SIEM
Central, encrypted collection of logs from firewalls, servers and endpoints; threat detection and alerting through correlation rules.
Managed security & monitoring
Eight modules from SIEM to network and system monitoring — one platform, one console, from setup to alert. Enterprise-grade security operations without building your own SOC.
No sign-up for the demo · Easily integrated into your systems
Modules
Every module runs in the same portal, so you never get lost between screens. Scope follows the plan and add-ons you choose.
Central, encrypted collection of logs from firewalls, servers and endpoints; threat detection and alerting through correlation rules.
Monitoring of CPU, memory, disk, service state and network metrics, with instant alerts when thresholds are crossed.
Automatic discovery of device and software inventory, with device-to-user mapping and lifecycle tracking.
Tamper-evident, encrypted retention of records required under Türkiye's Law No. 5651.
Regular backup, versioning and change (diff) tracking of network and security device configurations.
Assessment and reporting of firewall rule sets for hygiene, compliance and risk.
Active Directory and domain security auditing; detection of privileged accounts and weak configurations.
Scan results and your overall security posture, presented in a single SOC console.
Plans
A fixed plan fee plus a monthly per-device fee. You can see the price right away via the calculator; prices are in USD, invoiced in TRY at the daily rate.
We send you the console login; you monitor whenever you like and make the decisions.
Understand the alert, know the next move.
We watch, you run your business.
CLOUD ADD-ONS — PRICED SEPARATELY FROM THE PLAN
Office 365 Integration — Ingesting Azure AD, Exchange and SharePoint logs into SIEM
Asset Inventory — Inventory software that scales with your device count
5651 Compliant Logging — Statutory record retention, per device
Radar — SOC console — with no device limit
How it works
On your side, setup is a single collector server; the platform and, if you wish, our SOC team handle the rest.
We map your network and log sources together, then pin down the scope and the quote.
A single collector (proxy) is installed on your network. The guided setup takes under an hour in most environments.
Log sources are connected, monitoring and correlation rules are enabled, and your console access is opened.
Depending on your plan, you follow alerts in the console or our 24/7 SOC team watches and notifies you; service levels are measured and reported every month.
Security & compliance
Roles defined by a data processing agreement; processing only on instruction and for the stated purpose.
All records are kept on in-country infrastructure; no data leaves the country at runtime.
Customer data is kept separate through row-level security (RLS) in the database and role-based access control.
Logs travel over an encrypted channel; 5651 records are sealed to be tamper-evident and verifiable.
FAQ
A single virtual server is enough. The voosec proxy installed on it collects your log sources and forwards them to the center over one encrypted channel; agents are required for SIEM and device-monitoring areas, while for your other systems collection also works via syslog/WMI/API.
On our infrastructure in Türkiye. Customer data is isolated at the row level; the roles and obligations under KVKK are defined by a contract annex (data processing agreement).
Yes. Common firewalls (such as FortiGate, Sophos and Check Point), Windows/Linux servers, network devices and the Office 365 environment are supported.
A fixed plan fee plus a monthly per-device/agent fee. We clarify the scope together and quote the same day; prices are in USD, invoiced in TRY at the daily rate.
We work in 12- or 24-month terms; a discount applies to the 24-month commitment.
Contact
Enter your device count and log sources in the calculator to see the monthly and setup fees instantly. We'll pick the right plan together; if you prefer, tour the platform in the demo first.
email [email protected]
phone 0212 222 34 56
company VOO Bilişim Çözümleri Ltd. Şti.
