Englishالعربية Soon
Under attack?
Compromise assessment · Threat detection

A vulnerability assessment asks where you are exposed. This one asks whether they are already in.

A compromise assessment hunts for evidence of intrusion across your endpoints, network and identity systems, establishes whether an attacker is present or has been, and tells you how they got in.

Intrusions are quiet

Attackers do not announce themselves. They wait.

Access is often established long before it is used, and dwell time is measured in months. An assessment looks for the traces that persistence, credential theft and staging leave behind, rather than waiting for an alert.

A finding you can act on

If we find something, containment starts the same day.

You get a clear answer, the evidence behind it, the root cause, and a prioritised remediation plan. If the assessment turns into an incident, our response team is already on the engagement.

What we look for

The traces an intrusion leaves

Absence of alerts is not evidence of absence. These are the artefacts that are hard for an attacker to clean.

Persistence mechanisms

Scheduled tasks, services, startup entries and account changes that keep access alive across reboots.

Credential theft artefacts

Evidence of memory access, hash extraction and ticket abuse against your authentication systems.

Command and control traffic

Outbound connections to attacker infrastructure, including traffic tunnelled inside permitted protocols.

Lateral movement

Remote execution, administrative share access and authentication patterns that do not match how your staff work.

Staged data

Archives assembled in unusual locations, which is what exfiltration looks like just before it happens.

Suspicious accounts and privilege

Accounts created or elevated outside your change process, including ones that look plausible at a glance.

Tampered logging

Cleared, disabled or gapped audit trails, which are themselves a finding.

Known indicators

Current threat intelligence indicators checked against your environment and its retained history.

Anomalous behaviour

Access and process behaviour that deviates from the established baseline for that host or account.

How the hunt runs

Five phases, and a containment path if we find something

The engagement is designed to answer one question. If the answer is yes, it becomes an incident response engagement immediately.

EndpointsServersDomain controllersNetwork trafficCloud and identityEmailRemote access
01
Scope
Systems, data sources, retention and access agreed, along with who to call if we find something at 2am.
02
Collect
Endpoint, network, identity and log data gathered, with forensic integrity preserved.
03
Hunt
Indicators, behavioural analytics and hypothesis driven hunting applied across the collected data.
04
Investigate
Anything suspicious traced to establish what happened, when, how far it went and what it touched.
05
Report
A clear answer, the evidence, the root cause and a prioritised plan, with containment support if needed.
If an active intrusion is confirmed, containment begins under the incident response process rather than waiting for the report.
Delivery model

Scheduled assessment

A defined engagement across an agreed scope, typically run annually or before a major event such as an acquisition or an audit.

Learn more →

Delivery model

Suspicion driven assessment

Fast mobilisation when something feels wrong but nothing is confirmed, with a direct path into full incident response.

Learn more →

Related

Controls that work alongside it

Incident response

Where the engagement goes if the answer is yes.

SIEM

The telemetry that makes the next hunt faster and the next intrusion louder.

NDR

Retained traffic that turns a suspicion into a timeline.

Get a straight answer.

A scoped assessment across your critical systems tells you whether an intruder is present, and if so, how they got in.