Today's cyber threat landscape is rapidly evolving. Nation-state threat actors, well-funded attack campaigns, highly motivated adversaries, and extremely sophisticated attacks have become daily headlines. This new generation of threat actors and advanced attackers are highly targeted and focused on acquiring something valuable and vital to your organization, such as sensitive personal information, intellectual property, or insider information. These targeted attacks occur across all industries, and are stealthy and persistent enough to go undetected by traditional security technologies, such as next-generation firewalls, traditional IPS, anti-virus, and secure email or Web gateways.
In order to combat these advanced attacks and persistent adversaries organizations need to reimagine security and adopt a Continuous Threat Protection model. This means having the ability to detect threats in real time as well as reduce the time to contain and resolve the threat, thereby preventing or minimizing the business impact of these threats. The FireEye Platform does this with a multi-faceted approach to security – Prevent, Detect, Contain, Resolve.
- Prevent - Prevention must enable real-time, proactive blocking and provide rich and actionable intelligence to better understand the nature of attacks for continuous improvement of the security posture.
- Detect - Today’s advanced threats require an architecture that is aware of the multi-stage and multi-vector nature of attacks. The security solution should be able to detect known and unknown threats in real time and be able to scale with the demands of the network.
- Contain - Effective containment demands real-time validation of threats coupled with the ability to rapidly stop the impact of an attack on compromised systems.
- Resolve - To limit exfiltration and serious business impact, security incidents must be investigated, scoped, and resolved in a timely and cost effective way.
The FireEye Platform provides products, people, and intelligence to deliver the industry’s first continuous threat protection model. The global, real-time platform prevents, detects, contains, and resolves advanced threats to help secure brands, intellectual property, and data.
The key elements of the FireEye Platform include:
Threat Prevention Platforms
The FireEye Threat Prevention Platforms include all the FireEye appliance- and cloud-based products including network, email, content, mobile, forensics, and endpoint solutions to address today’s advanced cyber threats. The FireEye Threat Prevention Platforms use the patented and proven Multi-Vector Virtual Execution (MVX) technology to enable real-time detection and prevention of advanced threats.
The MVX engine captures and confirms zero-day and targeted advanced persistent threat (APT) attacks by detonating suspicious Web objects, email attachments, content files, and mobile apps within instrumented virtual machine environments. The MVX engine is designed to provide scalable, accurate, and timely protection across the primary threat vectors—Web, email, file, and mobile – and also provides actionable threat intelligence to enable rapid event prioritization and incident response.
Leveraging alerts from the FireEye Threat Prevention Platforms, the Endpoint Threat Prevention Platform, or HX series, enables security teams to confidently detect, contain, and resolve incidents in a fraction of the time it takes using conventional approaches. Using auto-generated Indicators of Compromise (IOCs) from the alerts provided by the FireEye Threat Prevention Platforms, the endpoint agents accelerate triage of suspected incidents and drive rapid containment of the compromised host devices.
The innovative FireEye Threat Prevention Platforms:
- Enrich the threat detection efficacy at a network and host level
- Scale performance and throughput to successfully counter the advanced cyber attacks across diverse types of networks (enterprise, government, small and midsize businesses, branch offices) and deployment scenarios (on-premise, cloud, endpoint, mobile)
- Detect today’s advanced threats and prevent future attacks
FireEye Subscription Services
Today’s global attacks required worldwide 24x7x365 support. Organizations are challenged to defend against the growing and ever-evolving cyber threat landscape with limited access to security experts.
The FireEye Managed Defense portfolio provides organizations the combination of products, people, and intelligence to help detect and respond to a threat before the attackers can complete their mission. It allows organizations that do not have resources, or ones that would rather focus on their core business, to leverage the FireEye expertise in addressing advanced threats.
With FireEye Managed Defense organizations can:
- Gain insight into their security posture relative to their industry vertical by leveraging dynamic threat intelligence generated from FireEye Threat Prevention Platforms
- Receive guidance and remediation support on attacks
- Conduct lean-forward defenses using technology and services to protect against aggressive attackers
- Help contain and resolve the initial alert without having to make large investments in incident response or advanced security analysis capabilities
Mandiant Security Consulting Services
Mandiant Security Consulting Services enable organizations to leverage our expertise while managing advanced threats and incidents, ultimately improving their security posture. We help customers secure their networks against threats and resolve computer security incidents of all kinds. Mandiant Security Consulting Services offers a full range of security services designed to help organizations prepare for and respond to security incidents:
- Incident Response: This service focuses on helping customers recover from security incidents while minimizing the impact of the event on the organization. Learn more.
- Security Assessments: Our consultants review organizations' computer systems, applications, and networks for security vulnerabilities that are most likely to be leveraged by attack groups to compromise their environment. Learn more.
- Incident Response Program Development: Our incident response program development services draw on our expertise in incident response to compare an organization’s incident response team against leading practices and help determine where their program needs to go and how to get there. Learn more.
Dynamic Threat Intelligence
The FireEye Dynamic Threat Intelligence is a robust repository of threat intelligence obtained through years of consulting and millions of VMs deployed worldwide. Having access to rich, actionable threat intelligence and expert research and forensics teams enables FireEye to augment its products and services to provide organizations the most comprehensive protection against today’s advanced cyber attacks.
In addition:
- The Dynamic Threat Intelligence (DTI) cloud enables real-time sharing of auto-generated threat intelligence from global deployments of FireEye Threat Prevention Platforms
- The APT Discovery Center catalogs and analyzes hundreds of current and past APT campaigns and characterizes APT attacks by technical footprint, geography, and target customer or industry
- The combination of the DTI cloud and APT Discovery Center help security teams, law enforcement, and governments understand the trends and drivers behind various threats to continuously improve defenses