location Ataköy Towers A Blok Kat:1 No:48 34156 Bakırköy İstanbul
Period: 1–31 August 2026 · Report no VS-BR-2608-014 · Scope: 214 assets, 6 sites, 19 log sources · Issued: 8 September 2026
| # | Asset | Finding | Severity | Status | Engineer | Closed | Effort (h) | Class | Source | Detected | Confidence | Recommended action |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | VPN portal · authentication | 4,212 failed authentication attempts from three external addresses; 38 different usernames tried. One account succeeded and the session lasted 90 seconds. | CRITICAL | Closed | S.K. | 30 Aug 2026 | 8 | Brute force — successful access | SIEM correlation | 29 Aug 2026 | confirmed | Suspend the account, reset the password and review the session records. Enable account lockout and source-country restriction on the portal. |
| 2 | SRV-DC-02 · security log | The security event log was cleared outside working hours. The 40 minutes preceding the clear event are no longer readable. | CRITICAL | In progress | M.A. | — | 6 | Audit trail cleared | SIEM correlation | 30 Aug 2026 | confirmed | Restrict the clear-log privilege and stream logs off the host in real time. A single local copy is not an audit trail. |
| 3 | Privileged account · 3 servers | The same administrator account opened sessions on three servers between 02:40 and 03:10. There is no change record or ticket reference. | HIGH | Closed | S.K. | 31 Aug 2026 | 4 | Out-of-hours privileged access | SIEM correlation | 29 Aug 2026 | to verify | Confirm with the account owner. If it was planned maintenance a change record is required; if not, start incident response. |
| 4 | User account · remote access | The same account signed in from two different countries 11 minutes apart. The distance cannot be covered physically. | HIGH | Closed | E.T. | 1 Sep 2026 | 3 | Impossible travel | SIEM correlation | 30 Aug 2026 | to verify | Verify with the user; personal VPN use is a common false-positive source. If it cannot be explained, reset the password. |
| 5 | SRV-APP-04 · service records | Three Windows services created and deleted six minutes later, within one night. A classic persistence and clean-up pattern. | HIGH | In progress | M.A. | — | 8 | Persistence indicator | SIEM correlation | 31 Aug 2026 | probable | Capture memory and disk images before isolating the server. A backup agent's install behaviour can produce the same pattern — rule that out first. |
| 6 | Client · outbound connection | 14 GB transferred out from a single client within 36 hours. The destination address belongs to none of the corporate cloud providers. | HIGH | In progress | E.T. | — | 6 | Unusual data transfer | SIEM correlation | 31 Aug 2026 | to verify | Identify the destination and the process. It may be a legitimate backup tool; if not, treat it as data exfiltration. |
| 7 | Domain · 62 accounts | Sixty-two accounts each saw a single failed sign-in, all within a four-minute window and all from the same source. A password-spraying pattern. | MEDIUM | Closed | S.K. | 29 Aug 2026 | 3 | Password spraying | SIEM correlation | 28 Aug 2026 | confirmed | Block the source address. Account lockout thresholds are ineffective against this pattern; source-based rate limiting is required. |
| 8 | Mail gateway | 27 targeted phishing messages aimed at administrator accounts were quarantined; two reached users and one was clicked. | MEDIUM | Closed | M.A. | 2 Sep 2026 | 4 | Phishing — clicked | SIEM correlation | 30 Aug 2026 | confirmed | Review the clicking user's sessions and reset their password. Tighten the gateway rule on the sender domain. |
| 9 | SRV-DC-01 · 10.20.10.4 | One of the domain's two controllers runs a server release whose vendor support has ended. It no longer receives security updates. | CRITICAL | Closed | M.A. | 4 Sep 2026 | 40 | Domain controller on end-of-life OS | AD audit module | 28 Aug 2026 | confirmed | Move to a supported release. Standing up a new controller and transferring FSMO roles is preferable to an in-place upgrade. |
| 10 | SYSVOL · 3 group policies | Passwords embedded in group policies sit in the SYSVOL share. Any authenticated user in the domain can read and decrypt them. | CRITICAL | Closed | M.A. | 1 Sep 2026 | 4 | Password embedded in group policy | AD audit module | 28 Aug 2026 | confirmed | Remove the preference entries, then change the passwords of the affected accounts. Removal alone is not sufficient. |
