ScopeWise for security consultancies and MDR providers
Two of the assessments clients ask for most, detection coverage and code security, are usually delivered as a spreadsheet and a deck built by hand for every engagement. ScopeWise generates both from scored data, so the second engagement costs the same effort as the tenth.
The deliverable problem
A SOC maturity or detection-coverage engagement ends with a mapping of the client's rules to MITRE ATT&CK, a coverage figure per tactic, a gap list and a roadmap. Built by hand, the mapping depends on who did it, the coverage figure is hard to defend when the client asks how not-applicable was decided, and none of it survives the next rule change.
Code review engagements have the same shape: raw scanner output on one side, a client who needs verified findings, exploit chains and a fix order on the other, and a consultant in between turning one into the other by hand.
What ScopeWise produces for each engagement
MITRE ATT&CK coverage assessment
Upload the rule export and a one-workbook environment inventory; get coverage by tactic and technique, derived and declared not-applicable reported separately, ranked gaps and a 90-day roadmap.
Product detailsBoard deck, tracker and Navigator layer
The PPTX briefing deck, the XLSX tracker with reference KQL for Sentinel gaps, and an ATT&CK Navigator layer are generated from the same scored data, so the numbers match everywhere.
Code security review
Run the open-source scanner on your side, upload findings only, and get a severity-ranked register, exploit chains and the fewest fixes that break every chain.
Product detailsRepeat runs and trend
Connect Sentinel or Splunk read-only for scheduled re-runs, and show the client what improved and what regressed since the last assessment.
Honest by construction
Coverage numbers are computed by code, never by a language model. The report always shows two figures, your client's own rules and their tooling's native claims, and never merges them. Coverage means a detection exists; detection strength is reported alongside it. Every not-applicable technique carries its reason. The scanner's findings are triage candidates for your reviewer, not a completed assessment, and the page says so.
Your client's data
No raw logs and no source code are uploaded. Rule metadata and environment inventory only for the coverage assessment; the findings file only for the code review. SIEM credentials are encrypted with AES-256-GCM, write-only after saving, and every connection is read-only. Read the privacy policy.
FAQ
Can we white-label the deliverables?
The PPTX and XLSX exports are editable files, so you can add your own cover and branding before delivery. ScopeWise does not currently offer a fully white-labeled portal.
Which SIEMs are supported?
Microsoft Sentinel and Splunk have live read-only connectors. Any other SIEM works from a file export in xlsx, csv, pdf or docx.
Does the client need a ScopeWise account?
No. The consultant runs the assessment and delivers the exports. Client accounts can be added to an organization if you want them to view results directly.
Is this a substitute for a red-team or purple-team exercise?
No. ScopeWise measures whether detections exist and how strong they look on paper. Validating that they fire is what a purple-team exercise is for, and the gap list is a good place to start one.