|
Documentation
Refine
Mandiant Advantage
How to Use - Features & Guides
Expertise On Demand
Integrations & Apps
Data Processing
Attack Surface Management
Getting Started with Attack Surface Management
Guides
Integrations
Resources
API
Release Notes
Managed Services
Managed Defense
Mandiant Threat Defense
Security Validation
Security Validation: MSV (on-prem) and MA-SV (SaaS)
Threat Intelligence
Security Operations and Fusion Subscriptions
Digital Threat Monitoring
On-Demand Intelligence Access
Use Cases: Applying Threat Intelligence
Threat Scoring
Service Descriptions
Homepage Placeholder Helper
User Management
Integrations
APIs
Mandiant Security Validation (MSV and MA-SV) API
Threat Intelligence API
Videos
Release Notes
Attack Surface Management
Managed Defense
Mandiant Threat Defense
Security Validation MSV (On-Prem)
Security Validation MA-SV (SaaS)
Threat Intelligence
Glossary
Other Offerings
Training
Customer Support
Customer Success
Significant Events
Table of Contents
Table of Contents
Toggle navigation
Refine
Mandiant Advantage
How to Use - Features & Guides
Expertise On Demand
Integrations & Apps
Data Processing
Attack Surface Management
Getting Started with Attack Surface Management
Guides
Integrations
Resources
API
Release Notes
Managed Services
Managed Defense
Mandiant Threat Defense
Security Validation
Security Validation: MSV (on-prem) and MA-SV (SaaS)
Threat Intelligence
Security Operations and Fusion Subscriptions
Digital Threat Monitoring
On-Demand Intelligence Access
Use Cases: Applying Threat Intelligence
Threat Scoring
Service Descriptions
Homepage Placeholder Helper
User Management
Integrations
APIs
Mandiant Security Validation (MSV and MA-SV) API
Threat Intelligence API
Videos
Release Notes
Attack Surface Management
Managed Defense
Mandiant Threat Defense
Security Validation MSV (On-Prem)
Security Validation MA-SV (SaaS)
Threat Intelligence
Glossary
Other Offerings
Training
Customer Support
Customer Success
Significant Events
Refine
Mandiant Advantage
How to Use - Features & Guides
Expertise On Demand
Integrations & Apps
Data Processing
Attack Surface Management
Getting Started with Attack Surface Management
Guides
Integrations
Resources
API
Release Notes
Managed Services
Managed Defense
Mandiant Threat Defense
Security Validation
Security Validation: MSV (on-prem) and MA-SV (SaaS)
Threat Intelligence
Security Operations and Fusion Subscriptions
Digital Threat Monitoring
On-Demand Intelligence Access
Use Cases: Applying Threat Intelligence
Threat Scoring
Service Descriptions
Homepage Placeholder Helper
User Management
Integrations
APIs
Mandiant Security Validation (MSV and MA-SV) API
Threat Intelligence API
Videos
Release Notes
Attack Surface Management
Managed Defense
Mandiant Threat Defense
Security Validation MSV (On-Prem)
Security Validation MA-SV (SaaS)
Threat Intelligence
Glossary
Other Offerings
Training
Customer Support
Customer Success
Significant Events
Home
Glossary
Mandiant Advantage
How to Use - Features & Guides
Platform Navigation
Custom Dashboards
Custom Dashboard Widgets
Custom Dashboard Use Case
Expertise On Demand
Getting Started with Expertise On Demand
Expertise On Demand Use Cases
Expertise On Demand Service Description
Expertise On Demand List of Available Services
Integrations & Apps
Mandiant Advantage for Splunk
Data Processing
Geographic Data Processing
GDPR: Subprocessors
Attack Surface Management
Getting Started with Attack Surface Management
Core Concepts
Understanding Attack Surface Management Seeds
ASM Issue Severity Definitions and Examples
Collections Tips and Tricks
ASM Roles and Permissions
Attack Surface Management User Roles
Attack Surface Management Onboarding
Comparing Attack Surface Management versions
How Attack Surface Management differs from vulnerability management tools
How DNS Exfiltration Vulnerabilities are Detected
Guides
Projects
Manage Project Membership
Collections
Customize Collections
Create a Collection
Third Party Monitoring Workflow
Assign Roles Within a Collection
Collection Scan Rate
Issue Settings
Account Settings Overview
Notifications
Reviewing Entities
Search Summary
Discovery Context Visualizer
Scan History
Inferred Vulnerabilities
Reviewing Issues
Analyzing SSL/TLS Issues
Bulk Select
Understanding Technologies
Search Syntax for Attack Surface Management
Export Search Results
ASM Organization Switcher
Opt Out of Attack Surface Management Scanning
Insights Overview
Integrations
Inbound Integrations
Attack Surface Management Credential Security Details
ASM Mandiant Advantage Threat Intelligence Integration
ASM Akamai Integration
ASM AWS Integration
ASM AWS Integration Considerations
ASM AWS Integration
Scale AWS Integration Across AWS Organizations
ASM Azure Integration
ASM Cloudflare Integration
ASM DNS Made Easy Integration
ASM GitHub Integration
ASM GoDaddy Integration
ASM Google Cloud Integration
Scale Google Cloud Integration
Outbound Integrations
ASM Google SecOps SIEM Integration
ASM Google SecOps SOAR Integration
ASM Cortex XSOAR Integration
ASM Jira Integration
ASM ServiceNow Integration
ASM Splunk Integration
Other Integrations
ASM and Security Command Center
Resources
How Issues Work
How Collections Work - Default Tasks
Assessment Capabilities
How to Set Entities Out of Scope
Task Library
ASM Scan Ranges
How to delete an ASM project
API
Attack Surface Management API Limits and Quotas
Release Notes
Managed Services
Federated access for the Managed Defense Portal
Managed Defense
Getting Started with Managed Defense
Managed Defense Supported Technologies
Security Technologies that Managed Defense Supports
Security Technology Monitors
Onboarding Responsibilities
Administration
Configuring Organization Settings
Setting up your Managed Defense Account
Guides
Working with Managed Defense Dashboards
Viewing and Creating Summary Reports
Managing Announcements
Managed Defense Threat Hunting
MD SOC Containment
Configuring MD User Accounts & Notifications
Resources
The Managed Defense Portal
Managed Defense Terminology
Troubleshooting
Verifying Your Service Health
Managed Defense Escalation Matrix
Managed Defense RACI Chart
API
Mandiant Threat Defense
How Mandiant Threat Defense uses Curated Detections
Mandiant Hunting Dashboard
Onboarding
Enable EDR File Acquisitions for Mandiant Threat Defense
Managed Defense Portal Guide
Configure Organization Settings
Mandiant Threat Defense Hunting Dashboard
Offboarding
Security Validation
