Updated Articles

  1. Configure Organization Settings

    During your onboarding process, the Mandiant Support team will set up the account of your organization and establish all user accounts and access privileges. The profile page of your organization contains information about the Subscription p...
  2. Use the DTM API

    Overview In this document, we're providing common ways to use the Digital Threat Monitoring (DTM) API. The examples here use the CURL command, but you could also use Postman or your favorite API tool. The maximum number of API reque...
  3.  Working with Managed Defense Dashboards

    When you first log in to the MD Portal, you will see the Dashboard. The Dashboard provides real-time threat information, protection status, and coverage information for all your network and endpoint devices. The Dashboard page is divided into thre...
  4.  Adding Users

    One of the first things you will need to do is to add users, typically the analysts in your security operations center and grant them the permissions they need to do their job. To add a new user: You can add users from the User Management pa...
  5. Managing Announcements

    MD uses the Announcements page to communicate important information to your team. These communications include standard announcements, blog posts, Intel, and highlights related to current threats or attacks. Only Mandiant MD users with Team Adm...
  6. Managed Defense Terminology

    The following definitions are specific to the Managed Defense (MD) topics in this documentation portal. Term Description Supported Technology Products or subscriptions supported by MD Security Event(s) An observable occurrenc...
  7. Protected Theater Minimum System Requirements

    The specifications in the following table are necessary for the installation of each Protected Theater. Protected Actor Minimum System Requirements are separate and must be considered when configuring the disk (Gold) image requirements. T...
  8. Federated access for the Managed Defense Portal

    The Portal can be integrated with other identity providers for authentication. There are two main types of federation: identity provider (IdP) initiated and service provider (SP) initiated. The Portal supports IdP initiated sign in. An in...
  9.  Managing Notifications

    A Notification Profile is how you link Monitors or Monitor Groups to a specific Notification Format and how you define the notification interval. A Notification Profile is also required to receive automatic notifications if a Job for a Monitor err...
  10.  Working with Monitor Notification Formats

    The Notification Format defines how you want the platform to notify you when an alert is generated by Monitor Actions or when a Monitor errors. There are three types of notification formats available: Email : Sends the notifi...