MICROSOFT 365 THREAT DETECTION & RESPONSE · BUILT BY KEMPCORE

Microsoft 365 security that tells you what actually happened.

SearchCentral watches your tenant's sign-in and audit logs, explains every detection in plain English, and lets your officer acknowledge or remediate it from their phone. No agents on a single endpoint.

Runs on hardware you own Entra ID authentication MITRE ATT&CK mapped Data never leaves your tenant
TOTAL ALERTS
24
+12% vs last 24h
ACTIVE ATTACKS
3
+45% vs last 24h
USERS AT RISK
7
+16% vs last 24h
MITRE TECHNIQUES
11
+8% vs last 24h

Sample tenant data. The simulator below writes into it as you use it.

INTERACTIVE DEMO · SIMULATED ATTACKS, REAL DETECTIONS

Fire an attack simulation. Watch it land on the phone.

Pick one of three Microsoft 365 attack paths and launch it. The attack is simulated — the detection logic, the MITRE mapping and the alert your officer receives are exactly what ships. Nothing here is pre-recorded.

M365 ATTACK SIMULATOR
Select Simulation
Simulates real-world attack scenarios
for security testing
THREE ATTACK VECTORS
1. Brute Force Login
Password spray attack simulation
2. OAuth Consent Grant
Malicious app consent simulation
3. Impossible Travel
Impossible travel detection test
GLOBAL ATTACK MAP
 
SIMULATED ATTACK
HIGH RISK
REMEDIATED
YOUR TENANT
HUNT & BLAST RADIUS SEARCHCENTRAL HOST ONLY
Threat hunting and dossier generation run on the SearchCentral host. The mobile companion is alert, acknowledge and remediate only — it never queries the audit buffer.
Scope: last 30 days · 23,847 events · searchcore.exampleidle
> ready. select an alert on the companion, or edit the query above.
SEARCHCENTRAL
WHAT IT DOES

Everything a small security team actually needs.

No query language to learn, no endpoint rollout to negotiate, no data leaving your tenant.

Plain-English alerts

Every detection arrives with what it means and what to do, written for a human on a Sunday morning — not a KQL snippet.

No endpoint agents

Reads Microsoft 365 audit and sign-in logs through Graph. Nothing to install, package or defend on staff machines.

Triage from your pocket

Acknowledge or apply a named remediation from the phone, behind an explicit confirm. Hunting stays on the SearchCentral host, by design.

MITRE ATT&CK mapped

Every rule carries its technique ID, so your board reporting and your auditor's framework already line up.

Your host, your data

Runs on hardware you own, authenticated with your own Entra ID app registration. The audit buffer never leaves the tenant.

Simulation built in

Prove the detections fire before you need them. Three real Microsoft 365 attack paths, on demand, against a test account.

HOW IT WORKS

Three steps, about thirty minutes.

That is the SearchCentral side — the app registration, the poller, and your first real detections. No endpoint rollout to schedule and no forwarder to babysit. Reaching the host from a phone is separate work on your network, and how long it takes depends entirely on what you already run.

Connect your tenant

Create a read-only Entra ID app registration and point SearchCentral at it. Nothing is installed on staff machines and nothing changes on your network.

READ-ONLY BY DEFAULT

Detections start running

The poller reads sign-in and audit logs continuously, maps every hit to a MITRE ATT&CK technique and writes it to an audit buffer on your own host.

FIRST ALERTS SAME DAY

Your officer acts

Alerts arrive on the phone in plain English with what it means and what to do. Acknowledge, or confirm a named remediation. Hunting and dossiers stay on the SearchCentral host.

This step is the one that needs a route from the phone to your host — published through Entra, or over a tunnel you already run. Both routes are in the FAQ.

CONFIRM BEFORE ANY ACTION
MODULES

One shipping. Two on the way.

All three run on the same audit buffer as the core platform — no second agent to deploy, no second console to learn, no extra licence to reconcile.

SHIPPING

AUDIT_AI

Hunt, Timelines & Dossiers

Live in the product today — not a promise.

  • Scoped hunt by account and date range
  • Per-account incident timelines
  • MITRE ATT&CK mapping throughout
  • HTML and PDF reports for the board
IN BUILD

TOKENS.EXE

OAuth Session Shield

Detection ships today. Containment is the work in progress.

  • Detects consent granted to unverified publishers
  • Flags suspicious OAuth token activity
  • Blocks malicious consent at grant time
  • Real-time session protection
PLANNED

EXFIL_GUARD

SharePoint ACL Isolation

Designed, not started. Shaped by what pilot tenants ask for.

  • Monitors SharePoint permissions
  • Detects excessive access grants
  • Isolates compromised permissions
  • Prevents data exfiltration
PRICING · PER MONTH

Priced per tenant, not per incident.