Important Security Validation Terminology
Security Validation: MSV (on-prem) and MA-SV (SaaS)
Getting Started with Security Validation
Environment Safety
Addressing Security Concerns with Security Validation
System Requirements
Security Validation Component Requirements Overview
Network Actor Requirements
Network Communication Requirements
Endpoint Actor Requirements
Protected Theater Minimum System Requirements
Protected Actor Minimum System Requirements
Director System Requirements
Proxy Allow List Requirements
Installation Decisions
Pre-Installation Decisions - Actor
Pre-Installation Considerations
Install & Deploy
Install the Director
MSV Director Install: Before You Begin
Director Installation
Director Installation: Next Steps
Actor Installation - Before You Begin
Windows 64-bit Actor Artifacts and Services
Easy Actor Installation
Handling software dependencies
Configure Windows Accounts
General Actor Install & Registration
Adding the Endpoint Actor Configuration to the Director
Adding the Network Actor Configuration to Director
Adding the Actor Configuration - API
Registering the Actor using Bulk Registration Tokens
Register the Windows Endpoint Actor
Registering Your Linux Actor - Automated Method (Command Line)
Deploy Mandiant Security Validation on Google Cloud
Installing the Linux Actor
Configure the Linux Environment to support installation of the Security Validation Actor
Linux Actor Installation
Verify Linux Actor Configuration after Installation
Updating the sshd_config File
Sudo Commands Explained - Actor
Sudo Calls List
Installing the Mac Actor
Mac Actor Installation
Configuring MacOS Users for Bash
Installing the Windows Actor
Windows Actor Installation
Actors in the Cloud
AWS Configuration Requirements
Configuration for Actors in the Cloud
Mandiant-hosted Cloud Actors
Confirming Actor-Director Communication
Getting Started with Security Validation's TAAM
Accessing Validation Resources
Security Validation Quick-Start Workbook
Security Validation Use Cases
Validation Platform Credentials
Security Validation Icons
Security Validation Actor Overview
Supported Action Types for Actors
Administration
Actors
Actor Communication Settings
Adding Network Actor Interfaces
Setting the Alternate Hostname
Editing an Actor
Add a Custom Certificate to your Linux Actor
Update the Actor Test Interface to use a Signed Certificate
Viewing an Actor's Network Settings
Configure Source-Based Routing for Network Actors
Reattach an Actor
Managing your Actor's SSH Keys
Uninstalling Actors
Uninstalling the Director
Authentication Settings
Using Active Directory for Authentication
Use Active Directory and Google Authenticator for Authentication
Use Google Authenticator for Authentication
Using SAML for Authentication
X.509 PKI Authentication Setup with SAML
Email & Email Theater
Managing Email Settings
Configure Email Action Settings
Managing Email Actions Settings (Profiles & Rules)
Networking and Communications
Add Network Actor Static Routes
Manage NTP Servers Settings
Virtual Addresses
Updating a Linux Actor's Network Settings
Applying Network Settings
Configuring DNS Settings
Network Settings
Proxy Overview
Proxy Settings
Protected Theaters & Protected Actors
Protected Theater Settings
Editing Protected Theater or Protected Actor Settings
Creating and Managing PT Snapshots
Adding Disk Storage to the Protected Theater
Upgrading your Protected Theater and Protected Actor
Security Content
Running Actions – Admin Settings
Captive IOC Actions Settings
Manage Security Validation Content
Enabling Running Captive IOC Actions for Actors
Password Settings
Add a Custom Certificate to the Director
SSL Settings
User Policy
Manage User Accounts in Security Validation
Add a License
Audit Log Settings
Managing Security Validation Tags
Login Settings
Block Rules Settings
Update Security Validation Components
Managing Security Technologies
Security Validation User Groups and Permissions
Understanding Pass/Fail Rules
Security Zones
Backup and Restore Security Validation
Expand the Actor storage
Expand the Director Storage
Set up your Director to use an external database
Upgrade Security Validation Virtual Appliances to Rocky Linux 8
Using Security Validation
Creating Security Content Overview
Adding Captive DNS Query Actions
Add Captive IOC - URL Actions
Adding Captive IOC - PCAP Actions
Add Email Actions
Adding File Transfer Actions
Add Host Command Line Interface Actions
Adding Malicious DNS Query Actions
Adding Actions from Packet Capture
Adding Protected Theater Actions
Add Socket-based Actions
Adding TCP Port Scan Actions
Adding Web-based Actions
Creating Sequences and Evaluations
Creating Sequences or Evaluations from a File
Clone or Edit a Sequence or Evaluation
Creating File Library Templates
Generating a Data Exfil File
Managing Files in the File Library
Running Security Content and Working with Jobs
Run Actions
Run Actions Based on Action Tags
Running Bulk Actions
Viewing Bulk Job Results
Run Email Actions
Run All Actions as an Evaluation
Run Protected Theater Actions
Local Web Server for In-Memory Host CLI Actions
Supported Actions for Run As User
Work with Sequences and Evaluations
Run Evaluations
Run Sequences
Map - Running Sequences and Evaluations
Bundle Security Content Using Assessments
Configure Assessments
Manage Assessments
Run Content from an Assessment
Work with Job Results from Assessments
Print the Job Results
View Events
Delete Jobs
Reassign, Suppress, and Drop Events from Jobs
Filter Jobs
View Individual Jobs
Export Jobs
Override Action Results
Run a PCAP Action as a Captive IOC PCAP Action
Add Notes and Attachments to Jobs
Testing Cloud Controls
Cloud Validation Module and Cloud Actions Overview
Cloud Profiles
Run Cloud Actions
Add Cloud Actions
Testing Ransomware Defense Controls
Get Started with Ransomware Defense in Security Validation
Check Ransomware Exposure using Security Validation
Working with MSV Reports
Viewing Job Reports
Managing Job Reports
Managing the Summary Report
Filtering the MITRE ATT&CK Dashboard
Manage Gauges
Working with Uncategorized Detected Actions
Working with Uncategorized Prevented Actions
Monitoring your Network with AEDA
Create and Edit Monitors
Working with Failed Monitors
Working with Disconnected Monitors
Working with Monitor Groups
Working with Monitor Notification Formats
Managing Notifications
Creating a .csv of all Actions
How can I change the time on the Mandiant Security Validation Director User Interface?
