Summary findings of the assessment may include, but are not limited to, the following:
- End-of-life operating system reporting
- Remote access software and related tool reporting
- File transfer software and related tool reporting
- Egress network traffic reporting
- Relevant endpoint software CVE reporting
- Active directory account reporting
We leverage our forensic and incident response expertise in responding to 3,000+ engagements every year to assist in addressing current threats and advising on further incident response actions and any other additional investigative steps required.
What If Activity Is Detected During a Compromise Assessment?
A cybersecurity compromise assessment can uncover both past and current activity on a network. If this type of activity is actively identified during the course of the compromise assessment, Kroll can immediately pivot, leveraging the same tooling and endpoint coverage, into incident response and undertake forensic analysis on affected hosts. This involves:
- Containment and threat actor ejection
- Remotely collecting relevant forensic artifacts
- Determining the time frame and scope of potential sensitive data exposure, data exfiltration or compromised accounts
- Providing recommendations for containment and remediation to ensure your organization is more secure going forward