Answers to the questions our customers ask most often.
What is a compromise assessment?
A targeted examination of your environment for traces of past or ongoing compromise — whether or not an alert exists.
How is it different from a pentest?
A pentest looks for vulnerabilities; a compromise assessment looks for attacker traces. The two complement each other.
How long does it take?
Depending on environment size, typically two to four weeks including analysis and final report.
What happens if something is found?
When is a compromise assessment useful?
When a successful attack is suspected, and preventively for especially critical assets such as domain controllers, central servers or other crown jewels.
Which tools are used?
Among others the THOR APT scanner, CrowdStrike Falcon, Velociraptor, YARA rules and SIEM analysis — across Windows, Linux and macOS.
What information do you need from us?
Ideally network topology, an overview of critical systems, relevant logs and existing security controls. Access to SIEM logs improves the assessment of detected threats.
What report do we receive?
A detailed final report with all findings, detected compromises and prioritised recommendations for action.
How does a managed compromise assessment differ from a one-off?
Managed means regular, continuous assessments with a long-term threat picture; a one-off assessment only reflects the current status.
Who performs the assessment and how is confidentiality maintained?
Experienced analysts working under ISO/IEC 27001-certified processes. All data is treated confidentially and used solely for the assessment.