Job Notification Formats
Switching Security Validation Organizations
Associating an Evaluation or Sequence to a Threat Actor
Creating a Security Validation API Key
Managing Threat Actors in Security Validation
Integrations and Security Technologies
Integrations Overview
Manage Integrations
Configure Mandiant SecOps Integrations (MSI)
SIEM
AT&T USM Anywhere Integration with Security Validation
AWS CloudTrail Integration with Security Validation
AWS GuardDuty Integration with Security Validation
Anomali Security Analytics with Security Validation
ArcSight Integration with Security Validation
Cisco FirePower Integration with Security Validation
Crowdstrike Logscale Integration with Security Validation
Crowdstrike Next-Gen SIEM Search Integration with Security Validation
Darktrace Integration with Security Validation
Devo Integration with Security Validation
Elasticsearch Integration with Security Validation
Exabeam Cloud Integration with Security Validation
Exabeam Datalake Integration with Security Validation
Extrahop Reveal 360 Integration with Security Validation
Google BigQuery Integration with Security Validation
Google Chronicle Integration with Security Validation
Google Cloud Logging Integration with Security Validation
Graylog Integration with Security Validation
IBM Qradar Integration with Security Validation
Juniper JSA Integration with Security Validation
LogRhythm Cloud Integration with Security Validation
LogRhythm Elastic Integration with Security Validation
LogRhythm SQL Integration with Security Validation
Logzilla Integration with Security Validation
Microsoft Azure Log Analytics Integration with Security Validation
Microsoft Azure Sentinel Integration with Security Validation
Microsoft Graph API Integration with Security Validation
Opensearch Integration with Security Validation
RSA NetWitness Respond Integration with Security Validation
Rapid7 InsightIDR Integration with Security Validation
Securonix Integration with Security Validation
Splunk Integration with Security Validation
Sumo Logic Integration with Security Validation
DevOps
AWS CloudWatch Integration with Security Validation
Endpoint
Carbon Black Predictive Security Cloud (PSC) Integration with Security Validation
Carbon Black Protection Integration with Security Validation
Carbon Black Response Integration with Security Validation
CrowdStrike Integration with Security Validation
Cybereason Integration with Security Validation
Cylance Integration with Security Validation
Endgame Integration with Security Validation
Exabeam Analytics Integration with Security Validation
Microsoft Defender for Endpoint Integration with Security Validation
Netskope Integration with Security Validation
Palo Alto Networks Cortex XDR Integration with Security Validation
Palo Alto Networks Cortex XSIAM Integration with Security Validation
SentinelOne Integration with Security Validation
Sophos Cloud Integration with Security Validation
Symantec DLP Integration with Security Validation
Symantec Endpoint Protection Integration with Security Validation
Symantec Endpoint Security Integration with Security Validation
Tanium Threat Response Integration with Security Validation
Trellix Endpoint Detection and Response with Security Validation
Trellix Endpoint Security (HX) Integration with Security Validation
Trellix Enterprise Security Manager Integration with Security Validation
Trellix Network DLP with Security Validation
Trellix ePolicy Orchestrator (ePO) Integration with Security Validation
Trend Micro Trend Vision One Integration with Security Validation
Log Management
Better Stack Logs Integration with Security Validation
Network
Checkpoint Integration with Security Validation
Extrahop Enterprise Integration with Security Validation
Palo Alto Next-Gen Firewall Integration with Security Validation
RSA NetWitness Logs & Packets Integration with Security Validation
Tipping Point Integration with Security Validation
Trellix Email Security - Cloud (ETP) Integration with Security Validation
Trellix IPS Integration with Security Validation
Trellix Network Security (NX) Integration with Security Validation
iBoss Integration with Security Validation
Database
Clickhouse Integration with Security Validation
Snowflake Integration with Security Validation
Threat Detection
F5 Threat Stack Integration with Security Validation
SecureWorks Taegis XDR integration with Security Validation
Device Management
Fortianalyzer Integration with Security Validation
Configure the Mandiant SecOps Integrations (MSI) Service for OVA-based Directors
Configure the Mandiant SecOps Integrations (MSI) Service for Installer-Based Directors
Troubleshoot MSI Integrations
Remote Integrations
Integration Error Messages for MSI Service
Event Filtering
Event Filter Rules
Working with Event Filter Rules
Using Event Filter Rules
Endpoint Integrations (Legacy/Classic)
Carbon Black CB Response
Carbon Black Cloud
Cisco Advanced Malware Protection (AMP)
CrowdStrike
Cybereason
Cylance
Endgame
Trellix Endpoint Security (HX)
Trellix Endpoint Security
Microsoft Defender Advanced Threat Protection (ATP)
Netskope
Palo Alto Networks Cortex XDR
SentinelOne
Sophos Central
Symantec Endpoint Protection
Symantec Data Loss Prevention (DLP)
Network Integrations (Legacy/Classic)
AWS CloudTrail
AWS CloudWatch
AWS GuardDuty
Check Point
Cisco Firepower Management Center (FMC)
Darktrace
Exabeam Advanced Analytics
Trellix Email Security - Cloud (ETP)
Trellix Network Security (NX) Integration
