
Active Directory Security Assessment
Mitigate the risk of Active Directory misconfigurations, process weaknesses and exploitation methods
The Active Directory Security Assessment (ADSA) is based on our extensive incident response experience, global containment and remediation services, and emerging threat intelligence. Mandiant uses this expertise to help your organization improve the key processes, configuration standards, security, and monitoring controls required to effectively secure an Active Directory environment and its supporting infrastructure.
Overview
Organizations often struggle to properly maintain configurations and keep current with the latest security enhancements of Active Directory.
The practical guidance and recommendations derived from this assessment reflect tested and vetted techniques that have successfully eradicated attackers from client environments and helped remediate threats.
By using this proactive methodology, organizations can enhance their Active Directory security posture and protect against incidents that exploit common weaknesses in an Active Directory environment.
Datasheet
Active Directory Security Assessment
Active Directory Security Assessment benefits
Realize current state
Gain visibility into the current state of an organization’s Active Directory environment.
Get ahead of risk
Proactively mitigate commonly exploited Active Directory misconfigurations and settings.
Lessen harmful impact
Reduce the risk and impact of a security incident by hardening a common attack surface.
Enforce better detection
Increase visibility and detection within an Active Directory environment.
Improve the big picture
Strategically improve the overall security posture of the Active Directory infrastructure.
Take back control
Implement stricter policies to minimize privileged access.
Our approach
Mandiant experts conduct a series of onsite workshops in collaboration with key stakeholders from the client organization to:
- Perform data collection
- Analyze script output
- Evaluate the architecture (on-premise and cloud environments)
- Identify possible attack paths within the Active Directory infrastructure
Mandiant consultants then make recommendations to:
- Harden privileged user access and privileged access management
- Enhance visibility and detection of malicious events within Active Directory
- Provide a strategic roadmap to improve the overall Active Directory infrastructure
What you get
- Practical Active Directory hardening guidance and mitigations
- Prioritized approach to further leverage existing technologies and investments
- Detailed report that includes:
- A snapshot of the existing Active Directory security configuration for the environment
- Specific Active Directory security best practices to align with current technologies and operational processes
- Practical recommendations for restricting, managing, and monitoring privileged user access and accounts within the environment
- Detailed recommendations for further hardening the security posture of the Active Directory infrastructure
Related resources
Report
M-Trends 2019
Datasheet
Incident Response Retainer
Reasons
7 Reasons to have FireEye Mandiant on speed dial
Ready to get started?
Our security experts are
standing by to help you with an incident or
answer questions
about our consulting and managed detection and response services.