| 11 | Two directory sync accounts | The sync accounts hold the right to pull every password hash in the domain. One has not signed in for 190 days. | CRITICAL | In progress | S.K. | — | 3 | Privileged right — directory replication | AD audit module | 28 Aug 2026 | confirmed | Confirm which sync server is live; disable the dormant account, observe for 30 days, then delete it. |
| 12 | Kerberos master key account | The Kerberos master key has not been changed for 4,850 days. A hash leaked in the past can still issue valid tickets today. | CRITICAL | In progress | S.K. | — | 4 | Kerberos key hygiene | AD audit module | 28 Aug 2026 | confirmed | Change the password twice, leaving at least one replication cycle between the two. A single change provides no protection. |
| 13 | Privileged group — 4 accounts | Two of the four members of the privileged group are service accounts; one has a password older than 900 days. | HIGH | Closed | M.A. | 6 Sep 2026 | 4 | Privileged account management | AD audit module | 28 Aug 2026 | confirmed | Remove the service accounts from the privileged group and delegate only the rights they need. Issue separate admin identities for human accounts. |
| 14 | SRV-FILE-02 · 10.20.10.31 | An obsolete SMB version is enabled on the file server, exposing it to interception and downgrade attacks. | HIGH | Closed | E.T. | 2 Sep 2026 | 3 | Obsolete protocol enabled | Network vulnerability scanner | 28 Aug 2026 | confirmed | Remove SMBv1 and enforce signing. Confirm legacy client dependencies from the inventory first. |
| 15 | SRV-APP-07 · 10.20.20.15 | The database engine on the application server has not been patched for 14 months; 23 known vulnerabilities are open, three of them allowing remote code execution. | HIGH | In progress | E.T. | — | 6 | Patch backlog — database | Vulnerability detection engine | 30 Aug 2026 | confirmed | Apply the cumulative update in a maintenance window. Take a full backup and prepare a rollback plan beforehand. |
| 16 | Edge firewall pair | The management interface is reachable from the WAN side with no source restriction. | HIGH | Closed | S.K. | 30 Aug 2026 | 2 | Management interface exposed | Configuration audit | 29 Aug 2026 | confirmed | Restrict management access to the internal network and VPN; move it to a dedicated management interface where possible. |
| 17 | 12 clients · branch network | On twelve clients the endpoint protection signature database is more than 45 days old. On five, the service has stopped. | HIGH | Closed | E.T. | 5 Sep 2026 | 5 | Endpoint protection out of date | Monitoring platform | 30 Aug 2026 | confirmed | Start the stopped services and verify access to the update source. An egress rule on the branch network may be blocking it. |
| 18 | SRV-BCK-01 · 10.20.10.60 | The backup server has not produced a successful backup for 22 days. Alert e-mails are going to an invalid address. | HIGH | In progress | M.A. | — | 6 | Backup chain broken | Monitoring platform | 29 Aug 2026 | confirmed | Run the backup job manually to capture the error; correct the notification address and schedule a restore test. |
| 19 | Virtualisation management server | The default administrator account is enabled on the management interface and multi-factor authentication is not configured. | HIGH | Closed | S.K. | 3 Sep 2026 | 3 | Default credential | Configuration audit | 29 Aug 2026 | confirmed | Rename the default account, create per-person administrator accounts and enforce multi-factor authentication. |
| 20 | SW-CORE-01 / 02 · core | The core switch pair is stacked over a single link. A break on that link risks a split-brain condition. | MEDIUM | Open | E.T. | — | 4 | Network redundancy | Configuration audit | 27 Aug 2026 | to verify | Run the second stack link over a different physical path. A maintenance window is required. |
| 21 | 9 servers · data centre | Nine servers use different time sources. The largest drift is 4 minutes 12 seconds. | MEDIUM | Closed | E.T. | 31 Aug 2026 | 3 | Time synchronisation | Monitoring platform | 30 Aug 2026 | confirmed | Point every server at a single internal time source. This is required for log correlation and for Kerberos. |
| 22 | SRV-WEB-03 · 10.20.20.41 | Directory listing is enabled on the web server and configuration backups can be downloaded. | MEDIUM | Closed | M.A. | 29 Aug 2026 | 1 | Information disclosure | Network vulnerability scanner | 28 Aug 2026 | confirmed | Disable directory listing and move backup files out of the document root. |
