Cloud SIEM
The Sumo Logic chain from records to signals to insights, tied to entities: analysts work insights, not individual logs.
For teams that chose a cloud SIEM to avoid running infrastructure but end up with insights nobody works at night. The Fortgale MDR service runs rules and playbooks in your Sumo Logic tenant and contains through the connected tools, at a median TTC of <30 minutes.
The Sumo Logic components the SOC operates. Sumo Logic is SaaS only: if it is not in place yet, licensing and tenant setup are part of the service.
The Sumo Logic chain from records to signals to insights, tied to entities: analysts work insights, not individual logs.
Match, threshold, chain, aggregation, first seen and outlier rules written by Fortgale, with tuning expressions and match lists built on your environment.
Fortgale indicators loaded as a threat intelligence source next to the feeds already included in the tenant, used by rules through threat matching.
Enrichment, notification and containment playbooks in the Automation Service included with Cloud SIEM; with Cloud SOAR, incident management and War Room as well.
AWS CloudTrail, Azure, Google Cloud, Kubernetes, Microsoft 365 and third-party EDR in the same tenant.
Hunting led by Fortgale analysts on AWS IAM abuse, Entra ID compromise and exposed Kubernetes clusters.
A SIEM collects and correlates; it does not decide. Fortgale brings the detection engineering that turns it into a defence: rules built on 287 tracked adversary groups and attack tools, mapped to MITRE ATT&CK and maintained by the Milan SOC, with every alert enriched by proprietary CTI before it reaches the analyst. The data stays in your environment, under your retention. Noise drops by more than 90% by day 30, and once an alert is confirmed the analyst acts through the tools connected to the platform: median TTD <15 minutes, median TTC <30 minutes.
Sumo Logic does not contain on its own: a confirmed insight becomes action through Automation Service or Cloud SOAR playbooks, with integrations to the EDR for isolation, to Active Directory and Entra ID for account blocking and to AWS or Azure for session revocation.
The Automation Service included with Cloud SIEM runs playbooks but does not manage cases: incident management needs Cloud SOAR. At onboarding we agree with you where the analyst approves an action and where the playbook proceeds on its own.
Fortgale rules live in your tenant next to Sumo Logic content, and the 34,000 IOCs a week of Fortgale CTI enter as a threat intelligence source: a connection to attributed infrastructure raises a signal that weighs on the entity involved.
Takeover happens on your Sumo Logic tenant, in the region where you opened it: sources, collectors and retention stay as they are.
Monitoring starts as soon as access is live, and technical onboarding closes in one week: roles, Fortgale rules, match lists, playbooks and response authorisations.
That week also covers cloud and SaaS sources, because without Entra ID sign-in logs or CloudTrail some detections stay blind. On your side: a tenant administrator, permissions on the response integrations and the escalation list.
In April 2026 Fortgale published a case of phishing aimed at investment rounds: around ten key people, executives and finance staff, at a company in the middle of a funding round, approached with emails built on public news about the round. The kit was Rockstar 2FA, a phishing as a service that sits between the victim and Microsoft 365 to capture credentials and MFA tokens. The Fortgale anti-AiTM system flagged the page before compromise: one user had clicked, no unauthorised access happened. The campaign was linked to PhishSurf Nebula.
The article is not about Sumo Logic, but it shows where the game is played: in Microsoft 365 sign-in logs, on the most exposed identities. In Cloud SIEM that is the job of a first seen rule on a sign-in from never-seen infrastructure for an executive, a chain rule linking the link click to the following sign-in and a match list of the accounts to protect first; a playbook can then revoke sessions before the stolen token is used.
Yes. Logs stay in your tenant and in the region chosen when it was opened: in Europe Sumo Logic runs deployments in Frankfurt, Ireland and Zurich, and since June 2026 also on the AWS European Sovereign Cloud. Our analysts work inside your tenant with the agreed roles.
To run containment playbooks the Automation Service included with Cloud SIEM is enough. Cloud SOAR adds incident management, War Room and reporting: you need it if you want the whole case lifecycle to stay in Sumo Logic.
You need a tool that carries out the action. Sumo Logic correlates logs and signals, but host isolation is done by the EDR and session revocation by the identity or cloud provider: playbooks connect them, and where an integration is missing the analyst acts on the tool's console with the agreed permissions.
Sources and history stay in the tenant: only roles, active rules and playbooks change. Fortgale monitoring starts as soon as access is live, and the previous contract can end once technical onboarding is complete, after one week.
Either way: Fortgale operates the Sumo Logic tenant you already have, or provides licensing and setup as part of the service.
We walk through a Sumo Logic insight step by step: the signals that built it, the Fortgale rule that weighed most, the containment playbook and the evidence left in the tenant. Alongside it, the Report on the actors most likely to target your sector.
No nurturing sequences, no auto-replies. One of our analysts calls you back within one business day.
The full Report (executive summary · operational IoCs · technical runbook) is restricted. Share two details and one of our analysts contacts you with access and a short technical briefing.
Response in 30 minutes, containment in 1–4 hours. Even if you are not a Fortgale customer.