Managed Detection & Response with a Prime analyst who knows your environment, on the SIEM you already run, or on the GHS ASTRAL platform.
ASTRAL Intelligence is GHS MDR as a managed service for mid-market security teams: 24×7 SOC coverage, agentic triage and investigation, expert-led response, threat intelligence advisory and executive reporting. AI brings the speed; GHS practitioners make the consequential calls.
The industry's open secret: most MDR providers sell alerting, not outcomes. ASTRAL Intelligence is built to close the four gaps that leave the customer holding the call.
You get a Prime analyst who learns your business and attaches impact to every escalation.
Agents triage; GHS analysts validate every verdict before it becomes an action.
Senior responders and PhD-level threat researchers on the floor, with an IR retainer available.
Guided or fully managed response, bounded by your rules of engagement, you choose the line.
ASTRAL Intelligence is the only ASTRAL plan that runs either way. The service you receive is identical, same Prime analyst, same SOC, same SLA. What changes is who owns the platform underneath it. Toggle to see the difference.
| Responsibility | You | GHS | Shared |
|---|
Either way, telemetry stays yours, the rules of engagement are yours, and every action is recorded for your audit trail.
From your telemetry to a contained threat, a continuous loop, running 24x7, on whichever platform you chose above.
Telemetry connected across cloud, endpoint, identity, email and network. Your Prime analyst tunes detections to your environment and rules of engagement.
Curated and custom detections correlate signals into high-confidence incidents, around the clock.
Agents enrich, correlate and build the timeline; GHS analysts validate every finding and apply business context.
Playbook-driven containment across identity, endpoint and cloud, guided or fully managed, bounded by your approvals.
Post-incident analysis feeds detections and playbooks; monthly, quarterly and executive reporting show the trend.
ASTRAL Intelligence is the most popular ASTRAL plan: enough human depth to own outcomes, enough automation to keep the price predictable, and the freedom to run on the platform you already have.
Need a dedicated team, custom everything and a 30-minute SLA? That's ASTRAL Enterprise. Need less? ASTRAL Agentic and Growth run the same operation with fewer people in it.
| Best for | Mid-market security teams |
| Coverage window | 24x7 |
| Dedicated analyst | Prime analyst |
| Platform | SIEM-agnostic yours, or GHS-hosted Google SecOps / Elastic |
| Threat hunting | Optional |
| Threat intel | Advisory + GHS Threat Intel feed |
| AI Threat Defense / auto remediation | Included |
| Cloud security coverage | Included |
| Human effort | Hour blocks, tied to ingestion |
| Use cases / parsers | Up to 20 / yr · up to 5 custom |
| Change requests / SOAR | Up to 20 · up to 5 integrations |
| Reporting | Monthly / quarterly · exec optional |
| Critical response SLA | 1–3 hours |
| Hotline & IR | 24x7 hotline · IR retainer as add-on |
Thirty minutes with a GHS expert: we'll look at the platform you run today, your telemetry and your requirements, and show you what ASTRAL Intelligence looks like on your stack, and on ours.
No commitment. 30 minutes. Real security expertise.