Skip to content
Cyber Security

Threat Intelligence & Security Monitoring

Curated, telecom-aware threat intelligence and a 24×7 monitoring tier that tells you what is happening - brand, domain and dark-web watch, vulnerability intelligence and SIEM-as-a-service with compliant log retention.

Threat Intelligence & Security Monitoring - Dollu
  • 24×7

    Analyst monitoring

  • 50+

    Curated intel sources

  • 1–7 yrs

    Compliant log retention

Overview

What is Threat Intelligence & Security Monitoring?

Most organisations do not lack security data; they lack someone watching it and context to know what matters. Dollu’s Threat Intelligence & Security Monitoring service provides both: curated intelligence feeds tuned for carriers, service providers and connected enterprises, and a 24×7 monitoring tier in which our analysts watch your logs, alert you to what is real and hand you the evidence to act. It sits deliberately below full Managed Detection & Response, for teams that want to keep response in-house but need eyes on the estate around the clock.

Our intelligence is different because of where we sit. Dollu terminates billions of voice minutes a year, exchanges SMS with 800+ operator connections and scrubs DDoS traffic across a 1.4 Tbps backbone, so we see SIP scanners, IRSF number ranges, SS7 and Diameter probing, smishing infrastructure and SIM-swap patterns as they emerge, hours or days before they appear in generic feeds. We blend that first-party telemetry with commercial, open-source and government CERT sources into 50+ curated feeds, de-duplicated, confidence-scored and delivered over STIX/TAXII, API or directly into your SIEM and firewalls.

Around the feeds we monitor the things attackers target before they touch your network: your brand, domains and executives. Typosquat and look-alike domain registrations, phishing kits impersonating your login pages, fake apps, leaked credentials on paste sites and dark-web forums, and mentions of your data in ransomware leak sites are surfaced with takedown support. Vulnerability intelligence prioritises CVEs against your actual asset inventory and known exploitation, so patch cycles focus on the 5% of vulnerabilities that attackers are actually using.

SIEM-as-a-service completes the picture. We host the platform, connect your log sources, cloud accounts, endpoints, firewalls, SBCs and identity providers, build correlation use cases and retain logs for one to seven years in your chosen jurisdiction to satisfy PCI-DSS, ISO 27001, SOC 2, GDPR and Indian regulatory requirements. Analysts triage alerts 24×7, notify you within 15 minutes for critical events and deliver weekly intelligence briefs and monthly reports. When you are ready to outsource response as well, the same platform upgrades to MDR without re-onboarding.

Why Dollu

Why choose Dollu for threat intel & soc.

The advantages of buying from a carrier that owns its network, interconnects and operations - rather than a reseller.

  • Intelligence you can act on

    Every indicator carries source, confidence, first-seen date and recommended action; noisy or expired indicators are aged out automatically so your firewalls and SIEM rules stay clean.

  • Know when your brand is being abused

    Look-alike domains, phishing kits and fake apps are typically found within hours of registration, giving you time to warn customers and initiate takedowns before campaigns launch.

  • Patch what is exploited, not everything

    Vulnerabilities are ranked by real-world exploitation, exposure and business criticality, shrinking a backlog of thousands into a weekly list your team can actually complete.

  • Cover nights and weekends without hiring

    Our analysts watch your SIEM around the clock and call your on-call engineer with a triaged, evidence-backed alert rather than a raw notification.

  • Retention that satisfies auditors

    Immutable, searchable log archives with documented chain of custody in India, the EU, the US or Singapore, mapped to the retention clauses of PCI-DSS, ISO 27001, SOC 2 and sector regulators.

Capabilities

Capabilities in detail.

Everything included with Threat Intelligence & Security Monitoring - the platform features, options and controls you get from day one.

  1. 01

    Curated threat intelligence feeds

    50+ commercial, open-source, CERT and first-party sources normalised into IP, domain, URL, hash and TTP indicators with confidence scoring, expiry and false-positive suppression.

  2. 02

    Telecom and network abuse intelligence

    Indicators derived from Dollu’s voice, SMS, signalling and DDoS platforms: SIP scanning sources, IRSF and Wangiri number ranges, smishing URLs and sender IDs, SS7/Diameter probing origins and botnet C2 seen on our backbone.

  3. 03

    Brand and domain monitoring

    Continuous watch on new domain registrations, certificate transparency logs, app stores and social platforms for impersonation of your brands, with evidence packs and registrar or host takedown requests.

  4. 04

    Dark-web and credential-leak monitoring

    Monitoring of criminal forums, marketplaces, Telegram channels, paste sites and ransomware leak sites for your domains, employee credentials, customer data, source code and executive names.

  5. 05

    Vulnerability intelligence

    CVE enrichment with exploit availability, active exploitation reports and vendor advisories, matched against your asset inventory or scanner output to produce a prioritised remediation queue.

  6. 06

    24×7 security monitoring

    Analysts triage SIEM alerts continuously, suppress false positives, escalate genuine events with context and recommended actions, and track every case to closure in a shared portal.