| 23 | Wireless controller | There is no layer 2 separation between the guest wireless network and the corporate network. | MEDIUM | In progress | S.K. | — | 5 | Network segmentation | Configuration audit | 27 Aug 2026 | to verify | Move guest traffic to a separate VLAN and a separate egress, and block access to corporate resources. |
| 24 | 31 clients | On thirty-one clients the browser is three major versions behind. | MEDIUM | In progress | E.T. | — | 4 | Patch backlog — client | Vulnerability detection engine | 30 Aug 2026 | confirmed | Update through central deployment and enable the automatic update policy. |
| 25 | SRV-PRN-01 · 10.20.10.22 | The print spooler service is enabled on a server other than a domain controller but is not in use. | MEDIUM | Closed | M.A. | 30 Aug 2026 | 1 | Unnecessary service | Configuration audit | 29 Aug 2026 | confirmed | Disable the service if it is not in use. It widens the attack surface for no benefit. |
| 26 | Storage array · management | The storage management interface is accessed over an unencrypted protocol. | MEDIUM | Closed | S.K. | 1 Sep 2026 | 2 | Unencrypted management protocol | Network vulnerability scanner | 28 Aug 2026 | confirmed | Enforce HTTPS and close the plaintext port. Vendor documentation confirms support. |
| 27 | 4 switches · branch | Four switches run the same vendor firmware release, which carries a known privilege-escalation vulnerability. | MEDIUM | Open | E.T. | — | 6 | Device firmware out of date | Vulnerability detection engine | 30 Aug 2026 | confirmed | One root cause, four devices. Update them in sequence and verify connectivity after each one. |
| 28 | Domain users | The password policy enforces complexity but sets the minimum length at 7 characters. | MEDIUM | Open | M.A. | — | 2 | Password policy | AD audit module | 28 Aug 2026 | confirmed | Raise the minimum to at least 12 characters and enable breached-password checking. |
| 29 | SRV-MAIL-01 · published record | The e-mail authentication record for the domain is in monitoring mode only; spoofing is not blocked. | MEDIUM | In progress | S.K. | — | 3 | E-mail authentication | Configuration audit | 27 Aug 2026 | confirmed | Move the records to quarantine and then to reject. Report data should be observed for two weeks. |
| 30 | 17 clients | Disk encryption is disabled on seventeen clients, two of which are portable devices. | MEDIUM | Open | E.T. | — | 5 | Disk encryption | Monitoring platform | 30 Aug 2026 | confirmed | Enable encryption starting with the portable devices and escrow the recovery keys in the directory. |
| 31 | Edge router | Three unused services are open on the router; two carry known overflow vulnerabilities. | MEDIUM | Closed | S.K. | 2 Sep 2026 | 2 | Unnecessary service | Network vulnerability scanner | 28 Aug 2026 | confirmed | Close the unused services. No outage is expected, but it should still be done in a maintenance window. |
| 32 | Inventory · 23 devices | Twenty-three devices appear in the inventory without an owner; no responsible unit is assigned. | LOW | In progress | M.A. | — | 4 | Inventory data quality | Asset inventory | 31 Aug 2026 | confirmed | Assign ownership. Unowned assets are the most common reason findings take longer to close. |
| 33 | Log sources | Two log sources have sent no data for 11 days while the source systems are up. | LOW | Closed | E.T. | 2 Sep 2026 | 2 | Log source silent | Monitoring platform | 31 Aug 2026 | confirmed | Verify the forwarding configuration and the network path. A silent source creates a blind spot in event visibility. |
| 34 | 6 servers | Disk usage has passed 85% on six servers; two are trending to fill within 30 days. | LOW | Open | E.T. | — | 3 | Capacity trend | Monitoring platform | 31 Aug 2026 | confirmed | Archive old logs as a short-term measure and produce a capacity plan for the two servers. |
| 35 | Domain · 14 accounts | Fourteen user accounts have not signed in for more than 180 days. | LOW | In progress | M.A. | — | 2 | Dormant account | AD audit module | 28 Aug 2026 | confirmed | Confirm with HR, disable them, and delete after 60 days. |
| 36 | Certificate inventory | Four internal certificates expire within 45 days; the renewal owner of two is unclear. | LOW | Closed | S.K. | 3 Sep 2026 | 2 | Certificate lifetime | Configuration audit | 31 Aug 2026 | confirmed | Assign a renewal owner and automate expiry monitoring. |