Reactive engagement / 06

Compromise Assessment.

Establish whether an adversary is in the environment now, or has been, and close the gaps that would let the next one move.

Most organizations cannot say with confidence whether they are compromised. Preventive controls report on what they blocked, not on what passed. A compromise assessment answers the question directly, on evidence, by examining the environment for indicators of compromise and unauthorized activity that evaded the controls already in place.

The absence of alerts is not evidence of anything. It is the most common reason an intrusion runs for months.

The assessment reads both the past and the present. Historical artifacts and logs answer what already happened, and real-time telemetry collected across the estate answers whether someone is operating in it right now. The live half runs for the four weeks the engagement is in the environment, so the answer covers a window and not a moment.

Compromise assessments are run from Switzerland, across Europe and the Gulf, and the first call is with the person who will do the work.

5 weeks Typical duration, kick-off to report review
Principal Level of the operator, start to finish
0 Agents retained, and no new licenses
Your estate Where the data is collected and analyzed
[ THREE QUESTIONS, ONE PASS ]

More than a hunt for intruders.

A compromise assessment answers three separate questions from one body of evidence, which is why it is not the same instrument as threat hunting. The third question is the one most organizations have never had answered, and gaps in best practice are open invitations for a threat actor. Run over time, this is one of the most effective ways to drive down high-severity incidents.

A

The past

Evidence of a compromise that already happened and was never found. Execution artifacts, persistence, credential access, command and control, and the anti-forensic traces left by someone who tried to remove them.

The question it answers
Has this organization been breached before, without anyone noticing.
B

The present

Real-time telemetry collected across the estate, not only logs describing days and weeks that have already passed. It runs for the four weeks of the engagement, so an actor who moves in week three is still inside the window.

The question it answers
Is an advanced threat actor operating in this environment right now.
C

The next intrusion

Verification of how the security controls are actually configured, against what it would take to stop an adversary at each step. Found in the same pass, on the same evidence, at no extra collection cost.

The question it answers
Would the controls in place stop a foothold, lateral movement or privilege escalation.

What the work examines

Four sources, weighted by consequence.

Depth goes to the systems that carry the most risk, which are usually the ones carrying the least coverage.

01

Endpoints

Live forensic collection across the estate using Velociraptor, tuned to run at speed on the hardware already on site. Current state, not only what the logs kept.

Execution artifacts, persistence, credential access and anti-forensic traces. The tooling is deployed for the engagement and removed at the end. No agent stays behind and no new license is required.

02

Identity

Active Directory and Entra ID. Security logs, privilege paths, delegation and service accounts, and the misconfigurations that turn a single foothold into domain or tenant control.

This is where an intrusion stops being a machine problem and becomes an estate problem. On the cloud side that means conditional access, app registrations, legacy authentication and changes to MFA. It is also where the third question pays for itself, because most of what is found here is fixable before anyone uses it.

03

Network infrastructure

DNS, proxy and firewall logs reviewed for command and control, staging and exfiltration patterns, including traffic that looks legitimate at the perimeter.

Traffic that passes a control is not traffic a control approved. Most of what matters here was allowed by a rule that was written for something else.

04

Crown jewels

Critical IT assets and the business applications the organization actually runs on. During analysis most of the attention goes here, deliberately, because these are the systems that carry the most consequence and usually the least coverage.

They are usually not onboarded into the SIEM at all, and almost never included in a hunt, so in most estates nobody has examined them the way an assessment does. Where nothing can read a log, a parser is built for it so that system stays in scope.

What the work typically finds

Four things turn up in most environments.

Patterns across engagements, not any one client. Set out here because a buyer deserves to know roughly what a report contains before commissioning one.

FINDING 01

PRIOR INCIDENTS

NEVER FULLY CLOSED

Leftovers from an incident that was already handled.

