Skip to content
CyberSmithSECURE
Under Attack

Incident Response & Ransomware Recovery

Compromise Assessment

Dwell time for an undetected intrusion is routinely measured in months. A compromise assessment is the deliberate search for one that is already underway — not a vulnerability assessment, which finds what could be exploited, but a hunt for evidence that something already was. Most organisations have never had one, and the assessment is frequently commissioned because of a suspicion nobody can confirm or dismiss.

Methodology

  1. 01

    Scoping and hypothesis development

    The estate, what would be worth stealing, and which threat actors would plausibly target it. Hypotheses are written before hunting begins, so the assessment is directed rather than a fishing expedition.

  2. 02

    Telemetry assessment

    What data exists, how far back it goes, and where the blind spots are. A hunt is bounded by available telemetry, and the gaps are themselves a finding.

  3. 03

    Estate-wide artefact collection

    Triage artefacts collected from every reachable host — persistence, execution evidence, network configuration and account artefacts — rather than from a sample.

  4. 04

    Indicator-based hunting

    Known indicators from threat intelligence relevant to the client's sector, matched against collected artefacts and historical logs.

  5. 05

    Behavioural hunting

    Hypothesis-driven searches for technique patterns rather than known indicators, which is what finds an actor whose infrastructure is not yet published.

  6. 06

    Anomaly analysis

    Authentication patterns, privileged account usage, scheduled tasks, service accounts and outbound connections analysed against a baseline.

  7. 07

    Triage and validation

    Every candidate finding investigated to conclusion. A compromise assessment that hands over a list of unresolved anomalies has produced anxiety rather than an answer.

  8. 08

    Reporting

    A clear statement of what was found, what was searched for and not found, and where the telemetry gaps leave questions open.

Approach to testing

  • The assessment is bounded by telemetry, and the report says so. Concluding 'no compromise found' across an estate with 30 days of logs and no EDR on a third of hosts is a much weaker statement than the same words elsewhere, and the report distinguishes them.
  • Hypotheses are written before hunting. Undirected hunting finds unexplained anomalies rather than intrusions, and every estate has thousands of those.
  • Every candidate is resolved. Leaving unexplained findings with the client transfers the problem rather than solving it.
  • Collection is estate-wide rather than sampled, because an intrusion is not distributed evenly and the compromised host is rarely in the sample.
  • If compromise is found, the engagement converts to incident response immediately, under a pre-agreed escalation clause, so no time is lost to a commercial conversation.

Types of assessment

Full estate assessment (default)

Collection and hunting across every reachable host and cloud tenant. The complete answer, bounded by telemetry.

Targeted assessment

Focused on a specific suspicion, system or period. Faster and cheaper, and answers a narrower question.

Pre-transaction assessment

Run during due diligence, establishing whether an acquisition target is compromised before its network is connected.

Periodic hunt programme

Recurring assessments on a quarterly or biannual cycle, with hypotheses updated from current threat intelligence.

Frameworks and standards

MITRE ATT&CK
Technique catalogue driving behavioural hunting hypotheses and coverage reporting.
SANS threat hunting methodology
Hypothesis-driven hunt structure.
NIST SP 800-61
Incident handling lifecycle, entered immediately if compromise is confirmed.
Pyramid of Pain
Framing which indicator types are worth hunting on, since hashes and addresses are trivially changed and behaviours are not.
Sector threat intelligence
Actor profiles relevant to the client's industry and geography, so hunting is targeted.

Tools used

Tooling is where testing starts, not where it ends. Every automated result is reproduced by hand before it reaches a report.

Velociraptor

Estate-wide artefact collection and live hunting at scale, which is the backbone of the engagement.

YARA / Sigma

Indicator and behavioural rule matching across collected artefacts and logs.

Client EDR and SIEM

Historical telemetry, which usually reaches further back than anything CSS can collect fresh.

Plaso / Timesketch

Timeline construction where a candidate finding needs investigation.

Threat intelligence feeds

Current indicators relevant to the client's sector and geography.

Custom baseline analysis

Identifying what is normal for this estate, since anomaly detection requires a baseline that is rarely documented.

Checklist approach

The checklist is the floor, not the ceiling. It guarantees coverage so nothing standard is missed; the findings that matter usually come from what a tester does after it is complete.

