Security tools ship with defaults designed to suit every environment and, inevitably, none in particular. In the years that follow, exclusions get added during a rollout and quietly stay, integrations land half-finished once the project that needed them wraps up, and telemetry starts arriving faster than anyone has time to build detections against it. That's the ordinary condition of a stack maintained by a team with plenty of other work to do, and closing the distance between what those platforms can do and what they're currently doing is the engineering Oakmont takes on.
Services
Three things we're good at.
01
CrowdStrike Platform Engineering & Optimization
Prevention policy tuning, exclusion review and cleanup, detection tuning, workflow configuration, host group architecture, and console hygiene. For organizations already running CrowdStrike and need it configured by someone who understands how the console actually behaves in practice.
New setups for the security-critical SaaS tools that end up protecting everything else — enterprise password managers, SSO application onboarding, conditional access policy, and MFA rollout — configured deliberately from the start rather than left on whatever shipped in the box.
03
SIEM Enrichment
Turning raw telemetry into something a security team can actually use, through custom dashboards, detection logic, alert tuning, and log source onboarding, until the SIEM reflects what's happening in the environment rather than simply what's being ingested.
Threat Intelligence
Configuration, mapped to how intrusions actually run.
A tuning decision is much easier to defend when it traces back to something specific. These are six of the techniques that turn up most often in real intrusions, set against the configuration work that changes the outcome. Pick a tactic to see the mapping.
Tactic and technique references follow the MITRE ATT&CK® framework. ATT&CK is a registered trademark of The MITRE Corporation; Oakmont is not affiliated with or endorsed by MITRE, and the mapping from technique to configuration work is our own.
Who We Work With
Built for teams with security tools and not enough time to tune them.
Typically 50 to 500 employees, with an existing IT team but no dedicated security engineer, running CrowdStrike and SaaS security tools that were configured once during a rollout and haven't been revisited since. Most arrive working toward an insurance requirement or an audit, or trying to make sense of an environment they inherited from a prior IT hire or an acquisition.
50–500 employees with an existing IT team
Running CrowdStrike, Defender, or similar EDR
Microsoft 365, Google Workspace, Okta, or Entra ID in use
No dedicated internal security engineer
Cyber insurance requirements to satisfy
Preparing for audits or customer security reviews
Working with an environment they inherited
Navigating post-acquisition or IT staff transition
Process
How an engagement runs.
01
Assess
We work through what's configured today rather than what the rollout was supposed to produce, and the result is a picture of the gaps that's grounded in the environment as it actually stands.
02
Scope
From there we define what gets fixed and what it costs, and you approve a fixed quote before any work begins.
03
Implement
We make the changes, test them, and validate the result, keeping a record of what moved and the reasoning behind each decision.
04
Document
You're left with a written account of what changed and why, so the knowledge stays with your team instead of leaving with us.
05
Ongoing
If continued engineering makes sense once the initial work is done, we offer it on a scoped retainer you can cancel.
Not a SOC. Not MDR.
Oakmont doesn't monitor your environment around the clock or run your alert queue, because that's a different discipline with different staffing and there are firms that do it well. What we do instead is come in, engineer the configuration, document it, and hand it back in a form your team can maintain. If continued engineering help makes sense afterward, we offer it as a scoped retainer.
Outcomes
What changes after an engagement.
Detections tuned to the environment and exclusions reviewed against what's genuinely running, so fewer false positives reach the people who have to triage them.
SaaS tools configured deliberately, with the policies you chose rather than the ones that arrived by default.
SIEM dashboards built around the questions your team actually asks, which makes opening one worth the time it takes.
Documentation written for the people who'll maintain it, covering what changed and the reasoning behind each decision.
An engagement in numbers
Illustrative figures from a composite mid-market environment, shown to give the shape of the work. Not a specific client, and not a promise of identical results.
Self-check
Ten questions worth answering about your environment.
Answer them honestly, and treat "not sure" as a real answer, because for most teams it genuinely is. The whole thing runs in your browser and takes about a minute.
Question 1 of 10CrowdStrike
Loading…
Nothing is sent anywhere.
Pricing
Every engagement is scoped up front.
Pricing depends on environment size, platforms involved, and what needs fixing, so you get a fixed quote before work starts rather than an open-ended hourly arrangement that grows on its own.