Skip to content

Arctic Wolf Day-to-Day Operations

Overview

Arctic Wolf is Cirius Group's MDR (Managed Detection and Response) provider. They monitor all managed endpoints, the Azure tenants, and AWS continuously. This guide covers how to work with Arctic Wolf on a day-to-day basis — responding to their investigations, using the Concierge portal, and managing the relationship.

For the monthly health check (agent status, VLC health, connector status) see Arctic Wolf Health Check.

Key fact: Arctic Wolf has act-first authority. They do not need Rory's approval before isolating a device, blocking an IP, or taking a containment action. They will notify us, but they won't wait. This is by design — response time matters in a real incident.


Concierge Portal

URL: Arctic Wolf Concierge — credentials in Keeper → Vendor Accounts → Arctic Wolf

The portal is the primary interface for:

  • Viewing open and closed investigations (tickets)
  • Communicating with the Arctic Wolf SOC
  • Reviewing asset inventory
  • Running threat reports

Understanding Arctic Wolf Tickets (Investigations)

Priority Levels

PriorityWhat It MeansArctic Wolf ActionExpected Cirius Response
P1 — CriticalActive breach in progress, ransomware, data exfiltrationAct immediately without approval; page RoryRespond within 15 minutes; engage the incident response process
P2 — HighCredible threat requiring rapid containmentAct within 1 hour; notify RoryRespond within 1 hour; validate and confirm steps
P3 — MediumSuspicious activity requiring investigationInvestigate; notify Rory within 24hReview within 24 hours; provide context
P4 — LowInformational, tuning suggestion, advisoryNo immediate actionReview and acknowledge

Ticket Lifecycle

Arctic Wolf detects an event


AW SOC investigates (you may not see this phase)


AW creates an Investigation ticket in Concierge

    ├── P1/P2: AW takes containment action AND pages Rory

    └── P3/P4: AW creates ticket, Rory reviews async


    Rory reviews in Concierge + SecOps


    Rory responds with context (expected activity, false positive, or confirmed)


    AW closes the ticket when resolved

Arctic Wolf tickets are automatically pushed to SecOps as incidents via the webhook integration. If a SecOps incident exists for an AW ticket, link them together in both systems for full traceability.


Responding to a P1 or P2

When Arctic Wolf pages about a P1 or P2:

  1. Acknowledge immediately — respond in Concierge and by phone/email to the SOC contact. Even if you have no information yet, acknowledge receipt.

  2. Read the ticket — what did AW observe? What action have they taken? (They may have already isolated a device or blocked traffic)

  3. Switch to Incident Response mode — follow Incident Response

  4. Coordinate in real time — Arctic Wolf has a live SOC. Call their 24/7 number (in Keeper → Vendor Accounts → Arctic Wolf Emergency) for voice communication during active incidents. Do not rely on ticket comments for a P1.

  5. Provide context — Arctic Wolf sees telemetry but not everything you know. Tell them:

    • Was this a planned change (deployment, maintenance)?
    • Was this user or machine expected to do this?
    • Any recent changes to the environment?
  6. Do not reverse their containment actions during an active incident without discussing with the AW SOC first. If they isolated a machine, it's isolated for a reason.


Responding to P3/P4 Tickets

Most Arctic Wolf activity is P3/P4 — suspicious but not confirmed. These require context from Cirius to close.

  1. Review the ticket in Concierge — what did AW flag and why?
  2. Check SecOps — is there a corresponding incident?
  3. Investigate the flagged activity:
    • Was it expected? (maintenance, new deployment, known service account behavior)
    • Was it unexpected but benign? (user doing something unusual but authorized)
    • Was it malicious?
  4. Reply in the Concierge ticket with your finding and close it if benign
  5. If malicious or uncertain, escalate to P2 treatment

For recurring benign patterns, ask Arctic Wolf to tune the detection (see Tuning below).


Communicating with the Arctic Wolf SOC

In-Ticket Comments

For non-urgent communication, reply in the Concierge ticket. Arctic Wolf SOC analysts monitor ticket comments during business hours and 24/7 for P1/P2.

Always include:

  • Whether the activity was expected/authorized
  • Relevant context (who the user is, what change was in progress, etc.)
  • Whether you want them to take additional action or just close the ticket

Phone / Emergency Contact

For P1/P2 incidents: Arctic Wolf 24/7 SOC number is in Keeper → Vendor Accounts → Arctic Wolf Emergency Contact.

Slack / Teams Integration

Arctic Wolf can post to a Slack or Teams channel for real-time notifications. If this is configured, check that channel for active investigations.


Providing Context for Investigations

Arctic Wolf often needs Cirius context to classify a finding. Common situations:

AW FindsCirius Context NeededWhere to Look
Unusual admin account activityWas this Rory doing a planned change?SecOps CM tickets, Rory's schedule
New service installed on a serverWas this a deployment?GitHub Actions recent deployments
Large outbound data transferWas this a Veeam backup or DR test?Veeam email reports, DR test schedule
Lateral movement between serversWas this planned admin work?Maintenance window in SecOps
Off-hours loginWas this Rory or Kevin working late?Ask the individual

If you cannot rule out malicious activity after checking, treat it as confirmed and escalate.


Alert Tuning and False Positives

When a recurring alert is confirmed benign, ask Arctic Wolf to tune it — they manage the detection rules on their end.

When to request tuning:

  • Same alert fires 3+ times with the same confirmed-benign explanation
  • Activity is permanent and expected (not a one-time event)
  • The tuning scope is specific (exact account, exact machine, exact behavior)

How to request: Reply in the investigation ticket: "This is expected behavior from [account/machine] because [reason]. Please tune this detection for this specific scope."

Arctic Wolf will confirm the tuning request and apply it. Ask them to document the tuning scope so it can be reviewed at the next annual review.

What NOT to tune:

  • Break-glass account activity
  • Security tool installation/removal
  • Mass account lockouts
  • Broad behavioral patterns (these need investigation even if the last few were benign)

Weekly and Monthly Touchpoints

Weekly Threat Summary

Arctic Wolf sends a weekly threat summary email. Review it for:

  • Any detections affecting Cirius infrastructure
  • Industry threats relevant to healthcare/SMB
  • Recommended defensive actions

Quarterly Business Reviews (QBR)

Arctic Wolf schedules a QBR quarterly to review:

  • Detection volume and trends
  • Open tuning requests
  • Coverage gaps
  • Upcoming threat landscape changes

Rory attends. Prior to the QBR, pull the quarterly ticket volume from Concierge and review open tuning requests so the conversation is productive.

Annual Coverage Review

Annually, reconcile what Arctic Wolf is monitoring against the CMDB. See Arctic Wolf CMDB Check for the full procedure.



Document History

DateChangeAuthor
May 2026Initial draft — Concierge portal, priority levels, P1/P2 response flow, P3/P4 review, SOC communication, context provision, alert tuning, weekly/monthly touchpoints.Rory

Internal use only — Cirius Group