Persistence

  • Scheduled tasks and cron entries across every host
  • Services and drivers, particularly recently created ones
  • Registry run keys, WMI subscriptions and startup items
  • Web shells on internet-facing servers
  • Modified system binaries and DLL search order abuse
  • Cloud persistence: OAuth grants, app registrations, mailbox rules

Credential access and identity

  • Anomalous authentication patterns and impossible travel
  • Privileged account usage outside normal hours or hosts
  • New or modified service accounts
  • Kerberos anomalies including golden and silver ticket indicators
  • Directory permission changes and DCSync rights
  • Dormant accounts that have become active

Lateral movement

  • Remote execution artefacts: WMI, WinRM, PsExec, scheduled tasks on remote hosts
  • Administrative share access patterns
  • RDP session history and source hosts
  • Pass-the-hash and pass-the-ticket indicators

Command and control

  • Beaconing patterns in network telemetry
  • DNS anomalies including tunnelling and high-entropy queries
  • Connections to newly registered or low-reputation domains
  • Unusual outbound protocols and ports
  • Cloud storage and paste site access from servers

Collection and exfiltration

  • Archive creation on file servers and endpoints
  • Large data transfers outside normal patterns
  • Cloud storage uploads from servers
  • Database export activity
  • Email forwarding and auto-export rules

Telemetry coverage

  • Hosts with no EDR or an unresponsive agent
  • Log retention per source and whether it covers the hunt period
  • Cloud audit logging enabled and retained
  • Network telemetry coverage and blind spots
  • Gaps documented as limits on the assessment's conclusion

How findings are scored

Every finding is scored on CVSS 3.1 and placed in one of five levels. The executive summary adds a sixth band — Compliant — so components that passed appear on the same chart as those that did not.

Critical
Immediate measures must be taken. These vulnerabilities can allow an attacker to take complete control of the application or server — stealing user data, tricking users into supplying sensitive information, or defacing the site.
High
Maximum risk associated with a specific vulnerability instance. May enable an attacker to compromise the application and its data, partially or completely, or to modify application behaviour beyond its intended purpose. To be handled with utmost priority.
Medium
Considerable risk. May enable an attacker to exploit the application to a particular level, gaining low-level information that can be used to craft more specific attacks.
Low
Lowest risk. May allow an attacker to gain some information about the application that was not intended to be known, without an exploitation technique currently available at that instance.
Informational
A functionality or component is missing best-practice implementation. Not a risk today, but may become one as the application changes or as exploitation techniques, policy or legal requirements evolve.

Scan types selected

  • Safe Checks
  • Standard / OWASP Top 10
  • Destructive
  • SANS Top 25
  • Business Logic Vulnerability Testing

Standard toolset by stage

OSINT
Datasploit, Google Dorks, Shodan
Enumeration & Scanning
Nmap, Wfuzz, Unicornscan
Domain Enumeration
Nikto, DnsRecon, Knock
Crawling & Fuzzing
Burp Suite, Acunetix, Netsparker
Vulnerability Analysis
OpenSSL, sqlmap, CVE-Details
Exploitation
Metasploit, Netcat, Exploit-DB

How CSS tests

A unified swarm of agents, for blind spot detection

AI agents drive several testing tracks against the same target at once, then cross-check each other. A single tester works one hypothesis at a time; parallel agents cover the space a sequential pass leaves behind.

  • Estate-wide artefact collection produces millions of records. Surfacing the anomalous handful is exactly the problem parallel analysis exists for, and sampling defeats the purpose of the engagement.

  • Baselining what is normal across thousands of hosts is statistical work; without it, anomaly detection returns noise.

  • Beaconing detection requires timing analysis across every outbound connection over weeks, which is signal processing rather than inspection.

  • Behavioural hunting across the ATT&CK matrix means running hundreds of hypotheses against the collected set — breadth that a human hunter would have to prioritise away.

Every candidate finding is investigated to conclusion by a human analyst. Agents surface candidates; analysts determine whether something is an intrusion, a misconfiguration or normal-but-unusual. An automated 'possible compromise' handed to a client unresolved is worse than no assessment at all.

Why this differs

What CSS does that most vendors do not

Every one of these is checkable. Ask any vendor for the same and compare the answers.

The conclusion is bounded honestly

'No compromise found' means very different things across estates with different telemetry. CSS states what was searched, how far back, and where the blind spots are — so the client knows the strength of the answer they are buying.

