The tooling arrives with the responders. Not after procurement.
The thing that slows a breach investigation is rarely the investigation. It is that nobody can see the estate yet, and buying the thing that would let them see it takes two weeks you do not have.
Through our CrowdStrike partner licensing, Vijilan can stand CrowdStrike Falcon® up in your environment at no license cost for a defined sixty-day engagement window. That covers incident response, digital forensics, breach response and compromise assessment.
You pay for the responders. The platform they arrive with is not a separate purchase, and there is no procurement cycle standing between you and visibility on day one.
At the end of the window the licensing ends and the tooling deprovisions. The investigation is yours to keep: the timeline, the findings, the evidence and the remediation guidance.
What that actually buys you.
See it, the same day
Sensors go out across the estate and the picture assembles while the rollout is still running. Process execution, network connections, file and registry activity, on every host that has come online so far.
Contain while you investigate
Hosts isolated from the network but still reachable by the responder. Accounts disabled, malicious binaries blocked, persistence removed, without waiting to finish the forensics first.
Identity, not just endpoints
Most intrusions that matter involve a working credential. Identity telemetry shows the lateral movement, the privilege escalation and the accounts that need resetting before you hand the estate back.
Keep what you learn
Telemetry lands somewhere you can query it afterwards, so the timeline survives the engagement. Reconstructing an incident from memory three weeks later is how findings become opinions.
Sixty days, and an intent worth saying out loud.
The license runs sixty calendar days from the point it is provisioned, then it deprovisions. An extension of up to four weeks can be requested and is decided case by case, so it is not something to plan around. Your findings, timeline and evidence are yours permanently either way.
And the intent: engagements like this exist to show what the platform does in a real environment, and we would like you to keep it afterwards. That is the arrangement. Mid-incident it is a good one, and there is no obligation at the end of it.
Four engagements. Same licensing arrangement.
Incident response
Active intrusion, ransomware, business email compromise. We deploy, scope the intrusion, contain it, and stay until the environment is yours again.
Digital forensics
What happened, in what order, and what left the building. Timeline reconstruction and evidence handling suitable for insurers, regulators and counsel.
Breach response
The part after containment. Remediation, hardening the path they used, and the documentation your obligations require.
Compromise assessment
Nothing has alarmed, and you want to know whether that is because nothing is there. A time-boxed hunt across the estate for intrusions that never triggered an alert.
Common questions
What does the license actually cost during an engagement?
Nothing for the first sixty days. Through our CrowdStrike partner licensing we can stand Falcon up in your environment at no license cost for a defined sixty-day engagement window, which covers incident response, digital forensics, breach response and compromise assessment. You are paying for the responders, not for the platform they arrive with.
What happens at the end of the sixty days?
The licensing ends and the tooling deprovisions. An extension of up to four weeks can be requested and is decided case by case, so it is not something to plan around. What you keep regardless is the investigation: the timeline, the findings, the evidence and the remediation guidance. If you want the platform to stay, that becomes a normal licensing conversation and we will tell you plainly whether you need it.
So what is the catch?
There is no catch, but there is an intent and it is better said than implied. Engagements like this exist to show what the platform does in a real environment, and we would like you to keep it afterwards. That is the arrangement. When you are mid-incident it is a good one, because the alternative is a procurement cycle you do not have time for, and you are under no obligation at the end of it.
We already run Falcon. Does any of this apply?
The licensing does not, because you already have it. The response does. We run the engagement on the tenant you already own, and where you have Falcon Complete we do not duplicate the managed detection and response: we take the investigation, the forensics and the sources outside the Falcon estate.
Can you work with our insurer or breach counsel?
Yes, and it is usually better if they are in the room early. Evidence handling and reporting are shaped by what your policy and your counsel require, and those requirements are easier to meet while the investigation is running than to reconstruct afterwards.
We are an MSP. Can we bring you into our client’s incident?
Yes, white-label, and we never compete with our partners for their clients. The engagement can run entirely under your brand, which for an MSP mid-incident is usually the point.
Is this the same as a retainer?
No. A retainer buys you a guaranteed place in the queue before anything happens. This is the engagement itself. If you want the queue position as well, that is worth arranging while nothing is on fire, because the day you need it is the worst day to negotiate it.
If it is happening now, stop reading.
Call the hotline. It reaches the 24/7 SOC and it is the fastest thing on this page. If you are planning rather than responding, a compromise assessment is the version of this you run before anything is on fire, and it answers the question most people are actually asking.