Banded by user count, so a small team is not paying enterprise rates. One licence covers the poller, the console and the mobile companion — no per-seat agent fee, because there is no agent.

STARTER

1 MONTH FREE
0 – 50 users
£50
  • Core threat detection
  • Plain-English alerts
  • Email alerts
  • Community support

GROWTH

MOST POPULAR
50 – 250 users
£150
  • Everything in Starter
  • Mobile companion
  • Hunt & blast-radius console
  • Priority support

STANDARD

 
250 – 750 users
£250
  • Everything in Growth
  • All modules included
  • Scheduled reports
  • Named support contact

PROFESSIONAL

 
750 – 1,500 users
£500
  • Everything in Standard
  • Custom integrations
  • Custom detections
  • Onboarding & tuning

ENTERPRISE & MSP

 
1,500+ or multi-tenant
Let’s talk
  • Unlimited users
  • Multi-tenant MSP console
  • Bespoke detections
  • 24/7 dedicated support

All prices are in GBP and exclude VAT, charged at the prevailing UK rate.

QUESTIONS WE GET ASKED

The things your security review will want.

If something here is missing, ask us directly — we would rather answer it before you buy than after.

Do we have to install anything on staff machines?

No. SearchCentral reads Microsoft 365 audit and sign-in logs through Microsoft Graph. There is no endpoint agent to package, deploy, exempt from AV, or explain to your users.

Where does our data actually go?

Onto a host you own. The audit buffer, the index and the dossiers all stay on your hardware — there is no vendor cloud in the path and nothing to sign a data processing agreement about.

What permissions does it need?

A read-only Entra ID app registration with directory audit and sign-in log scopes. Remediation runs under a separate, explicitly approved write identity — the poller itself can never change anything.

Where does the work actually get done?

Remediation is a job for either surface — the console or the phone app. Both apply the same named actions behind a typed confirmation, a named officer and an append-only audit log, under a separate write-scoped identity. Nothing ever acts on its own, and every action carries a signature.

Hunting and dossiers are console-only, by design. The console also carries the full picture for deep work; the phone is the out-of-hours half — see it, understand it, acknowledge or fix it.

How does the phone reach our SearchCentral host?

Two ways, and you pick by what you already own. If you have Entra Application Proxy or Private Access, publish SearchCentral through it — your conditional access is enforced before a request ever reaches the host, and with Application Proxy there is nothing to install on the phone at all.

If you don't, any tunnel you already run works: the corporate VPN client your staff already have, Cloudflare Tunnel, or a WireGuard mesh such as Tailscale. We only need two things and don't mind how you provide them — the phone can reach the SearchCentral host on its port, over TLS the phone already trusts. (Site-to-site VPN on its own won't do it: a handset on mobile data is on neither network.)

And if you have neither, nothing is lost. The phone is a convenience, not a requirement — the desktop console does everything it does and more. You would be choosing not to carry alerts in your pocket, not doing without a feature.

Do you host anything, or see our data in transit?

No, and no. There is no SearchCentral relay or broker in the middle — the phone talks to your host directly across your own transport, so we never hold, proxy or see your logs. That is also why there is no data processing agreement to negotiate.

The one exception is push notification delivery, which has to travel via Apple and Google to reach a locked phone. Those messages are content-free by design: they say “open the app”, never what happened or to whom.

How do we know the detections work?

Run them. The attack simulator on this page is the same one that ships with the product — three real Microsoft 365 attack paths you can fire against a test account whenever you want proof.

What happens when the trial ends?

Pick a plan or stop. If you stop, detections stop and the data stays yours — the audit buffer and any dossiers already generated are just files on your host, to keep or delete as you like.

Removing it is one host, not a fleet: stop the poller service, delete the application directory, and revoke the Entra app registration. There is nothing to clean off staff machines, because nothing was ever put there.

GET STARTED

Try it against your own tenant.

One month, the full product, your real Microsoft 365 logs.

Start a one-month free trial

Read-only to begin with, so the first month cannot change anything in your tenant. Turn remediation on only when you are satisfied the detections are right.

  • Full product, no feature gates during the trial
  • No card required — we invoice if you continue
  • Setup call included — SearchCentral itself is usually live within the hour
  • Walk away by stopping one service and revoking one app registration

No card, no obligation. We reply personally, usually same day.

Still not sure? Fire the simulator.

You do not have to take our word for any of this — the demo on this page runs the same detections the product ships with.

RUN A LIVE SIMULATION
SearchCentral · a Kempcore product
sales@kempcore.co.uk
support@kempcore.co.uk
Microsoft 365 threat detection & response · MITRE ATT&CK mapped · built in Hull, UK