  7. 07

    SIEM-as-a-service

    Cloud-hosted SIEM with connectors for syslog, Windows and Linux agents, AWS, Azure, GCP, Microsoft 365, EDR, firewalls, SBCs and identity providers; use-case library tuned to your environment.

  8. 08

    Compliance log retention and reporting

    Hot search for 90 days, cold immutable archive for one to seven years, WORM option, regional data residency and audit-ready reports for PCI-DSS, ISO 27001, SOC 2, GDPR and TRAI/DoT obligations.

  9. 09

    Integration and automation

    STIX 2.1/TAXII 2.1, MISP, JSON API and webhooks; automatic blocklist push to supported firewalls, SASE and SMS firewalls; ticket creation in ServiceNow, Jira and email.

How it works

How it works.

From first conversation to live traffic - a tracked, engineer-led onboarding with a named owner at every step.

  1. Step 01

    Scope

    Agree the brands, domains, executives, IP ranges and log sources in scope, notification contacts, severity definitions and the retention period and jurisdiction you require.

  2. Step 02

    Connect

    Provision the SIEM tenant and connectors, enable feed delivery to your security tools over STIX/TAXII or API and start brand and dark-web monitoring immediately.

  3. Step 03

    Tune

    Two to four weeks of baselining: correlation use cases are enabled, thresholds set, known-good sources whitelisted and the notification matrix tested with you end to end.

  4. Step 04

    Monitor and report

    24×7 analyst monitoring goes live with weekly intelligence briefs, monthly service reports and quarterly reviews of coverage, log sources and emerging threats.

Use cases

Who uses this and why.

Typical deployments across carriers, enterprises, platforms and contact centres.

  • Carriers, MVNOs and ISPs

    Early warning on SIP scanning, IRSF ranges, signalling probes and smishing infrastructure, fed directly into SBCs, SMS firewalls and border routers.

  • Banks, fintechs and payment providers

    Phishing-domain and credential-leak detection, PCI-DSS log retention and 24×7 monitoring of core banking and payment gateway logs.

  • E-commerce and consumer brands

    Fake app, look-alike domain and social impersonation takedowns protecting customers during peak sales periods.

  • Enterprises with an in-house security team

    Overnight and weekend coverage plus curated intelligence for a team that wants to keep investigation and response in its own hands.

  • Public sector and critical infrastructure

    Government CERT feed integration, long-term log retention and monitoring aligned to national cyber-security directives.

  • MSPs and resellers

    White-label intelligence feeds and monitoring delivered per end-customer tenant with consolidated reporting for the partner.

Specifications

Technical & commercial specifications.

Key parameters at a glance. Ask us for the full service description and SLA document.

Intel sources50+ commercial, OSINT, CERT and Dollu first-party voice/SMS/DDoS telemetry
Feed formatsSTIX 2.1 / TAXII 2.1, MISP, JSON REST API, CSV, webhook push
Monitoring24×7 analyst triage; critical notification ≤ 15 min; case portal
SIEM connectorsSyslog, agents, AWS, Azure, GCP, M365, EDR, firewalls, SBCs, IdPs
IngestionFrom 10 GB/day to multi-TB/day per tenant
Retention90 days hot; 1–7 years immutable archive; WORM option
Data residencyIndia, EU, US or Singapore; single-tenant option
Brand monitoringDomains, certificates, app stores, social, dark web; takedown support
ReportingWeekly intel brief, monthly service report, quarterly review
Support24×7 SOC; P1 response ≤ 15 min; named account manager
Pricing model

How Security is priced.

Security services are priced per protected site or circuit, per user or per endpoint - and MDR by endpoint count or log volume. Assessments and penetration tests are fixed-scope projects.

We publish the model, not a public rate card - actual rates depend on destination, route class, volume and regulatory cost. See how every Dollu service is priced.

Monthly recurring · per site, user or endpoint
  • DDoS and managed firewall per protected site or circuit
  • SASE and zero trust per user
  • MDR per endpoint or by log volume
  • Assessments and penetration tests as fixed-scope projects
  • 12–36 month terms on managed services
Billing
Monthly recurring in advance; projects invoiced on milestones
Commitment
12–36 months for managed services; none for assessments
Talk to salesActual rates within one business day.
FAQ

Threat Intel & SOC - your questions answered.

The questions customers and carriers ask us most often before they interconnect. If yours is not here, our team answers within one business day.

Still have a question?

Ask our solutions team

This service detects, enriches and notifies; your team decides and acts. MDR adds our analysts taking containment actions on your endpoints and network under agreed authority. Many customers start here to gain 24×7 coverage and intelligence while retaining control, then move to MDR later. Because both run on the same platform, the upgrade requires a change of scope, not a new onboarding project.

Let’s talk

See what we already know about your attack surface.

Send us your primary domains and brand names and we will return a complimentary exposure snapshot covering look-alike domains, leaked credentials and open vulnerabilities.

Abstract globe with connected network lines