Trellix Network DLP
Palo Alto Networks Firewalls/Panorama
RSA NetWitness
Security Onion - ELK
Security Onion - ELSA
Symantec Data Loss Prevention (DLP)
Threat Stack
Tipping Point IDS/IPS
VMware AppDefense
SIEM Integrations (Legacy/Classic)
AlertLogic
AlienVault
ArcSight
Chronicle Backstory
Devo
Elasticsearch
Exabeam Data Lake
Trellix Helix
Google BigQuery
Google Cloud Logging
Graylog
IBM QRadar
Juniper Secure Analytics (JSA)
LogRhythm Elasticsearch
LogRhythm SQL
LogZilla
Trellix Enterprise Security Manager
Microsoft Azure Log Analytics
Microsoft Azure Sentinel
RSA NetWitness Respond
Securonix SNYPR
Splunk
Splunk Enterprise Security
Viewing Index data for Splunk Events
Sumo Logic
Threat Integrations
Anomali - TAAM Integration
CrowdStrike Intel
Mandiant Threat Intelligence - TAAM Integration
Intel471 - TAAM Integration
ThreatConnect
Threat Quotient - TAAM Integration
Windows Security Technologies
Windows Defender: Establish Exclusions
CrowdStrike: Exclusions & Local Logs
SentinelOne: Configure Exclusions
Protected Theater User & Admin Guide
Protected Theater Overview
Protected Theater in the Director
Protected Theater - Before you Begin
Installing Protected Theater
Protected Theater install - Add and configure the PT Virtual Environment
Verify Virtualization
Set up Networking for Protected Theater
Protected Theater Install - Register the Protected Theater
Configure Gold Images for Protected Theater
Import and Install the Gold Image to the Protected Theater
Windows Services for Protected Actor
Install and Register a Protected Actor
Protected Theater Configurations
Working with Protected Theater
Add a File to the Endpoint File Library
Connect to Protected Theater using VNC or the Console
Adding files to your Protected Actor
Troubleshooting Protected Theater
Nested Virtualization Not Enabled
PT and File System are not in Sync
Time Sync Issues
PT not responsive
PT - Slow Performance in Hyper-V
Not seeing expected Events when running PT Actions
Unexpected Results when running PT Actions
Updating PT's Windows Virtual Machine Settings
Restarting the PT networking and the PT Actor
Troubleshoot a Protected Theater Image Import Error
Resources
Integrations and Events
Integration Queries Overview
Integrations - Field Details
Variables used in Integration Queries
Correlated Events
Suspicious Events / Missing Events
Security Content and Jobs
Security Content Overview
Security Validation Actions
Security Validation Filters and Dimensions
Sequences & Evaluations
Action Tags
Action Details in Job Results
Sequence and Evaluation Tags
Understanding Job Results
Captive IOC Action Overview
Understanding Job Results - Classic View
Bulk Job Status
Running Actions – Form-Factor & Action Type Limitations
Job Export Fields
Jobs Queue
Understanding Email Action Results
Job Status
Repeating Jobs
Flexible scheduling of Jobs and Monitors
Scheduled Jobs
Security Validation Monitors
Intro to Security Validation's Monitors and Advanced Environmental Drift Analysis (AEDA)
AEDA Dashboard
How Pass/Fail is Determined for Monitors
Monitor Configuration Summary
AEDA Notification Settings
Reporting and Analytics
Security Validation Reports
Report Data Table Column Options
Data Source/Filter Rule Values in Job Reports and the MITRE ATT&CK Dashboard
Summary Report Overview
Heat Map
MITRE ATT&CK® Dashboard
The TAAM Dashboard
Effectiveness Gauges Overview
Effectiveness Validation Process (EVP) Overview
Email Theater
Email Theater Overview
Email Theater Before You Begin
Policy Document: Security Validation Software Version Support
Action User Profiles
Actor Communication Methods
Actor Installer Files
Actors Page in the Director
Actor Support for Web Application Firewalls (WAFs)
Advanced Settings for Security Validation
Audit Log Record Categorization
Overview of Security Validation's Backup and Restore Mechanism
Bulk Registration Tokens
Disaster Recovery Information
Using AWS System Manager with Security Validation
Email Settings for Common Email Providers
File Library
Group Details
The Mandiant Content Service
Network Communications Architecture
Network Map
Organizations Menu
Security Technology Auditing and Definitions
System Settings
Sudoers File Contents
Threat Actor Assurance Module (TAAM) Overview
Understanding Threat Actor Information in Security Validation
Update Your Password
User Preferences
Troubleshooting
Troubleshoot Actors
Actor did not respond - Windows and Protected Theater Actors
Allow Ping for Network Actors
Director IP address changed and now some of the Actor are not working
Failure to install a Linux Actor on Red Hat Enterprise Linux 7.x
Invalid Token Error When Updating the Actor
Issues Adding Interfaces
Issues with Action User Profiles
Operational Status: Actor Tests
Restarting and Rebooting Actors
Reverting Actors to Default State
Resolve Problems during Actor Registration
Some Actions will Not Run if Backend Service Doesn't Have Full Disk Access: Operation Not Permitted Error
Troubleshoot the Director
Address SysLog Configuration Issues with SELinux
Director issues involving the vsetdb command
Director Upgrade Failures due to Low Disk Space
Redis and pgbouncer users and user groups not created after an upgrade
Troubleshoot failed upgrades from MSV 4.14.4.1
Troubleshoot Protected Theater
Troubleshoot Security Content
Action Error Messages
Events Associated with the Wrong Action
Job is missing Events - Splunk / Splunk ES
Troubleshoot Host CLI Action Failures
Why is my Bulk Job Erroring?