Every candidate resolved

The report contains no unexplained anomalies. Handing a client a list of things nobody investigated transfers the problem and creates anxiety without reducing risk.

Estate-wide, not sampled

Intrusions are not evenly distributed. A sampled assessment answers a question about the sample.

Converts to response immediately

If compromise is confirmed, the engagement moves to incident response under a pre-agreed clause. No time is lost to a new commercial conversation while an actor is active.

Reporting

Two documents, two audiences

Both are produced for every engagement. They are not the same document at two lengths — they answer different questions and are written separately. The structure below is the one CSS actually issues.

Technical assessment report

For the engineers who will fix it

  • Disclaimer, and Limitations on Disclosure and Use
  • Risk Level & Description — the five levels above, scored on CVSS 3.1
  • Scan Type — which of the five assessment types were selected
  • Assessment Scope — the control areas covered
  • Assessment Date — the exact testing window
  • Objective of the Assessment — objectives listed against completion status
  • Tools Utilization — manual and automated tooling by stage
  • Summary of the Assessment
  • Overall Recommendations, split into Must Have and Should Have
  • Vulnerability Overall Classifications as per Organization
  • Security Issues Highlighted
  • The Key Findings — each with evidence and detailed recommendation
  • Summary of Findings & Conclusion

For this assessment specifically

  • Scope: hosts, cloud tenants, telemetry sources and the period covered
  • Hypotheses tested, with the outcome of each
  • Findings, if any, with full supporting evidence
  • Every candidate investigated and its resolution, including benign explanations
  • Telemetry coverage assessment and the blind spots that bound the conclusion
  • MITRE ATT&CK coverage: which techniques could and could not be hunted for
  • Detection and logging recommendations to make the next assessment stronger

Executive summary

For the people who will fund the fix

  • Objectives, each against a completion status
  • Overall Finding of the Assessment — total threats identified, broken down by component and severity
  • Summary of the Assessment
  • Artefacts of the Assessment — the key findings as a numbered register with severity
  • Observation of the Assessment — the major attacks the organisation should be prepared for, given what was found
  • Overall Recommendation, including a Business Enabling Recommendation sequence
  • Must Have and Should Have actions

For this assessment specifically

  • Whether evidence of compromise was found, stated plainly
  • How strong that conclusion is, given the telemetry available
  • What could not be assessed, and why
  • The three changes that would most improve the organisation's ability to answer this question itself
  • Recommended cadence
  • One page

Case studies

What this finds in practice

Representative engagement patterns. Sector and scale only — no client is named, and no detail is included that could identify one.

A financial services firm commissioning an assessment after a sector-wide advisory.

Finding
No active intrusion was found. Hunting did surface a web shell on a decommissioned but still-running internet-facing server, dormant for fourteen months with no evidence of use since. The server was absent from the asset register and from all monitoring.
Recommendation
Remove the server, reconcile the asset register against what is actually reachable from the internet, and extend monitoring to cover anything discovered by that reconciliation.
Outcome
Server removed. The reconciliation found six further unmanaged internet-facing hosts, which the client considered the more significant outcome.

A manufacturer conducting due diligence on an acquisition before network integration.

Finding
The target was actively compromised. An actor had been present for approximately four months with domain administrator access, and beaconing to command and control was ongoing at the time of assessment.
Recommendation
Halt integration, convert immediately to incident response, and renegotiate on the basis of the finding.
Outcome
Integration was stopped before the networks were connected. Incident response ran for six weeks. The acquiring organisation's view was that the assessment had prevented an intrusion inheriting its entire estate.

A hospital group with a suspicion arising from unexplained account lockouts.

Finding
No compromise. The lockouts traced to a service account with a stale credential in a scheduled task on three hosts. More significantly, the assessment found that 40% of endpoints had no working EDR agent and log retention was 14 days, meaning a real intrusion could not have been detected or reconstructed.
Recommendation
Fix the agent coverage and extend retention to 12 months before commissioning another assessment, because the current telemetry cannot support a meaningful conclusion.
Outcome
Agent coverage reached 97% within a quarter and retention was extended. The honest statement that the original conclusion was weak was, per the client, what unlocked the budget.

Next

Scope this assessment

Most scopes are settled in one call. Tell us what the application does and who uses it, and we will tell you what testing it properly involves.