Popular Articles

  1. Understanding IC-Score

    Threat intelligence is often difficult to leverage in practice due to the high level of noise and lack of coverage provided by most feeds. A typical organization has to purchase multiple subscriptions and develop ad-hoc methods to evaluate and clean...
  2. Protected Theater - Before you Begin

    Before you start the Protected Theater setup, verify the hardware and networking you plan to use will support Protected Theater and that you have gathered all the required information: Protected Theater requires a static IP (only the Protected Act...
  3. Protected Theater Minimum System Requirements

    The specifications in the following table are necessary for the installation of each Protected Theater. Protected Actor Minimum System Requirements are separate and must be considered when configuring the disk (Gold) image requirements. T...
  4. Mandiant Threat Defense

    is a threat detection, investigation and response service that combines the expertise of Mandiant's frontline security analysts and to help organizations protect against cyber threats. The service includes: Active threat detection : con...
  5. Security Technologies that Managed Defense Supports

    The following tables list the supported security technologies, required Google Security Operations parsers, and supported alert types from each vendor that are processed as part of providing security event monitoring and threat hunting services....
  6.  Reviewing Issues

    Issues are respective to the entity type, and different entity types warrant their own issue checks. The most common issue checks are for URI entities. Issue checks are selected based on the technology and version (as captured) that is fingerpri...
  7. Actor Communication Settings

    There are some settings that impact Actor Communication that need to be configured across the platform. The majority of the settings are for running port scans and the "Can Talk to Actor" (CTTA) behaviors, which is automated discovery of connect...
  8. Federated access for the Managed Defense Portal

    The Portal can be integrated with other identity providers for authentication. There are two main types of federation: identity provider (IdP) initiated and service provider (SP) initiated. The Portal supports IdP initiated sign in. An in...
  9. Install and Register a Protected Actor

    Once you have the host image added to the Protected Theater, you can install the Protected Actor. This process involves three steps: Adding the Protected Actor configuration to the Director. Installing the Protected Actor executable on the targ...
  10. Digital Threat Monitoring API