Managed Detection & Response // Black Hills Information Security

Defenders, sharpened by the attackers most SOCs miss.

ActiveSOC is built and run by career defenders who spar daily with one of the most seasoned offensive teams in the business.

Steel sharpens steel.

24/7 human-led detection and response, with nothing hidden — every case, every action, visible to you.

“It is rare for a third-party SOC to detect our attack activities.” — the finding that started ActiveSOC

eyes on glass
24/7/365
▲ CRITICAL Ransomware canary tripped — isolated in 31s
● MED Renamed rclone staging data out — killed
● INFO Fleet-wide hunt, fresh C2 infra — 0 hits

Defending community banks to the Fortune 100 since 2008

24/7/365 Coverage

Human-led, every shift of it. Real operators on the floor — not an answering service.

Milliseconds to Detect

That’s the unit we measure in. Not a typo.

Minutes to Respond

Not hours. Not next business day. We track it obsessively.

100% Transparency

Every investigation is visible in your ActiveSOC Portal — including the ones that never need your time.

40 IR Hours Included

Every customer, every year — not an upsell you negotiate mid-incident. Why would you accept less from the team you hired to keep watch?

No Volume Billing

Nobody should be held hostage by ingest-based pricing. Every security-relevant log gets collected — no one here is watching a meter. One annual price, and your telemetry is retained a year minimum, period.

Transparency & Control

No black box. You see everything we see.

Most MDR providers hand you a monthly PDF and a phone number. ActiveSOC hands you complete visibility into your environment and total insight into every case we work — including the dozens we close without ever needing you. Your ActiveSOC Portal is simply the interface to that transparency and control.

ActiveSOC Portal — interactive demo · sample data
ActiveSOC
Dashboards
Asset Inventory
Vulnerabilities
Search
Incident Timelines
Cases
CASM
Cloud Security
Email Security
Endpoint Protection
Deception Systems
Threat Intel
Reports
Hunts Tickets File Exchange Agent Deployment Audit Logs ActiveSOC Pulse Knowledge Base
Acme Federal Credit Union Dashboard
Global Timeframe: 30 days Export to PDF
ACTIVE / TOTAL ASSETS 1,284 / 1,291 +12 this week
TOTAL EVENTS 412M past 30 days
TOTAL CASES 47 44 needed nothing from you
TOTAL TICKETS 12 2 awaiting your reply
Event Count — past 30 days
Operating Systems
Windows
1,020
macOS
148
Linux
123
LOLDrivers Status
CLEAN 1,281 VULNERABLE 3 MALICIOUS 0
Cases Over Time — past 30 days
Data Sources
Endpoint agents 387M
Cloud & identity audit 14.2M
Email 8.4M
Network sensors 2.1M
412M events ingested · retained one year, minimum
Assets Checking In
LAST 7 DAYS · 1,262 LAST 30 DAYS · 22 OVER 30 DAYS · 7
Deception Systems
TOKENS · 24 DEVICES · 3 ACCOUNTS · 12
The interactive ActiveSOC Portal demo lives on bigger screens

Open this page on a laptop to click through the real shape of your ActiveSOC Portal — or take the two-minute video tour below.

Click through the nav — this is the real shape of your ActiveSOC Portal, with sample data. Every case, every asset, every scan: yours to read, including the 44 closures last month that needed nothing from you.

ActiveSOC Portal Walkthrough

See it before you buy it

A guided tour of the ActiveSOC Portal — cases, search, assets, and reports, exactly as customers see them. No sizzle reel. Just the product.

▶ Watch the walkthrough

Every case, not just escalations

Read the full narrative of every investigation — evidence, enrichment, closure notes. Most MDRs summarize. We show our work.

Your telemetry, searchable

Query your own raw endpoint and network data. Saved searches, shareable investigation timelines, bulk export. It’s your data.

Living asset inventory

Every managed endpoint with installed software, services, local users, and persistence mechanisms — diffed continuously.

Attack surface, attacker’s-eye view

Your external footprint, continuously discovered and scanned — with trends, deltas, and per-asset drill-downs.

CVEs you can close, not just count

Org-wide CVE visibility with real disposition tracking — accept, mitigate, reopen. Not a PDF that goes stale.

One-click forensics

Remote forensic triage from any endpoint in minutes — evidence-grade collection, downloadable in the ActiveSOC Portal.

Response authority, shared

Containment is our job — we isolate, block, and remediate for you, around the clock. The same controls sit in your ActiveSOC Portal whenever you want the wheel. Authority you hold; a burden you don’t.

Board-ready reports

On-demand or custom-range reports with full history — polished for the board, structured export for your tooling.

How We Defend

Layered defense, tested by people who get paid to beat it.

Each layer exists because our offensive teams proved something slips past without it. Defense informed by attack — not a checkbox stack.

“I’ve never seen such a complete and fully featured offering.”

David C. Information Services Sector

Cloud security

Agentless, continuous coverage across your entire cloud estate — infrastructure, identity, SaaS, and the AI platforms your teams are already using. We surface the misconfigurations, dormant privileged accounts, exposed data stores, and the toxic combinations that chain into real compromise. Everything lands in one ranked worklist, worked by the same operators who watch your endpoints.

Native in your ActiveSOC Portal.

