Incident Response & Ransomware Recovery
Compromise Assessment
Dwell time for an undetected intrusion is routinely measured in months. A compromise assessment is the deliberate search for one that is already underway — not a vulnerability assessment, which finds what could be exploited, but a hunt for evidence that something already was. Most organisations have never had one, and the assessment is frequently commissioned because of a suspicion nobody can confirm or dismiss.
Methodology
- 01
Scoping and hypothesis development
The estate, what would be worth stealing, and which threat actors would plausibly target it. Hypotheses are written before hunting begins, so the assessment is directed rather than a fishing expedition.
- 02
Telemetry assessment
What data exists, how far back it goes, and where the blind spots are. A hunt is bounded by available telemetry, and the gaps are themselves a finding.
- 03
Estate-wide artefact collection
Triage artefacts collected from every reachable host — persistence, execution evidence, network configuration and account artefacts — rather than from a sample.
- 04
Indicator-based hunting
Known indicators from threat intelligence relevant to the client's sector, matched against collected artefacts and historical logs.
- 05
Behavioural hunting
Hypothesis-driven searches for technique patterns rather than known indicators, which is what finds an actor whose infrastructure is not yet published.
- 06
Anomaly analysis
Authentication patterns, privileged account usage, scheduled tasks, service accounts and outbound connections analysed against a baseline.
- 07
Triage and validation
Every candidate finding investigated to conclusion. A compromise assessment that hands over a list of unresolved anomalies has produced anxiety rather than an answer.
- 08
Reporting
A clear statement of what was found, what was searched for and not found, and where the telemetry gaps leave questions open.
Approach to testing
- The assessment is bounded by telemetry, and the report says so. Concluding 'no compromise found' across an estate with 30 days of logs and no EDR on a third of hosts is a much weaker statement than the same words elsewhere, and the report distinguishes them.
- Hypotheses are written before hunting. Undirected hunting finds unexplained anomalies rather than intrusions, and every estate has thousands of those.
- Every candidate is resolved. Leaving unexplained findings with the client transfers the problem rather than solving it.
- Collection is estate-wide rather than sampled, because an intrusion is not distributed evenly and the compromised host is rarely in the sample.
- If compromise is found, the engagement converts to incident response immediately, under a pre-agreed escalation clause, so no time is lost to a commercial conversation.
Types of assessment
Full estate assessment (default)
Collection and hunting across every reachable host and cloud tenant. The complete answer, bounded by telemetry.
Targeted assessment
Focused on a specific suspicion, system or period. Faster and cheaper, and answers a narrower question.
Pre-transaction assessment
Run during due diligence, establishing whether an acquisition target is compromised before its network is connected.
Periodic hunt programme
Recurring assessments on a quarterly or biannual cycle, with hypotheses updated from current threat intelligence.
Frameworks and standards
- MITRE ATT&CK
- Technique catalogue driving behavioural hunting hypotheses and coverage reporting.
- SANS threat hunting methodology
- Hypothesis-driven hunt structure.
- NIST SP 800-61
- Incident handling lifecycle, entered immediately if compromise is confirmed.
- Pyramid of Pain
- Framing which indicator types are worth hunting on, since hashes and addresses are trivially changed and behaviours are not.
- Sector threat intelligence
- Actor profiles relevant to the client's industry and geography, so hunting is targeted.
Tools used
Tooling is where testing starts, not where it ends. Every automated result is reproduced by hand before it reaches a report.
Velociraptor
Estate-wide artefact collection and live hunting at scale, which is the backbone of the engagement.
YARA / Sigma
Indicator and behavioural rule matching across collected artefacts and logs.
Client EDR and SIEM
Historical telemetry, which usually reaches further back than anything CSS can collect fresh.
Plaso / Timesketch
Timeline construction where a candidate finding needs investigation.
Threat intelligence feeds
Current indicators relevant to the client's sector and geography.
Custom baseline analysis
Identifying what is normal for this estate, since anomaly detection requires a baseline that is rarely documented.
Checklist approach
The checklist is the floor, not the ceiling. It guarantees coverage so nothing standard is missed; the findings that matter usually come from what a tester does after it is complete.
