Mandiant: Support SOC teams in detecting attacks

Mandiant: Support SOC teams in detecting attacks

Share post

Mandiant expands its SaaS offering. The two new products Active Breach & Intel Monitoring and Ransomware Defense Validation complement the manufacturer-independent Extended Detection and Response (XDR) capabilities of the Mandiant Advantage platform.

They accelerate the operational use of the up-to-the-minute threat intelligence from Mandiant and check whether a company's security mechanisms can detect, contain and block common ransomware attacks. The offers for companies of all sizes improve the effectiveness of the security measures and the confidence in being able to ward off cyber attacks. The two new offers are expected to hit the market in January 2022.

Detect targeted attacks and security gaps

Hacker groups have become increasingly sophisticated, especially during the COVID-19 pandemic. They target companies of all sizes and industries. As companies invest in people and technology to stop these potential threats, they need solutions that can quickly identify targeted attacks and vulnerabilities based on up-to-date, relevant threat intelligence.

To meet the growing security needs of companies, Mandiant brings Active Breach & Intel Monitoring and Ransomware Defense Validation to the market. The SaaS-based solutions use the most accurate and relevant threat intelligence and enable companies to see whether there are active indicators of compromise (IOCs) in their IT environment. At the same time, they can check how well they are prepared to defend themselves against the latest ransomware attacks.

Active Breach & Intel Monitoring

Active Breach & Intel Monitoring is based on the findings from client's global incident response activities and extensive threat intelligence research. It is designed to identify relevant indicators of compromise (IOCs) in corporate IT environments. For this purpose, the latest information from real, worldwide investigations of security incidents is used. With this data, the Active Breach & Intel Monitoring module searches the customer's data for IOC matches for the last 30+ days.

As a SaaS-based solution, Mandiant Active Breach & Intel Monitoring is easy to implement and starts immediately identifying and prioritizing IOC matches. So that security teams and executives can focus on the highest priority alerts, the solution goes beyond simple reconciliation. It analyzes and evaluates the IOCs on the basis of a value based on data science and numerous context-related factors such as the direction of movement and the type of indicator. This enables security teams to respond to and respond to threat alerts more efficiently.

With Active Breach & Intel Monitoring, security teams of all sizes can quickly identify potential attacks that match IOCs of cyberattacks and reduce the length of time hacking groups spend. This can help reduce the effects of targeted attacks.

Ransomware Defense Validation

Active Breach & Intel Monitoring enable threat intelligence analysis and relieve SOC teams (Image: Mandiant).

The Ransomware Defense Validation tests the most important security mechanisms of companies against common ransomware and informs the security teams about functions that require immediate attention.

"With the rise in ransomware attacks, organizations of all sizes are grappling with fundamental questions and trying to figure out if they are prepared or if there is a vulnerability," said Chris Key, chief product officer at Mandiant. “With Ransomware Defense Validation, we offer a solution that equips companies with the tools and knowledge of Mandiant to test and improve their defense capabilities. Companies can use up-to-date and relevant threat intelligence to test their defenses against ransomware attacks within a few hours. "

Test of the security mechanisms of a company

On the basis of client threat intelligence on active ransomware attackers and their tactics, techniques and procedures (TTPs), Ransomware Defense Validation tests the relevant security mechanisms of a company. The solution determines which changes must be made to the defense in order to block or contain modern and widespread ransomware attacks. With Ransomware Defense Validation, security teams have XNUMX/XNUMX access to reports with quantitative data and information from Mandiant experts. This enables the most important stakeholders to be informed about the defenses against ransomware threats.

More at Mandiant.com

 


About Mandiant

Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident response. With decades of experience on the cyber frontline, Mandiant helps organizations confidently and proactively defend against cyber threats and respond to attacks. Mandiant is now part of Google Cloud.


 

Matching articles on the topic

Cybersecurity platform with protection for 5G environments

Cybersecurity specialist Trend Micro unveils its platform-based approach to protecting organizations' ever-expanding attack surface, including securing ➡ Read more

Data manipulation, the underestimated danger

Every year, World Backup Day on March 31st serves as a reminder of the importance of up-to-date and easily accessible backups ➡ Read more

Printers as a security risk

Corporate printer fleets are increasingly becoming a blind spot and pose enormous problems for their efficiency and security. ➡ Read more

IT security: Basis for LockBit 4.0 defused

Trend Micro, working with the UK's National Crime Agency (NCA), analyzed the unpublished version that was in development ➡ Read more

The AI ​​Act and its consequences for data protection

With the AI ​​Act, the first law for AI has been approved and gives manufacturers of AI applications between six months and ➡ Read more

MDR and XDR via Google Workspace

Whether in a cafe, airport terminal or home office – employees work in many places. However, this development also brings challenges ➡ Read more

Windows operating systems: Almost two million computers at risk

There are no longer any updates for the Windows 7 and 8 operating systems. This means open security gaps and therefore worthwhile and ➡ Read more

AI on Enterprise Storage fights ransomware in real time

NetApp is one of the first to integrate artificial intelligence (AI) and machine learning (ML) directly into primary storage to combat ransomware ➡ Read more