Cloud infrastructure — AWS, Azure & Google Cloud
Identity — who can reach what, and what shouldn’t exist
SaaS platforms — configuration drift and exposure
AI platforms — what your people are actually using
Compliance posture, assessed per control

Continuous monitoring & response

Host, cloud, identity, and network telemetry analyzed around the clock and retained for a minimum of one year. Risk-based alerting cuts the noise. New detections ship weekly. Lightweight agent deploys fleet-wide in minutes.

Memory & disk hunting

We don’t just watch logs. YARA runs against live process memory and suspicious files on disk, catching packed malware, in-memory implants, and the tooling built specifically to leave clean telemetry behind. Evading the sensor isn’t the same as being invisible.

EDR for AI coding agents

Your developers adopted AI coding agents that read files, run commands, and call APIs on their own. We sit inline in the execution path and inspect every tool call before it runs — known-safe actions auto-approve, policy violations get blocked, anything sensitive routes to a human, at latency nobody notices. Every invocation is logged and queryable, and your ActiveSOC Portal shows which agents are running on which endpoints.

Cyber deception

Decoy systems, credentials, and files placed exactly where attackers hunt — a discipline we’ve practiced and taught for over a decade. When a tripwire fires, it’s high-signal by design.

Network threat hunting

Behavioral analysis of how your systems communicate — beaconing intervals, non-human patterns, unusual egress. Catches what indicator lists miss, including supply-chain compromise from “trusted” sources.

Email security

Inbox-level detection and remediation — business email compromise, credential phishing, and attacks in flight — with mailbox coverage and outcomes visible in your ActiveSOC Portal.

Attack surface monitoring

Continuous discovery and scanning of your internet-facing footprint — new services, exposed assets, leaked credentials, misconfigurations — with real-time alerts when something changes.

Active Directory attack paths

Routine security assessments of the directory that still runs your enterprise — privilege chains, delegation mistakes, and the legacy configurations attackers actually walk. Findings come back mapped as paths: where an attacker starts, and every hop to Domain Admin. Not a config checklist with severity colors.

Adversarial emulation

Our offensive teams attack your environment so our SOC has to prove itself — security stack evaluation, directory-service review, privilege escalation testing — annually, with a written report and findings review.

ALSO INCLUDED
Severity-1 escalation in 30 minutes, day or night
One year of telemetry retention, minimum
Curated threat intelligence integrated into your detections
Cyber range access and three live training classes for up to 10 of your people
Direct access to the full BHIS expert bench
Scheduled SOC review sessions
Continuous Validation

We prove it. Then we keep proving it.

The questions most security programs never answer, we answer on a schedule — with evidence.

“Where do we even start?”

Assessed. Before go-live.

Onboarding opens with a security posture assessment — directory and cloud configuration, telemetry coverage, incident response readiness — capped with a tabletop exercise tailored to your environment.

“Am I sending the right logs?”

Checked. Automatically.

Telemetry coverage gets checked constantly, and gaps get flagged before an attacker finds them. You never have to wonder whether the right data is flowing.

“Is my directory or cloud actually secure?”

Audited. Continuously.

Ongoing posture assessment of your identity infrastructure and cloud estate — attack paths, privilege sprawl, misconfigurations — surfaced in your ActiveSOC Portal, not saved for a quarterly review.

“Do the detections still work?”

Proven. Constantly.

We test our own coverage against live adversary emulation — so detection never silently regresses. When we say we’d catch it, it’s because we just did.

“I’ve got Black Hills, I’m not worried about it.”

Mark L. General Manager, Information Security · Critical Infrastructure & Logistics
Attacks at Software Speed

Ready for attacks that don’t hesitate.

AI-driven offensive tooling identifies, chains, and exploits vulnerabilities faster than any human crew. We’ve spent years building the three disciplines that hold up when the attacker is software.

01

Shrink the surface

Automated attackers prioritize speed and opportunity. We strip away the easy wins first — exposed services, leaked credentials, misconfigurations — so automated scanning comes up short.

02

Tripwire the interior

AI doesn’t hesitate — it scans, exploits, and pivots. Deception turns that speed against it: traps in unmanaged corners, shadow IT, and IoT become the first (sometimes only) indicator something is wrong.

03

Hunt behavior, not signatures

Modern attacks ride trusted infrastructure past indicator lists. We hunt how systems communicate — beaconing, cadence, anomalous egress — so the tell is the behavior itself, not a known-bad address.

The Operators

Defensive operators. Not ticket-takers.

Most MDR hands your risk to a nameless queue. Ours hands it to people you’ll actually meet — at the conferences we run, in the classes we teach, on the phone at 3am. Our operators come up through the same shop that trains offensive teams and teaches the industry — and they hold themselves to standards we hold each other to daily.

Every detection rule, every investigation, every email carries our name. We sweat the details because you can’t afford for us not to.

Meet the team behind ActiveSOC →
// 01

Evidence-backed conclusions. Never guesses dressed up as findings.

// 02

The customer’s security outcome is the measure of everything we do.

// 03

We answer your next question before you have to ask it.

// 04

We don’t wait for the industry to hand us better tooling. We build it.

“I sleep a little better at night knowing you guys are watching.”

Nathan H. IT Manager, Manufacturing
Talk to the SOC

Analysts watch. Operators fight back.

Analysts watch attacks unfold and forward you a summary. Our operators get in the trenches and fight back. Tell us a little about your environment and we’ll show you the real thing, live — every case, every asset, no summary layer.

No lock-in. 45 days’ notice, no cancellation fee, done.
701-484-BHIS (2447)
890 Lazelle Street, Sturgis, SD 57785

Three required fields. A human follows up. No drip campaign unless you ask for one.