Compromise Assessment

Our Compromise Assessment Service provides you with state-of-the-art security tools to detect potential security breaches quickly and efficiently. With over 33,000 precise detection rules, we thoroughly analyze your IT environment and identify malicious artifacts that indicate a potential compromise. This ensures hidden threats are uncovered and your organization stays optimally protected.

Experienced Security Analysts

With a precise, fast and comprehensive Compromise Assessment, we secure your IT infrastructure and ensure your organization is optimally protected against cyberattacks. Let our experienced analysts support you and minimize downtime and damage through targeted remediation measures.

Flexible Managed Capacity

Managed Capacity gives you flexible access to entire analyst teams. We ensure that the agreed number of security analysis and monitoring experts is always available. This scalable solution guarantees continuous security and adaptability to your individual needs.

Key Facts About Our Managed Compromise Assessment Service

Our Compromise Assessment Service combines powerful forensic tools such as THOR, with over 33,000 detection rules, and Velociraptor for deep forensic analysis, as well as CrowdStrike for effective endpoint security, to specifically check your IT infrastructure for signs of compromise.

If a compromise is detected, we analyze the scope of the incident and identify hidden threats and malware that traditional security systems often miss. In the event of damage, our EDR experts can also handle and quickly roll out the most common EDR tools. Trust our Compromise Assessment to comprehensively secure your IT environment and proactively defend against future cyberattacks.

24 Hour Service

Our 24-hour service is available to you every day of the year! Our staff typically speak German, ensuring smooth and efficient communication.

>33,000 Compromise Detection Rules

THOR offers industry-leading detection rates and meets the requirements of global threat hunters with thousands of advanced signatures. CrowdStrike complements this with powerful endpoint security that detects, monitors, and responds to cyberattacks in real time.

30 Minute SLA

As a rule, our analysts respond to critical detections from the Compromise Assessment Service in less than 30 minutes - guaranteed by our service levels!

Flexible Ad-Hoc Deployment

Fast start of the Compromise Assessment so no time is lost!

Rapid deployment lets us respond regardless of the size or complexity of your IT infrastructure: detect compromises early, contain them, and minimize downtime so your secure operations resume fast.

Analysis Services in the Compromise Assessment

Comprehensive support through security analysis and incident response

In addition to providing a rapid Compromise Assessment, we offer additional services such as IT forensics and incident response to act effectively in the event of damage. Our experts use state-of-the-art technologies and tools to perform comprehensive analyzes, detect threats early, and take targeted action. Trust our solutions to sustainably strengthen your security strategy and resume operations smoothly.

Flexible Operating Hours

Maximum flexibility for the operating hours of the Compromise Assessment

The Compromise Assessment is flexibly scalable — 24x7, 10x5 or 8x5. We define analysis windows around your risk profile and deliver a transparent assessment of your security posture.

Multi-Platform

Cross-system review for security incidents

Our Compromise Assessment is Multi-Platform capable and supports a wide variety of operating systems, including Windows, Linux and macOS. This allows us to perform a comprehensive analysis of your entire IT infrastructure, regardless of platform. Our Multi-Platform approach provides comprehensive protection and ensures the security of your heterogeneous IT environment.

Frequently asked questions

Answers to the questions our customers ask most often.

What is a compromise assessment?
A targeted examination of your environment for traces of past or ongoing compromise — whether or not an alert exists.
How is it different from a pentest?
A pentest looks for vulnerabilities; a compromise assessment looks for attacker traces. The two complement each other.
How long does it take?
Depending on environment size, typically two to four weeks including analysis and final report.
What happens if something is found?
We escalate immediately and move seamlessly into incident response and IT forensics.
When is a compromise assessment useful?
When a successful attack is suspected, and preventively for especially critical assets such as domain controllers, central servers or other crown jewels.
Which tools are used?
Among others the THOR APT scanner, CrowdStrike Falcon, Velociraptor, YARA rules and SIEM analysis — across Windows, Linux and macOS.
What information do you need from us?
Ideally network topology, an overview of critical systems, relevant logs and existing security controls. Access to SIEM logs improves the assessment of detected threats.
What report do we receive?
A detailed final report with all findings, detected compromises and prioritised recommendations for action.
How does a managed compromise assessment differ from a one-off?
Managed means regular, continuous assessments with a long-term threat picture; a one-off assessment only reflects the current status.
Who performs the assessment and how is confidentiality maintained?
Experienced analysts working under ISO/IEC 27001-certified processes. All data is treated confidentially and used solely for the assessment.

Question not answered here? Ask us