Updated Articles

  1. Mandiant MISP Collector Updated

    Developed By: Mandiant Latest Version: 2.3.0.8 Last Released: June 3, 2026 Key Contact: Download: Docker : mandiant-misp-2308.tar (MD5: 0f1d4dfbc5c2c4ccc59f520712d9db93) Python : mandian...
  2. How Pass/Fail is Determined for Monitors

    When you create a Monitor, you define the expected results for each Action that is run. You can configure the Actions so they match the pass/fail definitions assigned by your Validation Platform Admins, or you can tailor the definitions. Since M...
  3. AEDA Notification Settings

    When you run Monitors, you may want to receive alert notifications. Notification Settings is the feature you use to configure the messages, which can be create in several different formats and profiles. You define what is included in the message, ...
  4. Monitor Configuration Summary

    The AEDA Configuration page lists all Monitors that are configured in the Validation Platform. There are two sections on this page: Disconnected Monitors : Monitors that contain a Sequence or Evaluation that has been modified. Mon...
  5.  Create and Edit Monitors

    You can add a Monitor from several places: From an Action in the Action Library: Go to  Library > Actions then click Monitor .   From a Sequence or Evaluation: after you click Run , click Monitor . From a Job: click the Job's ...
  6. Managed Defense Threat Hunting

    As part of the service offering, analysts perform hunting missions throughout your environments. Hunting missions may be regularly performed (such as checks for commonly used threat vectors by attackers) or ad hoc (for instance, a specific res...
  7. Mandiant Threat Defense Hunting Dashboard

    dashboard is designed to provide you with the information you require to track your subscription service metrics and act on Investigations. uses the customer Google Security Operations (SecOps) instance as the telemetry source and the hu...
  8. Configure Organization Settings

    During your onboarding process, the Mandiant Support team will set up the account of your organization and establish all user accounts and access privileges. The profile page of your organization contains information about the Subscription p...
  9. Use the DTM API

    Overview In this document, we're providing common ways to use the Digital Threat Monitoring (DTM) API. The examples here use the CURL command, but you could also use Postman or your favorite API tool. The maximum number of API reque...
  10.  Working with Managed Defense Dashboards

    When you first log in to the MD Portal, you will see the Dashboard. The Dashboard provides real-time threat information, protection status, and coverage information for all your network and endpoint devices. The Dashboard page is divided into thre...