-
As a new customer, there are several recommended steps as you get started. Start with the basics
Review the Mandiant Managed Defense Service Description for more detail on MD alert handling, reporting processes, and definition of terms.
...
-
The Mandiant Security Validation (MSV) and Mandiant Advantage Security Validation (MA-SV) Protected Theater (PT) is an isolated virtual environment that lets you safely test the efficacy of endpoint security controls against destructive behaviors. E...
-
Using inbound integrations, leverages the API of various infrastructure vendors (DNS, cloud, and code repositories) to automatically pull or retrieve assets upon every scan refresh. is directly applied to your attack surface. For more informati...
-
To assist with troubleshooting, support logs are helpful. There are various types of Director and Actor logs available when you create your support logs, as listed in the following tables. See Checking Security Validation System Status and Col...
-
Learn more about the Mandiant Advantage for Splunk app.
-
The initial setup of the Protected Theater can be completed in VMware or Hyper-V. Before adding and configuring the environment, verify the hardware you selected meets Protected Theater Minimum System Requirements and you have addressed everythi...
-
An effective monitor in is one that targets the content that’s relevant to your needs, while minimizing the amount of false-positives (noise). To build effective monitors, we recommend that you first explore existing data using Research Tools t...
-
The Actor platform determines specific Actions that can be run. Refer to this table to see which Actions are supported on which Actor platforms. Actor Platforms→ Windows Endpoint macOS Endpoint Linux Network (CentOS/RHEL/Rocky Linux & Amazon...
-
You can deploy a Linux Actor as a pre-configured Appliance (AWS, Azure, Hyper-V, or OVA) or install the Software directly on your own Linux system.
For software installations, the general process involves preparing the OS, running the ins...
-
Monitors in let you define conditions for searching artifacts (called Documents) collected from the deep and dark web for exposures relevant to your organization.
You can create your own custom Monitor, or you can use any of the Monitor cre...