Mandiant for Intelligent Response is an appliance-based solution that scales your experienced incident responders and forensics specialists to investigate thousands of endpoints and scope the impact of an incident. Are you compromised? How did the attacker get in? What systems are involved? Mandiant for Intelligent Response lets you answer these questions so you can respond appropriately to keep advanced attackers from achieving their objective in your systems. Perform fast, precisely targeted investigations to quickly understand the scope of an attack and stop it before critical loss occurs.
Highlights
- Mandiant Threat Intel - Apply Mandiant’s proprietary intel on advanced attackers
- Find More Than Malware - Identify behavior that reveals attackers’ objectives
- Memory Forensics - Analyze live memory without downloading memory images
- Speed & Scale - Rapidly sweep thousands of endpoints at a time
Capabilities
- Sweep Endpoints for Evidence of Compromise - Sweeps all of your endpoints for evidence ofcompromise including malware, general malware behaviors and non-malware attacker tactics
- Remotely Investigate Any Endpoint, Anywhere - Retrieve data required for investigation securely over any network, using Agent Anywhere™ technology, without having to wait for access to be granted or exposing administrative credentials to an attacker in control of a system. Collect images and full live response or ask for only the exact data you need
- Access Mandiant’s Intel & Create Your Own - Utilizes Mandiant’s latest Indicators of Compromise (IOC) library based on our experience on the front lines or create your own IOCs as well
- Triage Alerts With Automated Host Interrogation Automatically collect info and analyze suspicious systems based on alerts generated by your SIEM, ticketing system or other applications
- Memory Forensics - Analyze live memory without downloading memory images to uncover malware that hides from normal tools
- Open IOC Support - Supports the XML-based OpenIOC standard so you can create, edit and share your own Indicators of Compromise and access custom indicators shared by others using the OpenIOC standard
- Collect Targeted Forensic Data at Scale - Intelligent filtering capabilities Mandiant’s lightweight, non-intrusive agent return only the data you need so you can find answers to forensic questions on thousands of hosts at a time






