Compromise Assessment

Mandiant Consulting

Identify ongoing or past attacker activity in your environment

A Mandiant Compromise Assessment combines our extensive experience responding to intrusions carried out by advanced threat actors, industry-leading threat intelligence and FireEye technology to: identify your ongoing or past intrusions, assess risk by identifying weaknesses in your security architecture, vulnerabilities, improper usage or policy violations and system security misconfigurations, and increase your ability to respond effectively to future incidents.

generic-code

Overview

We built this assessment to meet your business objectives with speed, scale, and efficiency. In addition to identifying evidence of ongoing or past attacker activity in your environment, the assessment offers:

Context derived from threat intelligence

Provides insight into attacker attribution and motivation so organizations know if they are being targeted.

Identification of risks

Identifies security architecture and configuration weaknesses, including missing patches or security software.

Facilitation of future investigations

Recommends strategic options that can better prepare your organization's security team to respond to intrusions.

What we provide you with:

What we provide you with:

  • Comprehensive analysis of your environment—focused on finding evidence of ongoing or past compromises
  • A view into your organization’s systemic risks and exposures
  • Identification of your security program’s hygiene issues
  • Best practice recommendations for furthering your organization’s ability to effectively respond to future incidents
  • Options to deploy on-premise or cloud-hosted technology

What you get:

What you get:

  • Analysis of endpoint, network, email and log data
  • Identification of compromised systems
  • Report of attacker activity
  • Summary of findings

TESTIMONIAL

“A compromise assessment answers the all important question: Have you been breached?”

- Benefits of Compromise Assessments


Benefits of Compromise Assessments and Why Security-Conscious Firms Use Them
Download white paper

Our Approach

The major activities our consultants perform during a Compromise Assessment include:

Deploy proprietary endpoint, network, email and log inspection technology

We place investigative technology at Internet egress points and on host systems such as servers, workstations, and laptops.

Assess your environment using intelligence from prior investigations

We apply our comprehensive library of indicators of compromise to evaluate network traffic, servers, workstations, laptops, and critical log data for evidence of current and past attacker activity.

Analyze evidence

Our consultants perform host and network forensic analyses as well as malware and log analyses to conduct the assessment. We confirm initial findings to minimize false positives prior to reporting them.

Summarize findings

We provide a detailed report that summarizes the steps taken during the assessment, the major findings, and any appropriate recommendations for next steps.

Related resources

Professional affiliations and certifications

FSISAC_logo
cesg-cpni-certification-color
pci-security-standards-council