Persistence
- Scheduled tasks and cron entries across every host
- Services and drivers, particularly recently created ones
- Registry run keys, WMI subscriptions and startup items
- Web shells on internet-facing servers
- Modified system binaries and DLL search order abuse
- Cloud persistence: OAuth grants, app registrations, mailbox rules
Credential access and identity
- Anomalous authentication patterns and impossible travel
- Privileged account usage outside normal hours or hosts
- New or modified service accounts
- Kerberos anomalies including golden and silver ticket indicators
- Directory permission changes and DCSync rights
- Dormant accounts that have become active
Lateral movement
- Remote execution artefacts: WMI, WinRM, PsExec, scheduled tasks on remote hosts
- Administrative share access patterns
- RDP session history and source hosts
- Pass-the-hash and pass-the-ticket indicators
Command and control
- Beaconing patterns in network telemetry
- DNS anomalies including tunnelling and high-entropy queries
- Connections to newly registered or low-reputation domains
- Unusual outbound protocols and ports
- Cloud storage and paste site access from servers
Collection and exfiltration
- Archive creation on file servers and endpoints
- Large data transfers outside normal patterns
- Cloud storage uploads from servers
- Database export activity
- Email forwarding and auto-export rules
Telemetry coverage
- Hosts with no EDR or an unresponsive agent
- Log retention per source and whether it covers the hunt period
- Cloud audit logging enabled and retained
- Network telemetry coverage and blind spots
- Gaps documented as limits on the assessment's conclusion
How findings are scored
Every finding is scored on CVSS 3.1 and placed in one of five levels. The executive summary adds a sixth band — Compliant — so components that passed appear on the same chart as those that did not.
- Critical
- Immediate measures must be taken. These vulnerabilities can allow an attacker to take complete control of the application or server — stealing user data, tricking users into supplying sensitive information, or defacing the site.
- High
- Maximum risk associated with a specific vulnerability instance. May enable an attacker to compromise the application and its data, partially or completely, or to modify application behaviour beyond its intended purpose. To be handled with utmost priority.
- Medium
- Considerable risk. May enable an attacker to exploit the application to a particular level, gaining low-level information that can be used to craft more specific attacks.
- Low
- Lowest risk. May allow an attacker to gain some information about the application that was not intended to be known, without an exploitation technique currently available at that instance.
- Informational
- A functionality or component is missing best-practice implementation. Not a risk today, but may become one as the application changes or as exploitation techniques, policy or legal requirements evolve.
Scan types selected
- Safe Checks
- Standard / OWASP Top 10
- Destructive
- SANS Top 25
- Business Logic Vulnerability Testing
Standard toolset by stage
- OSINT
- Datasploit, Google Dorks, Shodan
- Enumeration & Scanning
- Nmap, Wfuzz, Unicornscan
- Domain Enumeration
- Nikto, DnsRecon, Knock
- Crawling & Fuzzing
- Burp Suite, Acunetix, Netsparker
- Vulnerability Analysis
- OpenSSL, sqlmap, CVE-Details
- Exploitation
- Metasploit, Netcat, Exploit-DB
How CSS tests
A unified swarm of agents, for blind spot detection
AI agents drive several testing tracks against the same target at once, then cross-check each other. A single tester works one hypothesis at a time; parallel agents cover the space a sequential pass leaves behind.
Estate-wide artefact collection produces millions of records. Surfacing the anomalous handful is exactly the problem parallel analysis exists for, and sampling defeats the purpose of the engagement.
Baselining what is normal across thousands of hosts is statistical work; without it, anomaly detection returns noise.
Beaconing detection requires timing analysis across every outbound connection over weeks, which is signal processing rather than inspection.
Behavioural hunting across the ATT&CK matrix means running hundreds of hypotheses against the collected set — breadth that a human hunter would have to prioritise away.
Every candidate finding is investigated to conclusion by a human analyst. Agents surface candidates; analysts determine whether something is an intrusion, a misconfiguration or normal-but-unusual. An automated 'possible compromise' handed to a client unresolved is worse than no assessment at all.
Why this differs
What CSS does that most vendors do not
Every one of these is checkable. Ask any vendor for the same and compare the answers.
The conclusion is bounded honestly
'No compromise found' means very different things across estates with different telemetry. CSS states what was searched, how far back, and where the blind spots are — so the client knows the strength of the answer they are buying.
