Home / Services / Compromise Assessment

Compromise Assessment

The average dwell time of an undetected breach is 204 days. Mjolnir's Compromise Assessment systematically sweeps your entire environment to detect active intrusions, dormant implants, and evidence of historical compromise that your existing security tools have missed.

MJOLNIR SECURITY · DFIR SERVICES

COMPROMISE
ASSESSMENT

Are you already breached and don't know it? We find out.

IOCs FOUND
DWELL DAYS
DATA SOURCES
8 ingested
LOOKBACK
90 days
COMPROMISE ASSESSMENT METHODOLOGY
📋
KICKOFF & SCOPE
📥
DATA INGESTION
📊
BASELINE ANALYSIS
🎯
THREAT HUNTING
🔬
FINDING VALIDATION
📑
EXECUTIVE REPORT
KICKOFF & SCOPE Define assessment scope, data sources, timeframe window, and crown jewel assets. Obtain read-only access credentials.
🪟 Windows Event Logs
4.2M events · 90d
🛡️ EDR Telemetry
18.7M events · 90d
📊 Sumo Logic SIEM
31.4M events · 90d
🏢 Active Directory Logs
890K events · 90d
📧 M365 Audit Logs
2.1M events · 90d
🔥 Firewall / NetFlow
62.3M events · 90d
☁️ Cloud Trail (Azure)
1.4M events · 90d
🔑 VPN Access Logs
210K events · 90d
Dormant implant beaconing on low-frequency schedule ○ PENDING
Kerberoastable SPN harvested months ago — cracked offline ○ PENDING
Local admin abuse for lateral movement across domain ○ PENDING
Scheduled task persistence surviving patch cycles ○ PENDING
Cloud storage used as dead-drop exfil channel ○ PENDING
#️⃣ Malicious Hashes
0
🌐 C2 Domains / IPs
0
👤 Suspicious Accounts
0
👻 Persistence Mechanisms
0
➡️ Lateral Movement
0
📦 Data Staging Events
0
Initial Access Spear phish → credential harvest
Persistence Scheduled task · Registry run key
Lateral Movement Pass-the-Hash · WMI exec
C2 Channel HTTPS · 6h jitter · JA3 evasion
Objective Data staging · exfil via cloud
Dwell Time Not yet determined
Awaiting assessment kickoff…
Compromise Finding Brief
BLUF-format: compromised / not compromised
IOC Package
All discovered indicators for blocking/hunting
Attacker Timeline
Reconstructed intrusion chronology
MITRE ATT&CK Overlay
Visual TTP mapping of observed techniques
Remediation Roadmap
Eradication steps · hardening priorities
Post-Breach Validation
Confirm attacker has been fully evicted
M&A Due Diligence
Assess target org before acquisition closes
Compliance Attestation
Evidence of clean state for auditors / insurers
Proactive Assurance
Annual check even without a known incident

Most organizations operate under the assumption that their security tools would alert them if they were compromised. The reality is that sophisticated adversaries -- nation-states, advanced ransomware operators, and well-resourced criminal groups -- routinely bypass endpoint detection, evade SIEM correlation rules, and maintain persistent access to networks for months or years without triggering a single alert. A Compromise Assessment is the proactive answer to the question every CISO should be asking: Are we already breached?

Mjolnir Security's Compromise Assessment is not a vulnerability scan or a penetration test. It is a forensic-grade examination of your live environment designed to detect the indicators of compromise that active monitoring may have missed. We deploy lightweight collection agents across your endpoint estate, ingest network telemetry from strategic chokepoints, analyze authentication logs from your identity infrastructure, and examine cloud audit trails -- all without disrupting your operations or tipping off a potential adversary.

Our assessment methodology is informed by hundreds of real-world incident response engagements. We know what adversary persistence looks like in practice -- the registry run keys, scheduled tasks, WMI event subscriptions, and legitimate tool abuse patterns that attackers use to maintain access. We scan for tens of thousands of known IOCs while simultaneously hunting for behavioral anomalies that no IOC feed would capture: unusual service account activity, anomalous DNS resolution patterns, suspicious parent-child process relationships, and lateral movement artifacts in authentication logs.

At the conclusion of the assessment, you receive a comprehensive report detailing any evidence of compromise discovered, the assessed severity and scope of each finding, the likely attack timeline, and prioritized remediation recommendations. If we discover an active intrusion, our incident response team is prepared to transition immediately from assessment to containment and eradication -- ensuring zero gap between detection and response.

Proactive Breach Detection

Our approach assumes compromise and works backward to either confirm or rule it out. We examine your environment through the lens of an adversary who has already achieved initial access and is working to expand their foothold. This offensive mindset, applied to defensive analysis, uncovers threats that traditional defensive tooling is not designed to detect.

IOC Scanning & Behavioral Analysis

We combine signature-based IOC scanning against our proprietary threat intelligence databases with behavioral analytics that detect anomalies without relying on known signatures. This dual approach catches both commodity malware that matches known indicators and bespoke adversary tooling that has never been seen before. Our IOC database is continuously enriched by our Skuggaheimar dark web intelligence unit and our active IR caseload.

Network Traffic Analysis

Strategic deployment of network sensors at egress points, inter-VLAN boundaries, and cloud gateways captures the traffic patterns that reveal adversary communications. We detect command-and-control beaconing, DNS tunneling, data exfiltration over encrypted channels, and lateral movement protocols that indicate an adversary is actively operating inside your network.

Dormant Threat Identification

Some of the most dangerous compromises are the ones that are not currently active. Adversaries plant backdoors, web shells, and dormant implants designed to be activated at a later date -- often after selling access to another group. Our assessment identifies these sleeping threats by examining persistence mechanisms, scheduled task configurations, and comparing baseline system states against known-good configurations.

Core Assessment Capabilities

🔎

Assume Breach Methodology

We start from the assumption that your environment is compromised and work methodically to confirm or disprove it. This offensive mindset applied to defensive analysis uncovers threats that conventional monitoring misses entirely.

🧬

500K+ IOC Database

Our proprietary IOC database contains over 500,000 indicators enriched by real-world IR engagements and Skuggaheimar dark web intelligence. We scan for known threats while simultaneously hunting for novel behavioral anomalies.

💤

Dormant Threat Detection

Adversaries plant backdoors and sleeping implants designed for later activation. We identify these dormant threats by examining persistence mechanisms, scheduled tasks, and system configurations against known-good baselines.

📡

Network Telemetry

Strategic sensor deployment captures C2 beaconing, DNS tunneling, encrypted exfiltration channels, and lateral movement patterns. We analyze traffic at egress points, VLAN boundaries, and cloud gateways for signs of adversary activity.

🛡

Zero Disruption

Our lightweight collection methodology operates silently alongside your production workloads. No reboots, no performance degradation, and no alerts to a potential adversary that an investigation is underway.

🔄

Seamless IR Transition

If active compromise is discovered, our IR team transitions immediately from assessment to containment -- no handoffs, no re-scoping, no wasted time. The same analysts who found the threat lead the remediation effort.

Related Services

Are You Already Compromised?

The only way to know for certain is to look. Schedule a Compromise Assessment and get a definitive answer backed by forensic-grade analysis of your entire environment.