Where an organization has been through a major incident, remnants of it are still in the estate. Tooling that was never removed, accounts that were never disabled, persistence that survived the remediation, and hosts rebuilt everywhere except the one that mattered.

None of this means the response failed. It means the response ended when the pressure did, which is when everyone stops looking. An assessment is the first time anyone checks the closing state against the estate rather than against the report.

FINDING 02

PENETRATION TESTING

TRACES AND LEFTOVERS

Traces of penetration testing, in three forms.

The first is the tooling and the techniques a tester left behind. On the evidence alone these look the same as an intruder, and separating the two is work that has to be done before anything else can be believed.

The second matters more. The technologies a penetration test usually targets have been hardened, but partially. A vulnerable network protocol is disabled on most hosts and still answering on the rest. A setting is corrected in one forest and not the other. The finding was closed in the report and not in the estate, and the half that was missed is the half still reachable.

The third is what the test itself switched on and nobody switched off. An account created for the engagement, given the privilege it needed to prove a point, and still in that group months later. Credentials shared across a team during the test and never rotated afterwards. Delegation and trust attributes written onto computer or service objects to demonstrate a path to a privileged identity, left in place once the path was demonstrated.

None of it was careless at the time. Each change was deliberate, scoped to the test, and meant to be reverted. The test ended, the report was delivered, and the environment was never put back. What remains is not a finding the report describes. It is exposure the test created, and it is usually held by an account nobody is watching.

FINDING 03

IDENTITY AND ENDPOINT

PATHS, NOT HOLES

Configuration that leaves an attacker room to move.

Active Directory, Entra ID and the endpoint security controls, configured in ways that hand an adversary options. Delegation, privilege, trust relationships, policy exceptions and control settings decided for convenience years ago and never revisited since.

These are not vulnerabilities in the sense a scanner reports. Nothing here is unpatched. They are paths, and there are usually more of them than anyone in the organization expects, because no single change looked dangerous on the day it was made.

FINDING 04

IDENTITY COMPROMISE

MISSED BY MONITORING

Credentials already in someone else’s hands.

Two independent sources tend to point at the same accounts. The first is deep research into the places stolen credentials are traded, run against the organization’s domains and its people rather than against a keyword. The second is in the estate’s own authentication logs: the pattern left by a credential broker checking a list, testing which of the logins they are holding are live and which were fabricated by whoever sold them.

That second pattern is easy to dismiss as noise. It is not a brute force run and does not look like one. It is a measured pass against real usernames, sized to answer a commercial question rather than to break in: how much of this list is still good. By the time it appears, the credentials have already changed hands.

Many organizations already buy brand protection or credential monitoring, and it rarely surfaces what an assessment finds. Those services watch the sources that are straightforward to watch. The credentials that matter are usually somewhere else, in a set that was never posted publicly because it was sold directly. A valid login is the cheapest way into an estate: it needs no vulnerability, and on the day it is used it does not look like an attack.

Repeating the assessment on a cycle turns the path inventory into a shrinking list: each round closes routes an attacker would have taken, and the next round starts from a smaller set.

How an engagement runs

Five phases, kick-off to report review.

An assessment is not a snapshot. It reads backwards as far as the estate still remembers, and forwards for the four weeks it is running, collecting more than the estate was keeping on its own.

EVIDENCE AVAILABLE how much there is to work with, before and during LIMITED BY RETENTION DFIR ARTIFACTS AND TELEMETRY YEARS WEEKS ENGAGEMENT START EVIDENCE THE ESTATE ALREADY KEPT WHAT THE ASSESSMENT COLLECTS ENHANCED AUDITING AND EVIDENCE COLLECTION ASSESSMENT PHASES agreed in writing before anything begins PHASE 01 Kick-off and planning scope, in writing PHASE 02 Velociraptor deployment your accounts PHASE 03 Data collection the agreed scope PHASE 04 Triage of hits a person decides PHASE 05 Report and review walked through Both sides of the line are in scope. How far back the assessment can read depends on what the estate kept, not on how hard anyone looks. From the first day on site the assessment collects more than the estate was keeping: auditing raised, and DFIR tooling it does not normally run.
PHASE 01

Kick-off and planning

Objectives, scope and scale are established: the critical assets, systems and network segments to examine.