Every candidate resolved
The report contains no unexplained anomalies. Handing a client a list of things nobody investigated transfers the problem and creates anxiety without reducing risk.
Estate-wide, not sampled
Intrusions are not evenly distributed. A sampled assessment answers a question about the sample.
Converts to response immediately
If compromise is confirmed, the engagement moves to incident response under a pre-agreed clause. No time is lost to a new commercial conversation while an actor is active.
Reporting
Two documents, two audiences
Both are produced for every engagement. They are not the same document at two lengths — they answer different questions and are written separately. The structure below is the one CSS actually issues.
Technical assessment report
For the engineers who will fix it
- Disclaimer, and Limitations on Disclosure and Use
- Risk Level & Description — the five levels above, scored on CVSS 3.1
- Scan Type — which of the five assessment types were selected
- Assessment Scope — the control areas covered
- Assessment Date — the exact testing window
- Objective of the Assessment — objectives listed against completion status
- Tools Utilization — manual and automated tooling by stage
- Summary of the Assessment
- Overall Recommendations, split into Must Have and Should Have
- Vulnerability Overall Classifications as per Organization
- Security Issues Highlighted
- The Key Findings — each with evidence and detailed recommendation
- Summary of Findings & Conclusion
For this assessment specifically
- Scope: hosts, cloud tenants, telemetry sources and the period covered
- Hypotheses tested, with the outcome of each
- Findings, if any, with full supporting evidence
- Every candidate investigated and its resolution, including benign explanations
- Telemetry coverage assessment and the blind spots that bound the conclusion
- MITRE ATT&CK coverage: which techniques could and could not be hunted for
- Detection and logging recommendations to make the next assessment stronger
Executive summary
For the people who will fund the fix
- Objectives, each against a completion status
- Overall Finding of the Assessment — total threats identified, broken down by component and severity
- Summary of the Assessment
- Artefacts of the Assessment — the key findings as a numbered register with severity
- Observation of the Assessment — the major attacks the organisation should be prepared for, given what was found
- Overall Recommendation, including a Business Enabling Recommendation sequence
- Must Have and Should Have actions
For this assessment specifically
- Whether evidence of compromise was found, stated plainly
- How strong that conclusion is, given the telemetry available
- What could not be assessed, and why
- The three changes that would most improve the organisation's ability to answer this question itself
- Recommended cadence
- One page
Case studies
What this finds in practice
Representative engagement patterns. Sector and scale only — no client is named, and no detail is included that could identify one.
A financial services firm commissioning an assessment after a sector-wide advisory.
- Finding
- No active intrusion was found. Hunting did surface a web shell on a decommissioned but still-running internet-facing server, dormant for fourteen months with no evidence of use since. The server was absent from the asset register and from all monitoring.
- Recommendation
- Remove the server, reconcile the asset register against what is actually reachable from the internet, and extend monitoring to cover anything discovered by that reconciliation.
- Outcome
- Server removed. The reconciliation found six further unmanaged internet-facing hosts, which the client considered the more significant outcome.
A manufacturer conducting due diligence on an acquisition before network integration.
- Finding
- The target was actively compromised. An actor had been present for approximately four months with domain administrator access, and beaconing to command and control was ongoing at the time of assessment.
- Recommendation
- Halt integration, convert immediately to incident response, and renegotiate on the basis of the finding.
- Outcome
- Integration was stopped before the networks were connected. Incident response ran for six weeks. The acquiring organisation's view was that the assessment had prevented an intrusion inheriting its entire estate.
A hospital group with a suspicion arising from unexplained account lockouts.
- Finding
- No compromise. The lockouts traced to a service account with a stale credential in a scheduled task on three hosts. More significantly, the assessment found that 40% of endpoints had no working EDR agent and log retention was 14 days, meaning a real intrusion could not have been detected or reconstructed.
- Recommendation
- Fix the agent coverage and extend retention to 12 months before commissioning another assessment, because the current telemetry cannot support a meaningful conclusion.
- Outcome
- Agent coverage reached 97% within a quarter and retention was extended. The honest statement that the original conclusion was weak was, per the client, what unlocked the budget.
Next
Scope this assessment
Most scopes are settled in one call. Tell us what the application does and who uses it, and we will tell you what testing it properly involves.