Security Basics mailing list archives

Re: Mandiant Intelligent Response


From: David Kovar <dkovar () gmail com>
Date: Fri, 8 Jun 2012 19:30:51 -0500

Greetings,

I've used it a bit. A couple of observations:

1) It takes a certain amount of skill and training to use well. If you use it occasionally, you might be constantly 
relearning how to use it effectively.
2) The current version is constantly in flux as it was designed for internal use and they've made it available for 
clients to use.
3) I think they're considering a major rewrite to make it more customer friendly, but do not know for sure.
4) Much of the value in it is the IOCs used, and another significant contributor to effective use is the operator. 
5) They also sell a managed service with the option to have your own controller so you can use the Mir environment 
while Mandiant does the heavy lifting. This might be a good way to start.
6) NTAP adds significant value to Mir.

-David

On Jun 6, 2012, at 9:07 PM, Dave Kleiman wrote:


Does anyone have any experience with Mandiant Intelligent Response (http://www.mandiant.com/products/platform/ )?  We 
are considering buying the system, and wanted to know if anyone could provide feedback on accuracy, ROI etc.?



Respectfully,

Dave Kleiman - http://www.ComputerForensicsLLC.com - http://www.DaveKleiman.com

4371 Northlake Blvd #314
Palm Beach Gardens, FL 33410
561.310.8801 





------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: