Posts

Showing posts with the label mandiant

Mandiant Global Median Dwell Time Deteriorates from 11 to 14 Days

Image
  Oh snap. My single most important cybersecurity metric deteriorated again.  In the M-Trends report for calendar year 2024, Mandiant’s global median dwell time metric worsened from 10 to 11 days. In the newest report, released today, for calendar year 2025, that metric worsened again, from 11 to 14 days.  In other words, organizations are taking even longer to detect and respond to intrusions. 10 days was already still too much, in a world where teams need to detect and contain in an hour to be effective.  I’m not a doomer. We made amazing progress since 2011, when median global dwellers time was over 400 days. But, two bad years in a row has never happened. Before last year, the metric had always improved! It’s possible Mandiant is just dealing with ever tougher cases. I have to dig into the full report. 

The Origin of the Term Indicators of Compromise (IOCs)

Image
I am an historian . I practice digital security, but I earned a bachelor's of science degree in history from the United States Air Force Academy. (1) Historians create products by analyzing artifacts, among which the most significant is the written word. In my last post , I talked about IOCs, or indicators of compromise. Do you know the origin of the term? I thought I did, but I wanted to rely on my historian's methodology to invalidate or confirm my understanding. I became aware of the term "indicator" as an element of indications and warning (I&W), when I attended Air Force Intelligence Officer's school in 1996-1997. I will return to this shortly, but I did not encounter the term "indicator" in a digital security context until I encountered the work of Kevin Mandia. In August 2001, shortly after its publication, I read Incident Response: Investigating Computer Crime , by Kevin Mandia, Chris Prosise, and Matt Pepe (Osborne/McGraw-Hill). I ...

Bejtlich on the APT1 Report: No Hack Back

Image
Before reading the rest of this post, I suggest reading Mandiant/FireEye's statement Doing Our Part -- Without Hacking Back . I would like to add my own color to this situation. First, at no time when I worked for Mandiant or FireEye, or afterwards, was there ever a notion that we would hack into adversary systems. During my six year tenure, we were publicly and privately a "no hack back" company. I never heard anyone talk about hack back operations. No one ever intimated we had imagery of APT1 actors taken with their own laptop cameras. No one even said that would be a good idea. Second, I would never have testified or written, repeatedly, about our company's stance on not hacking back if I knew we secretly did otherwise. I have quit jobs because I had fundamental disagreements with company policy or practice. I worked for Mandiant from 2011 through the end of 2013, when FireEye acquired Mandiant, and stayed until last year (2017). I never considered quitting...

The Missing Trends in M-Trends 2017

Image
FireEye released the 2017 edition of the Mandiant M-Trends report yesterday. I've been a fan of this report since the 2010 edition , before I worked at the company. Curiously for a report with the name "trends" in the title, this and all other editions do not publish the sorts of yearly trends I would expect. This post will address that limitation. The report is most famous for its "dwell time" metric, which is the median (not average, or "mean")  number of days an intruder spends inside a target company until he is discovered. Each report lists the statistic for the year in consideration, and compares it to the previous year. For example, the 2017 report, covering incidents from 2016, notes the dwell time has dropped from 146 days in 2015, to 99 days in 2016. The second most interesting metric (for me) is the split between internal and external notification. Internal notification means that the target organization found the intrusion on its...

Mandiant APT1 Report: 25 Best Commentaries of the Last 12 Days

Image
Two weeks ago today our team at Mandiant was feverishly preparing the release of our APT1 report . In the twelve days that followed publication on the evening of Monday the 18th, I've been very pleased by the amount of constructive commentary and related research published online. In this post I'd like to list those contributions that I believe merit attention, in the event you missed them the first time around. These sorts of posts are examples of what the security community can do to advance our collective capability to counter digital threats. Please note I avoided mass media accounts, interviews with Mandiant team members, and most general commentary. They are listed in no particular order. Seth Hall (Bro): Watching for the APT1 Intelligence Jason Wood (SecureIdeas): Reading the Mandiant APT1 Report Chris Sanders: Making the Mandiant APT1 Report Actionable Symantec: APT1: Q&A on Attacks by the Comment Crew Tekdefense (NoVA Infosec): MASTIFF Analysis of APT...