Checking Security Validation System Status and Collecting Logs
Generated Support Logs
Operational Readiness
Operational Status
Operational Status Settings
Troubleshooting Security Validation in AWS
Viewing Job Debug Results
Threat Intelligence
Security Operations and Fusion Subscriptions
Getting Started with your Threat Intelligence Subscription
Threat Intelligence Quick Start Guide
Threat Intelligence Guides
Threat Campaigns
Mandiant Techniques and Key Events on the Timeline
Indicators
Threat Intelligence Organization Switcher
Mandiant Advantage Threat Intelligence Browser Plug-in
How to Use MATI's Browser Plugin with Splunk
File Analysis
How to Explore Threat Indicators
Explore Threat Actors
Explore Vulnerabilities
Explore Malware and Tools
Search Threat Intelligence content in MATI
Using the MITRE ATT&CK Framework to Analyze Threat Actors & Malware
Build a Personalized Threat Landscape with Threat Profiles
Threat Intelligence Integrations
Mandiant Advantage for IBM QRadar
Mandiant Advantage Vulnerability Explorer (MAVE) Integration
Mandiant MISP Collector
Updated
Microsoft Sentinel and Defender ATP Integrations Admin Guide (Docker Version)
Microsoft Sentinel and Defender ATP Integrations Admin Guide (Azure Logic App Version)
Palo Alto Cortex XSOAR Integration
Splunk SOAR Integration
Integrating with ThreatQuotient ThreatQ
Elastic SIEM Integration
Threat Intelligence Resources
CVSS Ratings in MATI
Suspected Attribution
How does Mandiant track threat actors?
How Your Threat Landscape Uses AI Recommendations
Threat Intelligence Reports
Manage User Accounts in Threat Intelligence
Manage Threat Intelligence Account Settings
Digital Threat Monitoring
Guides
Create DTM Monitors
Monitor Compromised Credentials
Work with Alerts
Use Research Tools
Configuring DTM Email Notifications
Deleting Monitors and Alerts
Resources
Build Effective Monitors
DTM Monitor & Research Tools Fields
Lucene Queries in DTM
Lucene Queries for DTM Alerts
Monitor Matching Methodology
DTM Alert Severity Definitions and Examples
Digital Threat Monitoring FAQ
Digital Threat Monitoring API
Use the Digital Threat Monitoring API
Digital Threat Monitoring API Limits and Quotas
Digital Threat Monitoring User Roles
On-Demand Intelligence Access
How to submit an On-Demand Intelligence Access request
How to Manage Existing On-Demand Intelligence Access Requests
On-Demand Intelligence Access Service Description
Use Cases: Applying Threat Intelligence
Creating a Cyber Threat Profile
Introduction to an Intelligence-led Threat Hunting Framework
Scoping a Threat Hunt with Intelligence
Integrating Intelligence in Cyber Defense Command and Control
Optimizing the Security Operations Center Using Intelligence
The Role of Threat Intelligence in Incident Response
Acquiring Data from a Threat Hunt by Using Intelligence
Threat Scoring
Indicator Threat Score and Confidence Score Source Descriptions
Indicator Threat Score Methodology
Understanding IC-Score
Service Descriptions
Advanced Intelligence Access Service Description
Custom Threat Intelligence Service Description
Dark Web Analysis Service Description
Executive Intelligence Briefings Service Description
Intelligence Subscriptions Service Description
Managed DTM Service Description
Proactive Intelligence Access Service Description
Cyber Threat Profile Service Description
How Mandiant Rates Vulnerabilities
Vulnerability Intelligence Reporting Overview
Targeted Attack Lifecycle
Proxy Allowlist for Threat Intelligence
Threat Intelligence FAQ
Homepage Placeholder Helper
User Management
Integrations
APIs
Attack Surface Management API
Digital Threat Monitoring API
Use the DTM API
Managed Defense API
Mandiant Security Validation (MSV and MA-SV) API
MA-SV API
MSV 4.14.6.0 API
MSV 4.14.5.0 API
MSV 4.14.4.1 API
MSV 4.14.4.0 API
MSV 4.14.3.3 API
MSV 4.14.3.2 API
MSV 4.14.3.1 API
MSV 4.14.3.0 API
MSV 4.14.2.3 API
MSV 4.14.2.0 API
MSV 4.14.1.0 API
MSV 4.14.0.0 API
MSV 4.13.0.0 API
MSV 4.12.4.1 API
MSV 4.12.4.0 API
MSV 4.12.3.0 API
MSV 4.12.2.0 API
MSV 4.12.1.0 API
MSV 4.12.0.0 API
Creating a Security Validation API Key
Threat Intelligence API
Endpoint Pagination
Threat Intelligence API v3
Public Previews for Threat Intelligence API
Videos
Advantage Videos
Attack Surface Management Videos
Managed Defense Videos
Ransomware Defense Validation Videos
Threat Intelligence and Digital Threat Monitoring Videos
Services Videos
Release Notes
Attack Surface Management
Mandiant Advantage Attack Surface Management End of Life Announcement
April 2, 2026 ASM Discovery Engine Release
January 21, 2026 ASM Discovery Engine Release
December 19, 2025 ASM Discovery Engine Release
December 8, 2025 ASM Discovery Engine Release
December 3, 2025 ASM Discovery Engine Release
November 13, 2025 ASM Discovery Engine Release
October 28, 2025 ASM Discovery Engine Release
October 10, 2025 ASM Discovery Engine Release
September 30, 2025 ASM Discovery Engine Release
May - September 2025 ASM Discovery Engine Releases
May 19, 2025 ASM Discovery Engine Release
April 15, 2025 ASM Discovery Engine Release
February 26, 2025 ASM Discovery Engine Release
February 13, 2025 ASM Discovery Engine Release
January 22, 2025 ASM Discovery Engine Release
December 19, 2024 ASM Discovery Engine Release
December 12, 2024 ASM Discovery Engine Release
November 26, 2024 ASM Discovery Engine Release
