Reactive engagement / 06

Compromise

Assessment.

Establish whether an adversary is in the environment now, or has been, and close the gaps that would let the next one move.

Most organizations cannot say with confidence whether they are compromised. Preventive controls report on what they blocked, not on what passed. A compromise assessment answers the question directly, on evidence, by examining the environment for indicators of compromise and unauthorized activity that evaded the controls already in place.

The absence of alerts is not evidence of anything. It is the most common reason an intrusion runs for months.

The assessment reads both the past and the present. Historical artifacts and logs answer what already happened, and real-time telemetry collected across the estate answers whether someone is operating in it right now. The live half runs for the four weeks we are in the environment, so the answer covers a window and not a moment.

We run compromise assessments from Switzerland, across Europe and the Gulf, and the first call is with the person who will do the work.

5 weeks Typical duration, kick-off to report review
Principal Level of the operator, start to finish
0 Agents retained, and no new licences
Your estate Where the data is collected and analyzed
[ THREE QUESTIONS, ONE PASS ]

More than a hunt for intruders.

A compromise assessment answers three separate questions from one body of evidence, which is why it is not the same instrument as threat hunting. The third question is the one most organizations have never had answered, and gaps in best practice are open invitations for a threat actor. Run over time, this is one of the most effective ways to drive down high-severity incidents.

A

The past

Evidence of a compromise that already happened and was never found. Execution artifacts, persistence, credential access, command and control, and the anti-forensic traces left by someone who tried to remove them.

The question it answers
Has this organization been breached before, without anyone noticing.
B

The present

Real-time telemetry collected across the estate, not only logs describing days and weeks that have already passed. It runs for the four weeks of the engagement, so an actor who moves in week three is still inside the window.

The question it answers
Is an advanced threat actor operating in this environment right now.
C

The next intrusion

Verification of how the security controls are actually configured, against what it would take to stop an adversary at each step. Found in the same pass, on the same evidence, at no extra collection cost.

The question it answers
Would the controls in place stop a foothold, lateral movement or privilege escalation.

What we collect and examine

Four sources, weighted by consequence.

Depth goes to the systems that carry the most risk, which are usually the ones carrying the least coverage.

01

Endpoints

Live forensic collection across the estate using Velociraptor, tuned to run at speed on the hardware already on site. Current state, not only what the logs kept.

Execution artifacts, persistence, credential access and anti-forensic traces. The tooling is deployed for the engagement and removed at the end. No agent stays behind and no new licence is required.

02

Identity

Active Directory and Entra ID. Security logs, privilege paths, delegation and service accounts, and the misconfigurations that turn a single foothold into domain or tenant control.

This is where an intrusion stops being a machine problem and becomes an estate problem. On the cloud side that means conditional access, app registrations, legacy authentication and changes to MFA. It is also where the third question pays for itself, because most of what is found here is fixable before anyone uses it.

03

Network infrastructure

DNS, proxy and firewall logs reviewed for command and control, staging and exfiltration patterns, including traffic that looks legitimate at the perimeter.

Traffic that passes a control is not traffic a control approved. Most of what matters here was allowed by a rule that was written for something else.

04

Crown jewels

Critical IT assets and the business applications the organization actually runs on. During analysis most of the attention goes here, deliberately, because these are the systems that carry the most consequence and usually the least coverage.

They are usually not onboarded into the SIEM at all, and almost never included in a hunt, so in most estates nobody has examined them the way an assessment does. Where nothing can read a log, we build a parser for it instead of leaving that system out of scope.

How an engagement runs

Five phases, kick-off to report review.

An assessment is not a snapshot. It reads backwards as far as the estate still remembers, and forwards for the four weeks it is running, collecting more than the estate was keeping on its own.

EVIDENCE AVAILABLE how much there is to work with, before and during LIMITED BY RETENTION DFIR ARTIFACTS AND TELEMETRY YEARS WEEKS ENGAGEMENT START EVIDENCE THE ESTATE ALREADY KEPT WHAT THE ASSESSMENT COLLECTS ENHANCED AUDITING AND EVIDENCE COLLECTION ASSESSMENT PHASES agreed in writing before anything begins PHASE 01 Kick-off and planning scope, in writing PHASE 02 Velociraptor deployment your accounts PHASE 03 Data collection the agreed scope PHASE 04 Triage of hits a person decides PHASE 05 Report and review walked through Both sides of the line are in scope. How far back we can read depends on what the estate kept, not on how hard we look. From the day we arrive we collect more than it was keeping: auditing raised, and DFIR tooling it does not normally run.
PHASE 01

Kick-off and planning

Objectives, scope and scale are established: the critical assets, systems and network segments to examine.

Agreed in writing before anything begins.

PHASE 02

Velociraptor deployment

Collection tooling is deployed into your environment, under accounts your team issues.

Residency and classification rules are fixed inputs from the first call, not obstacles negotiated later.

PHASE 03

Data collection

Endpoint, identity, network infrastructure and business application data is gathered across the agreed scope.

Auditing is raised where it was too thin to answer the question, so the estate starts producing evidence it was not producing before.

PHASE 04

Triage of hits

Current threat intelligence supplies known indicators and adversary techniques. Automated analysis narrows the field.

A senior investigator then confirms or dismisses each candidate and assesses its impact.

PHASE 05

Report and review

Findings are written up, then walked through with your team so every one is clear and well understood, together with the plan to act on it.