Agreed in writing before anything begins.

PHASE 02

Velociraptor deployment

Collection tooling is deployed into your environment, under accounts your team issues.

Residency and classification rules are fixed inputs from the first call, not obstacles negotiated later.

PHASE 03

Data collection

Endpoint, identity, network infrastructure and business application data is gathered across the agreed scope.

Auditing is raised where it was too thin to answer the question, so the estate starts producing evidence it was not producing before.

PHASE 04

Triage of hits

Current threat intelligence supplies known indicators and adversary techniques. Automated analysis narrows the field.

A senior investigator then confirms or dismisses each candidate and assesses its impact.

PHASE 05

Report and review

Findings are written up, then walked through with your team so every one is clear and well understood, together with the plan to act on it.

What you receive

Four documents, written to be acted on.

Every conclusion states what was observed, what it supports, and the confidence attached to it. Where the evidence does not settle a question, that is written down.

Executive summary A high-level account for senior management: scope, method, key findings and the actions they imply, in business terms.
Detailed findings report Every indicator of compromise with its nature, affected systems, supporting evidence, and an analysis of the impact on security and operations.
Prioritized remediation plan Short-term fixes for immediate threats and longer-term measures to raise the posture, sequenced by consequence rather than drawn from a catalog.
Presentation and debriefing A formal presentation to your stakeholders and a working session to discuss results, agree next steps and transfer what was learned.

The method, in the open

Four things decide how an assessment is run.

The crown jewels are named before collection starts Which systems carry the most consequence is settled with the organization at kick-off and agreed in writing, rather than inferred from an asset inventory once analysis is under way. That list is what decides where the depth goes.
The threat landscape sets the hunts and the hardening What gets hunted, and what gets hardened afterwards, are both derived from who targets an organization of this profile and how those actors operate. The threat picture is built first, so the assessment looks for what is likely and the recommendations close what those actors actually use.
Evidence, down to the artifact Analysis reaches the raw forensic sources: file system metadata and journals, registry hives, execution remnants and process memory. That depth is what makes the thinnest trace recoverable, and what lets every conclusion cite the artifact it rests on.
One estate, not separate engagements Windows, macOS, Linux, the Microsoft cloud and the line-of-business applications are investigated as a single environment. An intrusion that begins on a laptop and ends in a cloud tenant is followed across every platform it crosses.

Who this is for

Where the call usually comes from.

After a major incident Organizations that have been through a major incident and want to know what the response left behind, including the systemic control weaknesses it exposed rather than only the incident itself.
Leaked credentials or documents A brand protection alert naming leaked credentials or documents, where the open question is whether any of it has already been used inside the estate.
After a penetration test or red team Significant findings from an offensive engagement, on the reasoning that a threat actor could have found the same paths, and may already have.
Posture validation Leadership that wants the current security posture established against evidence rather than against a control inventory.
A changed estate Estates after a merger, a divestment or a rapid cloud migration, where the visibility gaps have never been mapped.

What is needed to scope it

Four numbers are enough to price it.

Endpoints A count of the endpoints in the estate.
Applications How many are hosted, and how many are exposed to the internet.
Users A count of the users in the environment.
Microsoft cloud Whether Microsoft Entra ID and Microsoft 365 are in use.

Scoping starts with a conversation, not a questionnaire. If a compromise assessment is the wrong instrument for the question, that is said plainly at the first call.

NEXT / RELATED SERVICE

Digital Forensics and Incident Response

When the assessment finds something that cannot wait for a report.

NEXT / SCOPING

Engage

Describe the situation. The call is with the consultant who would run the assessment, not a salesperson.