November 20, 2024 ASM Discovery Engine Release
November 13, 2024 ASM Discovery Engine Release - Scan Ranges Expanded
November 11, 2024 ASM Discovery Engine Release
October 31, 2024 ASM Discovery Engine Release
October 24, 2024 ASM Discovery Engine Release
October 17, 2024 ASM Discovery Engine Release
October 14, 2024 ASM Discovery Engine Release
October 3, 2024 ASM Discovery Engine Release
October 2, 2024 ASM Discovery Engine Release
September 20, 2024 ASM Discovery Engine Release
September 11, 2024 ASM Discovery Engine Release
August 28, 2024 ASM Discovery Engine Release
August 8, 2024 ASM Discovery Engine Release
July 23, 2024 ASM Discovery Engine Release
July 16, 2024 ASM Discovery Engine Release
July 10, 2024 ASM Discovery Engine Release
July 1, 2024 ASM Discovery Engine Release
June 25, 2024 ASM Discovery Engine Release - Scan Ranges Expanded
June 20, 2024 ASM Discovery Engine Release
June 11, 2024 ASM Discovery Engine Release
May 30, 2024 ASM Discovery Engine Release
May 23, 2024 ASM Discovery Engine Release
May 20, 2024 ASM Discovery Engine Release
May 9, 2024 ASM Discovery Engine Release
May 1, 2024 ASM Discovery Engine Release
April 25, 2024 ASM Release
April 16, 2024 ASM Discovery Engine Release
April 15, 2024 ASM Release
April 4, 2024 ASM Discovery Engine Release
April 3, 2024 ASM Discovery Engine Release - Scan Ranges Expanded
March 28, 2024 ASM Discovery Engine Release
March 28, 2024 ASM Release
March 21, 2024 ASM Discovery Engine Release
March 14, 2024 ASM Discovery Engine Release
March 7, 2024 ASM Discovery Engine Release
March 7, 2024 ASM Release
February 28, 2024 ASM Discovery Engine Release
February 22, 2024 ASM Discovery Engine Release
February 20, 2024 ASM Release
February 15, 2024 ASM Discovery Engine Release
February 8, 2024 ASM Discovery Engine Release
February 1, 2024 ASM Discovery Engine Release
January 23, 2024 ASM Discovery Engine Release
January 12, 2024 ASM Discovery Engine Release
December 15, 2023 ASM Discovery Engine Release
December 15, 2023 ASM Release
December 6, 2023 ASM Discovery Engine Release
December 5, 2023 ASM Release
December 4, 2023 ASM Discovery Engine Release
November 29, 2023 ASM Discovery Engine Release
November 16, 2023 ASM Release
November 15, 2023 ASM Release
November 15, 2023 ASM Discovery Engine Release
November 10, 2023 ASM Discovery Engine Release
November 9, 2023 ASM Discovery Engine Release
November 2, 2023 ASM Release
November 1, 2023 ASM Discovery Engine Release
November 1, 2023 ASM Release
October 30, 2023 ASM Discovery Engine Release
October 19, 2023 ASM Discovery Engine Release
October 11, 2023 ASM Discovery Engine Release
September 29, 2023 ASM Discovery Engine Release
September 25, 2023 ASM Discovery Engine Release
September 12, 2023 ASM Discovery Engine Release
September 11, 2023 ASM Release
September 7, 2023 ASM Release
September 6, 2023 ASM Discovery Engine Release
August 30, 2023 ASM Discovery Engine Release
August 1, 2023 ASM Release
July 31, 2023 ASM Release
July 26, 2023 ASM Release
July 20, 2023 ASM Product Release Announcements
March 28, 2023 ASM Product Release Announcements
December 14, 2022 ASM Release
November 16, 2022 ASM Release
October 2022 ASM Releases
September 2022 ASM Releases
August 2022 ASM Release
July 2022 ASM Release
June 2022 ASM Release
May 2022 ASM Release
April 2022 ASM Release
Managed Defense
April 14, 2026 Managed Defense Release
March 16, 2026 Managed Defense Trellix Announcement
January 29, 2026 Managed Defense Release
January 21, 2026 Managed Defense Release
Mandiant Threat Defense
April 14, 2026 Mandiant Threat Defense Release
March 16, 2026 Mandiant Threat Defense Trellix Announcement
January 29, 2026 Mandiant Threat Defense Release
January 21, 2026 Mandiant Threat Defense Release
November 17, 2025 Mandiant Threat Defense Release
October 9, 2025 Mandiant Threat Defense Release
September 30, 2025 Mandiant Threat Defense Release
April 2, 2024 Mandiant Hunt Release
Mandiant SecOps Integrations (MSI) Service
Security Validation MSV (On-Prem)
Product Update 4.14.6.1 - May 19, 2026
Product Update 4.14.6.0 - May 12, 2026
Product Update 4.14.5.0 - February 19, 2026
2025 Release Archive
Product Update 4.14.4.1 - October 30, 2025
Product Update 4.14.4.0 - September 4, 2025
Product Update 4.14.3.4 - August 14, 2025
Product Update 4.14.3.3 - July 17, 2025
Product Update 4.14.3.2 - June 24, 2025
Product Update 4.14.3.1 - May 8, 2025
Product Update 4.14.3.0 - March 25, 2025
Product Update 4.14.2.3 - February 6, 2025
2024 Release Archive
Product Update 4.14.2.0 - November 21, 2024
Product Update 4.14.1.1 - November 4, 2024
Product Update 4.14.1.0 - August 15, 2024
Product Update 4.14.0.2 - May 16, 2024
Product Update 4.14.0.1 - May 7, 2024
Product Update 4.14.0.0 - April 15, 2024
Product Update 4.13.0.0 - February 26, 2024
Product Update 4.12.4.1 - January 23, 2024
2023 Release Archive
Product Update 4.12.4.0 - December 12, 2023
Product Update 4.12.3.0 - November 21, 2023
Product Update 4.12.2.0 - November 9, 2023
Product Update 4.12.1.0 - October 26, 2023
Product Update 4.12.0.1 - November 3, 2023
Product Update 4.12.0.0 - September 29, 2023
Product Update 4.11.3.0 - September 12, 2023
Product Update 4.11.2.0 - August 17, 2023
Product Update 4.11.1.0 - July 31, 2023
Product Update 4.11.0.0 - June 20, 2023
Product Update 4.10.5.0 - June 7, 2023