What we typically find

Four things turn up in most environments.

Patterns across engagements, not any one client. Set out here because a buyer deserves to know roughly what a report contains before commissioning one.

FINDING 01

PRIOR INCIDENTS

NEVER FULLY CLOSED

Leftovers from an incident that was already handled.

Where an organization has been through a major incident, remnants of it are still in the estate. Tooling that was never removed, accounts that were never disabled, persistence that survived the remediation, and hosts rebuilt everywhere except the one that mattered.

None of this means the response failed. It means the response ended when the pressure did, which is when everyone stops looking. An assessment is the first time anyone checks the closing state against the estate rather than against the report.

FINDING 02

PENETRATION TESTING

TRACES AND LEFTOVERS

Traces of penetration testing, in three forms.

The first is the tooling and the techniques a tester left behind. On the evidence alone these look the same as an intruder, and separating the two is work that has to be done before anything else can be believed.

The second matters more. The technologies a penetration test usually targets have been hardened, but partially. A vulnerable network protocol is disabled on most hosts and still answering on the rest. A setting is corrected in one forest and not the other. The finding was closed in the report and not in the estate, and the half that was missed is the half still reachable.

The third is what the test itself switched on and nobody switched off. An account created for the engagement, given the privilege it needed to prove a point, and still in that group months later. Credentials shared across a team during the test and never rotated afterwards. Delegation and trust attributes written onto computer or service objects to demonstrate a path to a privileged identity, left in place once the path was demonstrated.

None of it was careless at the time. Each change was deliberate, scoped to the test, and meant to be reverted. The test ended, the report was delivered, and the environment was never put back. What remains is not a finding the report describes. It is exposure the test created, and it is usually held by an account nobody is watching.

FINDING 03

IDENTITY AND ENDPOINT

PATHS, NOT HOLES

Configuration that leaves an attacker room to move.

Active Directory, Entra ID and the endpoint security controls, configured in ways that hand an adversary options. Delegation, privilege, trust relationships, policy exceptions and control settings decided for convenience years ago and never revisited since.

These are not vulnerabilities in the sense a scanner reports. Nothing here is unpatched. They are paths, and there are usually more of them than anyone in the organization expects, because no single change looked dangerous on the day it was made.

FINDING 04

IDENTITY COMPROMISE

MISSED BY MONITORING

Credentials already in someone else’s hands.

Two independent sources tend to point at the same accounts. The first is deep research into the places stolen credentials are traded, run against the organization’s domains and its people rather than against a keyword. The second is in the estate’s own authentication logs: the pattern left by a credential broker checking a list, testing which of the logins they are holding are live and which were fabricated by whoever sold them.

That second pattern is easy to dismiss as noise. It is not a brute force run and does not look like one. It is a measured pass against real usernames, sized to answer a commercial question rather than to break in: how much of this list is still good. By the time it appears, the credentials have already changed hands.

Many organizations already buy brand protection or credential monitoring, and it rarely surfaces what we find. Those services watch the sources that are straightforward to watch. The credentials that matter are usually somewhere else, in a set that was never posted publicly because it was sold directly. A valid login is the cheapest way into an estate: it needs no vulnerability, and on the day it is used it does not look like an attack.

Clients who run an assessment every six months see their incidents fall, in number and in severity. The mechanism is Finding 03: it is a list of the routes an attacker would have taken, and closing them removes the routes before anyone walks them.

What you receive

Four documents, written to be acted on.

Every conclusion states what was observed, what it supports, and how confident we are in it. Where the evidence does not settle a question, that is written down.

Executive summary A high-level account for senior management: scope, method, key findings and the actions they imply, in business terms.
Detailed findings report Every indicator of compromise with its nature, affected systems, supporting evidence, and an analysis of the impact on security and operations.
Prioritized remediation plan Short-term fixes for immediate threats and longer-term measures to raise the posture, sequenced by consequence rather than drawn from a catalog.
Presentation and debriefing A formal presentation to your stakeholders and a working session to discuss results, agree next steps and transfer what was learned.

Who this is for

Where the call usually comes from.

No independent evidence Organizations with no independent evidence of their current state, only the absence of alerts.
Board and regulator Boards and regulators asking for assurance that a control inventory cannot give.
Changed estate Estates after a merger, a divestment or a rapid cloud migration, where visibility has gaps nobody has mapped.
A suspicion, no incident Teams that suspect something happened but have no incident to point at.

What we need to scope it

Four numbers and we can price it.

Endpoints A count of the endpoints in the estate.
Applications How many are hosted, and how many are exposed to the internet.
Users A count of the users in the environment.
Microsoft cloud Whether Microsoft Entra ID and Microsoft 365 are in use.

Scoping starts with a conversation, not a questionnaire. We will tell you if a compromise assessment is the wrong instrument for your question.

The method, in the open

What the evidence in an assessment actually is.

Evidence of execution Proving a program ran on Windows, source by source, with what each one contains and what it will support in a report. Most of a triage queue is built from these.
Anti-forensics What file timestamps mean, and where a tool that wrote them leaves a mark the file system would not.
Linux estates Reading Linux timestamps, because an assessment that only covers Windows is an assessment of half the estate.

NEXT / RELATED SERVICE

Digital Forensics and Incident Response

When the assessment finds something that cannot wait for a report.

NEXT / SCOPING

Engage

Describe the situation. If we are the wrong firm for it, we will say so.