Updated Articles

  1. Managed Defense Threat Hunting

    As part of the service offering, analysts perform hunting missions throughout your environments. Hunting missions may be regularly performed (such as checks for commonly used threat vectors by attackers) or ad hoc (for instance, a specific res...
  2. Mandiant Threat Defense Hunting Dashboard

    dashboard is designed to provide you with the information you require to track your subscription service metrics and act on Investigations. uses the customer Google Security Operations (SecOps) instance as the telemetry source and the hu...
  3. Configure Organization Settings

    During your onboarding process, the Mandiant Support team will set up the account of your organization and establish all user accounts and access privileges. The profile page of your organization contains information about the Subscription p...
  4. Use the DTM API

    Overview In this document, we're providing common ways to use the Digital Threat Monitoring (DTM) API. The examples here use the CURL command, but you could also use Postman or your favorite API tool. The maximum number of API reque...
  5.  Working with Managed Defense Dashboards

    When you first log in to the MD Portal, you will see the Dashboard. The Dashboard provides real-time threat information, protection status, and coverage information for all your network and endpoint devices. The Dashboard page is divided into thre...
  6.  Adding Users

    One of the first things you will need to do is to add users, typically the analysts in your security operations center and grant them the permissions they need to do their job. To add a new user: You can add users from the User Management pa...
  7. Managing Announcements

    MD uses the Announcements page to communicate important information to your team. These communications include standard announcements, blog posts, Intel, and highlights related to current threats or attacks. Only Mandiant MD users with Team Adm...
  8. Managed Defense Terminology

    The following definitions are specific to the Managed Defense (MD) topics in this documentation portal. Term Description Supported Technology Products or subscriptions supported by MD Security Event(s) An observable occurrenc...
  9. Federated access for the Managed Defense Portal

    The Portal can be integrated with other identity providers for authentication. There are two main types of federation: identity provider (IdP) initiated and service provider (SP) initiated. The Portal supports IdP initiated sign in. An in...
  10.  Managing Notifications

    A Notification Profile is how you link Monitors or Monitor Groups to a specific Notification Format and how you define the notification interval. A Notification Profile is also required to receive automatic notifications if a Job for a Monitor err...