The past
Evidence of a compromise that already happened and was never found. Execution artifacts, persistence, credential access, command and control, and the anti-forensic traces left by someone who tried to remove them.
Reactive engagement / 06
Assessment.
Establish whether an adversary is in the environment now, or has been, and close the gaps that would let the next one move.
Most organizations cannot say with confidence whether they are compromised. Preventive controls report on what they blocked, not on what passed. A compromise assessment answers the question directly, on evidence, by examining the environment for indicators of compromise and unauthorized activity that evaded the controls already in place.
The absence of alerts is not evidence of anything. It is the most common reason an intrusion runs for months.
The assessment reads both the past and the present. Historical artifacts and logs answer what already happened, and real-time telemetry collected across the estate answers whether someone is operating in it right now. The live half runs for the four weeks we are in the environment, so the answer covers a window and not a moment.
We run compromise assessments from Switzerland, across Europe and the Gulf, and the first call is with the person who will do the work.
A compromise assessment answers three separate questions from one body of evidence, which is why it is not the same instrument as threat hunting. The third question is the one most organizations have never had answered, and gaps in best practice are open invitations for a threat actor. Run over time, this is one of the most effective ways to drive down high-severity incidents.
Evidence of a compromise that already happened and was never found. Execution artifacts, persistence, credential access, command and control, and the anti-forensic traces left by someone who tried to remove them.
Real-time telemetry collected across the estate, not only logs describing days and weeks that have already passed. It runs for the four weeks of the engagement, so an actor who moves in week three is still inside the window.
Verification of how the security controls are actually configured, against what it would take to stop an adversary at each step. Found in the same pass, on the same evidence, at no extra collection cost.
What we collect and examine
Depth goes to the systems that carry the most risk, which are usually the ones carrying the least coverage.
01
Live forensic collection across the estate using Velociraptor, tuned to run at speed on the hardware already on site. Current state, not only what the logs kept.
Execution artifacts, persistence, credential access and anti-forensic traces. The tooling is deployed for the engagement and removed at the end. No agent stays behind and no new licence is required.
02
Active Directory and Entra ID. Security logs, privilege paths, delegation and service accounts, and the misconfigurations that turn a single foothold into domain or tenant control.
This is where an intrusion stops being a machine problem and becomes an estate problem. On the cloud side that means conditional access, app registrations, legacy authentication and changes to MFA. It is also where the third question pays for itself, because most of what is found here is fixable before anyone uses it.
03
DNS, proxy and firewall logs reviewed for command and control, staging and exfiltration patterns, including traffic that looks legitimate at the perimeter.
Traffic that passes a control is not traffic a control approved. Most of what matters here was allowed by a rule that was written for something else.
04
Critical IT assets and the business applications the organization actually runs on. During analysis most of the attention goes here, deliberately, because these are the systems that carry the most consequence and usually the least coverage.
They are usually not onboarded into the SIEM at all, and almost never included in a hunt, so in most estates nobody has examined them the way an assessment does. Where nothing can read a log, we build a parser for it instead of leaving that system out of scope.
How an engagement runs
An assessment is not a snapshot. It reads backwards as far as the estate still remembers, and forwards for the four weeks it is running, collecting more than the estate was keeping on its own.
Objectives, scope and scale are established: the critical assets, systems and network segments to examine.
Agreed in writing before anything begins.
Collection tooling is deployed into your environment, under accounts your team issues.
Residency and classification rules are fixed inputs from the first call, not obstacles negotiated later.
Endpoint, identity, network infrastructure and business application data is gathered across the agreed scope.
Auditing is raised where it was too thin to answer the question, so the estate starts producing evidence it was not producing before.
Current threat intelligence supplies known indicators and adversary techniques. Automated analysis narrows the field.
A senior investigator then confirms or dismisses each candidate and assesses its impact.
Findings are written up, then walked through with your team so every one is clear and well understood, together with the plan to act on it.
What we typically find
Patterns across engagements, not any one client. Set out here because a buyer deserves to know roughly what a report contains before commissioning one.
FINDING 01
PRIOR INCIDENTS
NEVER FULLY CLOSED
Where an organization has been through a major incident, remnants of it are still in the estate. Tooling that was never removed, accounts that were never disabled, persistence that survived the remediation, and hosts rebuilt everywhere except the one that mattered.
None of this means the response failed. It means the response ended when the pressure did, which is when everyone stops looking. An assessment is the first time anyone checks the closing state against the estate rather than against the report.
FINDING 02
PENETRATION TESTING
TRACES AND LEFTOVERS
The first is the tooling and the techniques a tester left behind. On the evidence alone these look the same as an intruder, and separating the two is work that has to be done before anything else can be believed.
The second matters more. The technologies a penetration test usually targets have been hardened, but partially. A vulnerable network protocol is disabled on most hosts and still answering on the rest. A setting is corrected in one forest and not the other. The finding was closed in the report and not in the estate, and the half that was missed is the half still reachable.
The third is what the test itself switched on and nobody switched off. An account created for the engagement, given the privilege it needed to prove a point, and still in that group months later. Credentials shared across a team during the test and never rotated afterwards. Delegation and trust attributes written onto computer or service objects to demonstrate a path to a privileged identity, left in place once the path was demonstrated.
None of it was careless at the time. Each change was deliberate, scoped to the test, and meant to be reverted. The test ended, the report was delivered, and the environment was never put back. What remains is not a finding the report describes. It is exposure the test created, and it is usually held by an account nobody is watching.
FINDING 03
IDENTITY AND ENDPOINT
PATHS, NOT HOLES
Active Directory, Entra ID and the endpoint security controls, configured in ways that hand an adversary options. Delegation, privilege, trust relationships, policy exceptions and control settings decided for convenience years ago and never revisited since.
These are not vulnerabilities in the sense a scanner reports. Nothing here is unpatched. They are paths, and there are usually more of them than anyone in the organization expects, because no single change looked dangerous on the day it was made.
FINDING 04
IDENTITY COMPROMISE
MISSED BY MONITORING
Two independent sources tend to point at the same accounts. The first is deep research into the places stolen credentials are traded, run against the organization’s domains and its people rather than against a keyword. The second is in the estate’s own authentication logs: the pattern left by a credential broker checking a list, testing which of the logins they are holding are live and which were fabricated by whoever sold them.
That second pattern is easy to dismiss as noise. It is not a brute force run and does not look like one. It is a measured pass against real usernames, sized to answer a commercial question rather than to break in: how much of this list is still good. By the time it appears, the credentials have already changed hands.
Many organizations already buy brand protection or credential monitoring, and it rarely surfaces what we find. Those services watch the sources that are straightforward to watch. The credentials that matter are usually somewhere else, in a set that was never posted publicly because it was sold directly. A valid login is the cheapest way into an estate: it needs no vulnerability, and on the day it is used it does not look like an attack.
Clients who run an assessment every six months see their incidents fall, in number and in severity. The mechanism is Finding 03: it is a list of the routes an attacker would have taken, and closing them removes the routes before anyone walks them.
What you receive
Every conclusion states what was observed, what it supports, and how confident we are in it. Where the evidence does not settle a question, that is written down.
Who this is for
What we need to scope it
Scoping starts with a conversation, not a questionnaire. We will tell you if a compromise assessment is the wrong instrument for your question.
The method, in the open
NEXT / RELATED SERVICE
Digital Forensics and Incident ResponseWhen the assessment finds something that cannot wait for a report.