Detection and monitoring EU-developed

Sekoia Defend

Cloud security operations product that ingests telemetry, applies detection rules, supports alert and case investigation, and runs automated playbooks.

By Sekoia · France

EU-developed

The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.

At a glance

Recorded facts
Response workflow
Detection and monitoring
Developer or maintainer
Sekoia
Recorded country
France
Product model
Commercial
Deployment
SaaS
Software license
Commercial license; full terms not publicly verified
Upstream status
Active
Evidence class
EU-developed

What the sources establish

Origin note

Built by Sekoia.io SAS, a French security software company with its registered office in Rennes.

Reported capabilities

  • Collects logs from endpoints, cloud services, networks and applications.
  • Applies detection rules and provides alert triage and case management.
  • Runs playbooks for enrichment and response.

Scope and limits

Sekoia hosts the core platform; on-premises playbook runners do not imply an on-premises Defend product. Reveal and Elevate are dependent add-ons. Full product license terms were not publicly verified.

Inspect the research evidence 5 source observations
  1. identity / capabilities

    Sekoia documentation identifies Defend as a core XDR product with log collection, detection, triage, case investigation and playbooks.

    Read source
  2. origin

    The company describes its founding team and says they built a European cybersecurity software company and platform.

    Read source
  3. country

    The legal notice identifies Sekoia.io SAS and its registered office in Rennes, France.

    Read source
  4. license / deployment

    Official subscription documentation says Defend is licensed as a distinct paid product and identifies subscription tiers. It does not publish customer software rights or full product terms.

    Read source
  5. maintenance

    Current documentation describes the active Defend product and current platform features; no ceased-support notice appears.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

Sigma Capability

Applies Sigma detections and correlation rules to normalized event streams. The documented syntax includes Sekoia-specific time modifiers, so rules may need adjustment when moved to another engine.

Put the tool in context.

Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.

From Sigma rule to a tested detection