Mandiant Webinar Wednesday; Help Us Break a Record!

Image
I'm back for the last Mandiant Webinar of the year, titled State of the Hack: It's The End of The Year As We Know It - 2011 . And you know what? We feel fine! That's right, join Kris Harms and me Wednesday at 2 pm eastern as we discuss our reactions to noteworthy security stories from 2011. Register now and help Kris and me beat the attendee count from last month's record-setting Webinar. If you have questions about and during the Webinar, you can always send them via Twitter to @mandiant and use the hashtag m_soh . Tweet

Check Out MANDIANT Job Postings

Image
If you visit www.mandiant.com/hireme you'll notice MANDIANT is looking to hire a ton of people over the next few weeks and months. We have openings all over the company, including my MCIRT business line. Basically if you're the go-to person in your organization for coding, doing, or supporting incident detection and response tools and/or techniques, you will probably find an interesting job here! The easiest way to start the process is to pick a role and submit your resume. Thank you for your consideration. Tweet

Bejtlich Joining MANDIANT as CSO and Security Services Architect

Image
In June 2007 I posted that I was joining General Electric as Director of Incident Response . Since then I helped build and lead GE-CIRT from an "army of one" into a team of 40 analysts. It was an honor and a privilege to work with my team, but today I am announcing that I've accepted a new challenge. Effective 1 April I will be Chief Security Officer and Security Services Architect for MANDIANT , where I will build teams, tools, and capabilities to provide managed detection and response services. You can read the press release at the MANDIANT Web site or Businesswire if you're so inclined, as well as a MANDIANT blog post . I am really looking forward to this new opportunity. I worked for Kevin Mandia in 2002-2004 with Foundstone and for Travis Reese in 2004-2005 at ManTech International Corp.'s CFIA division. When I left ManTech to concentrate 100% on TaoSecurity, the first consulting I did was for Red Cliff, the precursor to MANDIANT. I also know many cu...

Notes from SC Magazine

The July 2006 SC Magazine features some blogworthy stories. From Working for Gold , we see more opinions that calculating security ROI is a waste of time : In recent years, the acronym of the day was ROSI — return on security investment. Analysts and security managers alike were struggling to find ways to measure security return on investment (ROI) and offer it up as proof to their bosses and executive boards that their money was being maximized. But the magic method to do this has never appeared. And some, such as André Gold, Continental Airlines' information security director, doubt it ever will. "There are a lot of people out there who want to turn the information security department into a profit and loss (P&L) entity and I don't think you can do it," Gold says. "I ran our ecommerce environment for almost seven years and it was really easy to do ROI-type of metrics there. In my opinion you just don't have that in security ." Gold isn't alon...

Red Cliff Consulting, a Trusted Professional Services Firm

Today I spoke with Kevin Mandia, lead author of Incident Response and Computer Forensics , the best IR book available. When the first edition was published, Kevin was director of incident response and computer forensics at Foundstone . I met him in person at the first SANSFIRE conference in 2001. Kevin hired me to join Foundstone's IR team in early 2002, and I left the team in early 2004 a few months after he did. Kevin is now running Red Cliff Consulting , a professional services firm headquartered in Alexandria, VA. He describes his group as "the experts that experts consult." I won't argue with that assessment. For example, Curtis Rose just joined Red Cliff, after working for years at Sytex . Curtis is one of the co-authors of the forthcoming book Real Digital Forensics , along with myself and Keith Jones. Kevin will be speaking at Black Hat 2004 in Las Vegas in late July. He plans to discuss "the five things that are problematic in incident re...