Product Update 4.10.4.0 - May 25, 2023
Product Update 4.10.3.0 - May 18, 2023
Product Update 4.10.2.3 - May 10, 2023
Product Update 4.10.2.2 - April 26, 2023
Product Update 4.10.2.1 - April 12, 2023
Product Update 4.10.2.0 - March 13, 2023
Product Update 4.10.1.0 - February 14, 2023
Product Update 4.10.0.1 - January 30, 2023
Product Update 4.10.0.0 - January 12, 2023
2021-2022 Release Archive
Product Update 4.9.2.0 - November 14, 2022
Product Update 4.9.1.1 - October 31, 2022
Product Update 4.9.1.0 - October 19, 2022
Product Update 4.9.0.1 - September 26, 2022
Product Update 4.9.0.0 - September 22, 2022
Product Update 4.8.4.3 - November 3, 2022
Product Update 4.8.4.2 - September 12, 2022
Product Update 4.8.4.1 - July 28, 2022
Product Update 4.8.4.0 - July 12, 2022
Product Update 4.8.3.1 - May 24, 2022
Product Update 4.8.3.0 - April 26, 2022
Product Update 4.8.2.0 - March 21, 2022
Product Release Archive (4.6.1.1 to 4.8.1.0)
Security Validation MA-SV (SaaS)
Product Update 5.14.4.0 - April 30, 2026
2025 Release Archive
Product Update 5.14.3.2 - July 10, 2025
Product Update 5.14.3.1 - June 12, 2025
Product Update 5.14.3.0 - May 22, 2025
Product Update 5.14.2.1 - March 6, 2025
Product Update 5.14.2.0 - February 27, 2025
Product Update 5.14.1.2 - January 14, 2025
2024 Release Archive
Product Update 5.14.1.1 - October 10, 2024
Product Update 5.14.1.0 - October 1, 2024
Product Update 5.14.0.4 - September 25, 2024
Product Update 5.14.0.3 - August 29, 2024
Product Update 5.14.0.2 - July 18, 2024
Product Update 5.14.0.1 - June 13, 2024
Product Update 5.14.0.0 - June 6, 2024
Product Update 5.13.0.3 - April 23, 2024
Product Update 5.13.0.2 - April 18, 2024
Product Update 5.13.0.1 - April 4, 2024
Product Update 5.13.0.0 - March 7, 2024
Product Update 5.12.4.4 - February 29, 2024
Product Update 5.12.4.3 - February 15, 2024
Product Update 5.12.4.2 - February 1, 2024
Product Update 5.12.4.1 - January 25, 2024
Product Update 5.12.4.0 - January 11, 2024
2023 Release Archive
Product Update 5.12.3.0 - November 30, 2023
Product Update 5.12.2.0 - November 21, 2023
Product Update 5.12.1.1 - November 8, 2023
Product Update 5.12.1.0 - November 2, 2023
Product Update 5.12.0.2 - October 31, 2023
Product Update 5.12.0.0 - October 12, 2023
Product Update 5.11.3.0 - September 25, 2023
Product Update 5.11.2.0 - September 5, 2023
Product Update 5.11.1.0 - August 10, 2023
Product Update 5.11.0.0 - July 12, 2023
Product Update 5.10.6.0 - June 28, 2023
Product Update 5.10.5.0 - June 9, 2023
Product Update 5.10.4.0 - May 31, 2023
Product Update 5.10.3.0 - May 24, 2023
Product Update 5.10.2.7 - May 12, 2023
Product Update 5.10.2.6 - May 4, 2023
Product Update 5.10.2.4 - April 25, 2023
Product Update 5.10.2.3 - April 14, 2023
Product Update 5.10.2.2 - April 5, 2023
Product Update 5.10.2.0 - March 23, 2023
Product Update 5.10.1.3 - March 14, 2023
Product Update 5.10.1.2 - March 13, 2023
Product Update 5.10.1.1 - March 3, 2023
Product Update 5.10.1.0 - February 16, 2023
Product Update 5.10.0.0 - January 18, 2023
2022 Release Archive
Product Update 5.9.2.1 - December 21, 2022
Product Update 5.9.2.0 - November 22, 2022
Product Update 5.9.1.0 - November 1, 2022
Product Update 5.9.0.0 - September 22, 2022
Product Update 5.8.4.1 - August 11, 2022
Product Update 5.8.4.0 - July 27, 2022
Product Update 5.8.3.2 - June 16, 2022
Product Update 5.8.3.1 - May 19, 2022
Product Update 5.8.3.0 - May 16, 2022
Product Update 5.8.2.1 - May 4, 2022
Product Update 5.8.2.0 - April 7, 2022
Threat Intelligence
Mandiant Advantage Threat Intelligence End of Life Announcement
Digital Threat Monitoring
November 5, 2025 Mandiant Advantage Threat Intelligence Release
September 4, 2025 Mandiant Advantage Threat Intelligence Release
June 30, 2025 Mandiant Advantage Threat Intelligence Release
April 14, 2025 Mandiant Advantage Threat Intelligence Release
March 24, 2025 Mandiant Advantage Threat Intelligence Release
January 22, 2025 Mandiant Advantage Threat Intelligence Release
January 15, 2025 Mandiant Advantage Threat Intelligence Release
January 29, 2026 Mandiant Advantage Threat Intelligence Release
December 18, 2025 Mandiant Advantage Threat Intelligence Release
October 23, 2025 Mandiant Advantage Threat Intelligence Release
October 15, 2025 Mandiant Advantage Threat Intelligence Release
September 17, 2025 Mandiant Advantage Threat Intelligence Release
September 4, 2025 Mandiant Advantage Threat Intelligence Release
August 7, 2025 Mandiant Advantage Threat Intelligence Release
July 11, 2025 Mandiant Advantage Threat Intelligence Release
June 30, 2025 Mandiant Advantage Threat Intelligence Release
May 27, 2025 Mandiant Advantage Threat Intelligence Release
May 7, 2025 Mandiant Advantage Threat Intelligence Release
April 14, 2025 Mandiant Advantage Threat Intelligence Release
March 24, 2025 Mandiant Advantage Threat Intelligence Release
February 19, 2025 Mandiant Advantage Threat Intelligence Release
2024 Release Archive
December 30, 2024 Mandiant Advantage Threat Intelligence Release
December 18, 2024 Mandiant Advantage Threat Intelligence Release
December 17, 2024 Mandiant Advantage Threat Intelligence Release
December 11, 2024 Mandiant Advantage Threat Intelligence Release
November 20, 2024 Mandiant Advantage Threat Intelligence Release
November 11, 2024 Mandiant Advantage Threat Intelligence Release
