Appearance
Arctic Wolf Day-to-Day Operations
Overview
Arctic Wolf is Cirius Group's MDR (Managed Detection and Response) provider. They monitor all managed endpoints, the Azure tenants, and AWS continuously. This guide covers how to work with Arctic Wolf on a day-to-day basis — responding to their investigations, using the Concierge portal, and managing the relationship.
For the monthly health check (agent status, VLC health, connector status) see Arctic Wolf Health Check.
Key fact: Arctic Wolf has act-first authority. They do not need Rory's approval before isolating a device, blocking an IP, or taking a containment action. They will notify us, but they won't wait. This is by design — response time matters in a real incident.
Concierge Portal
URL: Arctic Wolf Concierge — credentials in Keeper → Vendor Accounts → Arctic Wolf
The portal is the primary interface for:
- Viewing open and closed investigations (tickets)
- Communicating with the Arctic Wolf SOC
- Reviewing asset inventory
- Running threat reports
Understanding Arctic Wolf Tickets (Investigations)
Priority Levels
| Priority | What It Means | Arctic Wolf Action | Expected Cirius Response |
|---|---|---|---|
| P1 — Critical | Active breach in progress, ransomware, data exfiltration | Act immediately without approval; page Rory | Respond within 15 minutes; engage the incident response process |
| P2 — High | Credible threat requiring rapid containment | Act within 1 hour; notify Rory | Respond within 1 hour; validate and confirm steps |
| P3 — Medium | Suspicious activity requiring investigation | Investigate; notify Rory within 24h | Review within 24 hours; provide context |
| P4 — Low | Informational, tuning suggestion, advisory | No immediate action | Review and acknowledge |
Ticket Lifecycle
Arctic Wolf detects an event
│
▼
AW SOC investigates (you may not see this phase)
│
▼
AW creates an Investigation ticket in Concierge
│
├── P1/P2: AW takes containment action AND pages Rory
│
└── P3/P4: AW creates ticket, Rory reviews async
│
▼
Rory reviews in Concierge + SecOps
│
▼
Rory responds with context (expected activity, false positive, or confirmed)
│
▼
AW closes the ticket when resolvedArctic Wolf tickets are automatically pushed to SecOps as incidents via the webhook integration. If a SecOps incident exists for an AW ticket, link them together in both systems for full traceability.
Responding to a P1 or P2
When Arctic Wolf pages about a P1 or P2:
Acknowledge immediately — respond in Concierge and by phone/email to the SOC contact. Even if you have no information yet, acknowledge receipt.
Read the ticket — what did AW observe? What action have they taken? (They may have already isolated a device or blocked traffic)
Switch to Incident Response mode — follow Incident Response
Coordinate in real time — Arctic Wolf has a live SOC. Call their 24/7 number (in Keeper → Vendor Accounts → Arctic Wolf Emergency) for voice communication during active incidents. Do not rely on ticket comments for a P1.
Provide context — Arctic Wolf sees telemetry but not everything you know. Tell them:
- Was this a planned change (deployment, maintenance)?
- Was this user or machine expected to do this?
- Any recent changes to the environment?
Do not reverse their containment actions during an active incident without discussing with the AW SOC first. If they isolated a machine, it's isolated for a reason.
Responding to P3/P4 Tickets
Most Arctic Wolf activity is P3/P4 — suspicious but not confirmed. These require context from Cirius to close.
- Review the ticket in Concierge — what did AW flag and why?
- Check SecOps — is there a corresponding incident?
- Investigate the flagged activity:
- Was it expected? (maintenance, new deployment, known service account behavior)
- Was it unexpected but benign? (user doing something unusual but authorized)
- Was it malicious?
- Reply in the Concierge ticket with your finding and close it if benign
- If malicious or uncertain, escalate to P2 treatment
For recurring benign patterns, ask Arctic Wolf to tune the detection (see Tuning below).
Communicating with the Arctic Wolf SOC
In-Ticket Comments
For non-urgent communication, reply in the Concierge ticket. Arctic Wolf SOC analysts monitor ticket comments during business hours and 24/7 for P1/P2.
Always include:
- Whether the activity was expected/authorized
- Relevant context (who the user is, what change was in progress, etc.)
- Whether you want them to take additional action or just close the ticket
Phone / Emergency Contact
For P1/P2 incidents: Arctic Wolf 24/7 SOC number is in Keeper → Vendor Accounts → Arctic Wolf Emergency Contact.
Slack / Teams Integration
Arctic Wolf can post to a Slack or Teams channel for real-time notifications. If this is configured, check that channel for active investigations.
Providing Context for Investigations
Arctic Wolf often needs Cirius context to classify a finding. Common situations:
| AW Finds | Cirius Context Needed | Where to Look |
|---|---|---|
| Unusual admin account activity | Was this Rory doing a planned change? | SecOps CM tickets, Rory's schedule |
| New service installed on a server | Was this a deployment? | GitHub Actions recent deployments |
| Large outbound data transfer | Was this a Veeam backup or DR test? | Veeam email reports, DR test schedule |
| Lateral movement between servers | Was this planned admin work? | Maintenance window in SecOps |
| Off-hours login | Was this Rory or Kevin working late? | Ask the individual |
If you cannot rule out malicious activity after checking, treat it as confirmed and escalate.
Alert Tuning and False Positives
When a recurring alert is confirmed benign, ask Arctic Wolf to tune it — they manage the detection rules on their end.
When to request tuning:
- Same alert fires 3+ times with the same confirmed-benign explanation
- Activity is permanent and expected (not a one-time event)
- The tuning scope is specific (exact account, exact machine, exact behavior)
How to request: Reply in the investigation ticket: "This is expected behavior from [account/machine] because [reason]. Please tune this detection for this specific scope."
Arctic Wolf will confirm the tuning request and apply it. Ask them to document the tuning scope so it can be reviewed at the next annual review.
What NOT to tune:
- Break-glass account activity
- Security tool installation/removal
- Mass account lockouts
- Broad behavioral patterns (these need investigation even if the last few were benign)
Weekly and Monthly Touchpoints
Weekly Threat Summary
Arctic Wolf sends a weekly threat summary email. Review it for:
- Any detections affecting Cirius infrastructure
- Industry threats relevant to healthcare/SMB
- Recommended defensive actions
Quarterly Business Reviews (QBR)
Arctic Wolf schedules a QBR quarterly to review:
- Detection volume and trends
- Open tuning requests
- Coverage gaps
- Upcoming threat landscape changes
Rory attends. Prior to the QBR, pull the quarterly ticket volume from Concierge and review open tuning requests so the conversation is productive.
Annual Coverage Review
Annually, reconcile what Arctic Wolf is monitoring against the CMDB. See Arctic Wolf CMDB Check for the full procedure.
Related Documents
- Arctic Wolf Health Check — monthly agent/connector/VLC verification
- Arctic Wolf CMDB Check — quarterly asset coverage reconciliation
- Incident Response — full IR process when AW escalates a P1/P2
- SecOps Findings Triage — how AW tickets map to SecOps incidents
Document History
| Date | Change | Author |
|---|---|---|
| May 2026 | Initial draft — Concierge portal, priority levels, P1/P2 response flow, P3/P4 review, SOC communication, context provision, alert tuning, weekly/monthly touchpoints. | Rory |