, and SS7 and Diameter signalling attacks such as location tracking and SMS interception. For contact centres, UCaaS providers, CPaaS platforms and carriers, this is often the first time voice and messaging security has been monitored alongside IT security in one place.

Response is defined in advance. Playbooks agreed at onboarding specify what the SOC may do autonomously - isolate an endpoint, disable an account, block an indicator at the firewall or SASE layer, suspend a SIP trunk showing fraud - and what requires your approval. Incident responders join bridge calls for major incidents, lead containment and eradication, and produce a report with root cause, timeline and recommendations. Monthly service reviews cover incidents, detection coverage, mean time to detect and respond, and a prioritised list of hardening actions.

Why Dollu

Why choose Dollu for mdr & soc.

The advantages of buying from a carrier that owns its network, interconnects and operations - rather than a reseller.

  • Eyes on your environment every hour

    Analysts triage every critical alert within 15 minutes, day and night, so a compromise at 03:00 on a Sunday is contained before the business day begins.

  • Minutes to contain, not months to notice

    Correlated telemetry, tuned detections and pre-agreed containment actions collapse dwell time from the industry's months to minutes or hours.

  • Voice and messaging fraud caught early

    Detection content for SIP, SMS and signalling abuse - informed by what Dollu sees across 600+ carrier interconnects - stops toll fraud and OTP interception that IT-only providers never see.

  • Threat hunting finds what alerts miss

    Weekly hunts across your telemetry look for living-off-the-land tradecraft, credential misuse and slow-burn intrusions that do not trigger signatures.

  • A team that knows your estate

    Named SOC lead, onboarding that documents your assets and crown jewels, and playbooks written with you - not a generic ticket queue.

Capabilities

Capabilities in detail.

Everything included with Managed Detection & Response (MDR) & SOC - the platform features, options and controls you get from day one.

  1. 01

    SIEM and XDR platform

    Cloud-hosted SIEM with log ingestion from endpoints, servers, cloud, identity, email, network and security tools; XDR correlation across telemetry; retention from 90 days to 7 years; in-region storage options.

  2. 02

    Endpoint detection and response

    Deployment and management of EDR agents from CrowdStrike, SentinelOne or Microsoft Defender across Windows, macOS and Linux, with isolation, forensic collection and remote remediation.

  3. 03

    Cloud and identity monitoring

    Detection across AWS, Azure, Google Cloud and Dollu Cloud control planes, Microsoft 365 and Google Workspace, Entra ID and Okta, covering privilege escalation, persistence, data exfiltration and misconfiguration.

  4. 04

    Network detection

    Sensors and flow telemetry from Dollu circuits, firewalls, SASE and customer networks for command-and-control, lateral movement, DNS tunnelling and data staging.

  5. 05

    Telecom fraud and signalling detection

    CDR, SIP, SMPP and signalling analytics for IRSF, PBX hacking, Wangiri, traffic pumping, SIM-box, grey routes, smishing, OTP interception and SS7/Diameter attacks, with automated trunk and route controls.

  6. 06

    Threat intelligence

    Commercial and open-source feeds, sector sharing communities and Dollu network-derived indicators - malicious infrastructure, phishing domains, fraud sources - applied to detections and blocking.

  7. 07

    Threat hunting

    Weekly hypothesis-driven hunts by dedicated hunters, ad-hoc hunts on new intelligence, and findings converted into new detection content.

  8. 08

    Incident response

    Playbook-driven containment, incident bridge for major events, forensic analysis, eradication and recovery guidance, and reports with timeline, root cause and recommendations; retainer hours for large investigations.

  9. 09

    Governance and reporting

    Portal with live incidents and status, monthly service reviews covering MTTD, MTTR, coverage against ATT&CK and hardening actions, and evidence for ISO 27001, PCI-DSS, SOC 2 and RBI audits.

How it works

How it works.

From first conversation to live traffic - a tracked, engineer-led onboarding with a named owner at every step.