October 29, 2024 Mandiant Advantage Threat Intelligence Release
October 23, 2024 Mandiant Advantage Threat Intelligence Release
October 8, 2024 Mandiant Advantage Threat Intelligence Release
September 25, 2024 Mandiant Advantage Threat Intelligence Release
August 19, 2024 Mandiant Advantage Threat Intelligence Release
August 8, 2024 Mandiant Advantage Threat Intelligence Release
July 29, 2024 Mandiant Advantage Threat Intelligence Release
July 24, 2024 Mandiant Advantage Threat Intelligence Release
July 11, 2024 Mandiant Advantage Threat Intelligence Release
June 25, 2024 Mandiant Advantage Threat Intelligence Release
June 20, 2024 Mandiant Advantage Threat Intelligence Release
June 5, 2024 Mandiant Advantage Threat Intelligence Release
May 30, 2024 Mandiant Advantage Threat Intelligence Release
May 29, 2024 Mandiant Advantage Threat Intelligence Release
May 21, 2024 Mandiant Advantage Threat Intelligence Release
May 13, 2024 Mandiant Advantage Threat Intelligence Release
May 8, 2024 Mandiant Advantage Threat Intelligence Release
May 3, 2024 Mandiant Advantage Threat Intelligence Release
May 1, 2024 Mandiant Advantage Threat Intelligence Release
April 30, 2024 Mandiant Advantage Threat Intelligence Release
April 22, 2024 Mandiant Advantage Threat Intelligence Release
April 17, 2024 Mandiant Advantage Threat Intelligence Release
March 26, 2024 Mandiant Advantage Threat Intelligence Release
March 11, 2024 Mandiant Advantage Threat Intelligence Release
March 7, 2024 Mandiant Advantage Threat Intelligence Release
February 26, 2024 Mandiant Advantage Threat Intelligence Release
February 13, 2024 Mandiant Advantage Threat Intelligence Release
February 6, 2024 Mandiant Advantage Threat Intelligence Release
January 30, 2024 Mandiant Advantage Threat Intelligence Release
2023 Release Archive
December 13, 2023 Mandiant Advantage Threat Intelligence Release
December 5, 2023 Mandiant Advantage Threat Intelligence Release
November 17, 2023 Mandiant Advantage Threat Intelligence Release
November 14, 2023 Mandiant Advantage Threat Intelligence Release
October 10, 2023 Mandiant Advantage Threat Intelligence Release
September 27, 2023 Mandiant Advantage Threat Intelligence Release
September 26, 2023 Mandiant Advantage Threat Intelligence Release
September 8, 2023 Mandiant Advantage Threat Intelligence Release
August 23, 2023 Mandiant Advantage Threat Intelligence Release
August 17, 2023 Mandiant Advantage Threat Intelligence Release
August 10, 2023 Mandiant Advantage Threat Intelligence Release
August 1, 2023 Mandiant Advantage Threat Intelligence Release
July 10, 2023 Mandiant Advantage Threat Intelligence Release
June 23, 2023 Mandiant Advantage Threat Intelligence Release
June 7, 2023 Mandiant Advantage Threat Intelligence Release
May 15, 2023 Mandiant Advantage Threat Intelligence Release
May 8, 2023 Mandiant Advantage Threat Intelligence Release
April 19, 2023 Mandiant Advantage Threat Intelligence Release
March 30, 2023 Mandiant Advantage Threat Intelligence Release
March 14, 2023 Mandiant Advantage Threat Intelligence Release
February 24, 2023 Mandiant Advantage Threat Intelligence Release
February 6, 2023 Mandiant Advantage Threat Intelligence Release
2022 Release Archive
November 15, 2022 Mandiant Advantage Threat Intelligence Release
October 27, 2022 Mandiant Advantage Threat Intelligence Release
October 18, 2022 Mandiant Advantage Threat Intelligence Release
October 12, 2022 Mandiant Advantage Threat Intelligence Release
September 30, 2022 Mandiant Advantage Threat Intelligence Release
September 15, 2022 Mandiant Advantage Threat Intelligence Release
August 30, 2022 Mandiant Advantage Threat Intelligence Release
August 18, 2022 Mandiant Advantage Threat Intelligence Release
August 10, 2022 Mandiant Advantage Threat Intelligence Release
August 4, 2022 Mandiant Advantage Threat Intelligence Release
July 19, 2022 Mandiant Advantage Threat Intelligence Release
July 11, 2022 Mandiant Advantage Threat Intelligence Release
June 29, 2022 Mandiant Advantage Threat Intelligence Release
Glossary
Other Offerings
Mandiant-delivered webinars
Hardening, Mitigation, and Remediation Guides
Training
On-Demand Intelligence Training
Cyber Security Training Opportunities
Customer Support
How to Generate a HAR File for the Support Team
Customer Success
Significant Events
Article updates
Home
Release Notes
Threat Intelligence
2022 Release Archive
November 15, 2022 Mandiant Advantage Threat Intelligence Release
October 27, 2022 Mandiant Advantage Threat Intelligence Release
October 18, 2022 Mandiant Advantage Threat Intelligence Release
October 12, 2022 Mandiant Advantage Threat Intelligence Release
September 30, 2022 Mandiant Advantage Threat Intelligence Release
September 15, 2022 Mandiant Advantage Threat Intelligence Release
August 30, 2022 Mandiant Advantage Threat Intelligence Release
August 18, 2022 Mandiant Advantage Threat Intelligence Release
August 10, 2022 Mandiant Advantage Threat Intelligence Release
August 4, 2022 Mandiant Advantage Threat Intelligence Release
July 19, 2022 Mandiant Advantage Threat Intelligence Release
July 11, 2022 Mandiant Advantage Threat Intelligence Release
June 29, 2022 Mandiant Advantage Threat Intelligence Release
First Published:
June 3, 2026
Last updated:
June 3, 2026
In This Article
Related Articles
Was This Article Helpful?