We bring the same detection engineering discipline we apply to private-sector SOC environments to public-sector IT and security programs — tuning the platforms an agency already operates, closing telemetry gaps, and translating technical detection data into reporting that leadership and oversight bodies can act on.
NIST CSF 2.0 organizes a security program around six functions — Govern, Identify, Protect, Detect, Respond, and Recover. Here's where our engineering work concentrates:
Logging-gap assessments, telemetry validation, and detection coverage analysis to map what's actually visible.
AV and endpoint policy optimization that strengthens defenses without disrupting legitimate operations.
EDR and SIEM tuning, custom YARA rules, and behavioral detection logic mapped to MITRE ATT&CK — including identity-based threats like credential misuse.
Correlation logic and alert tuning that accelerates investigation and shortens time to action.
Govern and Recover sit outside our direct engineering scope — but our leadership-ready reporting is built to support Govern-level risk decisions. See For Management.
We tune the platforms an agency already owns — we don't sell a new box or a managed-SOC subscription on top of it.
A repeatable six-stage lifecycle — Discover, Identify, Engineer, Validate, Measure, Evolve. See the full process →
Dashboards built to give oversight bodies and agency leadership clear visibility without raw telemetry.
Any dashboard or reporting interface we build is designed with WCAG 2.0 AA accessibility in mind from the start.
WN Mackenjas has delivered detection engineering support as a subcontractor to Gray Tier Technologies, LLC — a government contracting firm — since 2022, continuing today through TDI following the two companies' 2025 merger. The engagement supports a government agency's security program: tuning existing detection technologies to improve alert fidelity, close telemetry gaps, and strengthen threat visibility.
Client agency reference and additional detail available upon request, subject to agency authorization.
Our detection engineering methodology is structured around the control families in NIST SP 800-53 and the functions of the NIST Cybersecurity Framework 2.0. Public-facing dashboards and reporting interfaces we deliver are designed with WCAG 2.0 AA accessibility in mind.
This describes our engineering approach and methodology — it is not a claim of formal certification, independent audit, or an authorization to operate. Confirm any compliance representations against the specific solicitation's requirements before submission.