  1. Step 01

    Onboard

    We document your assets, crown jewels, business hours and escalation contacts, connect log sources and deploy EDR and sensors, and agree playbooks and autonomous action limits.

  2. Step 02

    Tune

    Detections run for two to four weeks while analysts and detection engineers suppress noise, build allow-lists and add customer-specific rules and telecom content.

  3. Step 03

    Monitor and respond

    24×7 triage, investigation and containment under playbooks; incident bridges for major events; weekly threat hunts; continuous intelligence enrichment.

  4. Step 04

    Improve

    Monthly reviews of incidents, metrics and coverage gaps drive new detection content, hardening actions and adjustments to playbooks as your estate changes.

Use cases

Who uses this and why.

Typical deployments across carriers, enterprises, platforms and contact centres.

  • Carriers, MVNOs and UCaaS providers

    Monitor SIP infrastructure, SMS gateways and signalling links alongside IT, catching toll fraud, grey routes and SS7 abuse that erode margin and customer trust.

  • Banks and payment providers

    24×7 detection across core systems, cloud, identity and OTP messaging channels with retention, evidence and reporting aligned to RBI and PCI-DSS.

  • Healthcare

    Ransomware-focused detection and rapid containment for clinical and administrative systems, coordinated with Dollu backup and DR for clean recovery.

  • SaaS and CPaaS platforms

    Cloud-native detection across Kubernetes, hyperscaler accounts and identity, plus API abuse and account takeover monitoring for customer-facing platforms.

  • Mid-size enterprises

    Full SOC capability - EDR, SIEM, hunting and response - for organisations that cannot justify a dedicated in-house security operations team.

Specifications

Technical & commercial specifications.

Key parameters at a glance. Ask us for the full service description and SLA document.

Coverage24×7×365 analyst-staffed; Noida, London, Ashburn
Triage SLACritical ≤ 15 min; high ≤ 1 h; medium ≤ 4 h
TelemetryEndpoint, server, cloud, identity, email, network, firewall, SASE, telecom
EDR platformsCrowdStrike, SentinelOne, Microsoft Defender for Endpoint
Cloud coverageAWS, Azure, Google Cloud, Dollu Cloud, M365, Google Workspace
Telecom contentSIP, SMPP, CDR analytics, SS7/Diameter; trunk and route controls
Retention90 days hot standard; up to 7 years archive; in-region options
ResponsePlaybook containment; incident bridge; IR retainer hours
FrameworksMITRE ATT&CK mapping; ISO 27001, PCI-DSS, SOC 2, RBI evidence
SupportNamed SOC lead; monthly service review; P1 response ≤ 15 min
Pricing model

How Security is priced.

Security services are priced per protected site or circuit, per user or per endpoint - and MDR by endpoint count or log volume. Assessments and penetration tests are fixed-scope projects.

We publish the model, not a public rate card - actual rates depend on destination, route class, volume and regulatory cost. See how every Dollu service is priced.

Monthly recurring · per site, user or endpoint
  • DDoS and managed firewall per protected site or circuit
  • SASE and zero trust per user
  • MDR per endpoint or by log volume
  • Assessments and penetration tests as fixed-scope projects
  • 12–36 month terms on managed services
Billing
Monthly recurring in advance; projects invoiced on milestones
Commitment
12–36 months for managed services; none for assessments
Talk to salesActual rates within one business day.
FAQ

MDR & SOC - your questions answered.

The questions customers and carriers ask us most often before they interconnect. If yours is not here, our team answers within one business day.

Still have a question?

Ask our solutions team

Usually not. We ingest from most EDR, firewall, identity, cloud and email platforms and can manage the EDR you already license. Where a tool cannot provide the telemetry needed, we will say so and propose an alternative. Our SIEM/XDR platform is included; you can also send events to your own SIEM in parallel.

Explore

Related services.

Services customers commonly combine with Managed Detection & Response (MDR) & SOC.

All services
Let’s talk

See what is already in your network.

Start with a 30-day monitored assessment: we connect your key log sources, tune detections and report what we find before you commit to a contract.

Abstract globe with connected network lines