Mandiant Security Validation: Step 5 - Testing

Table of Contents

Below you'll find a table of contents for the Testing journey.

msv-testing.png

 

Mandiant Security Validation utilizes an isolated virtual environment called Protected Theater to allow you to safely test the efficacy of endpoint security controls against destructive behaviors. In this section, we will walk you through the process of deploying and utilizing the Protected Theater.

Prerequisites

  • Administrative access to MSV Director.

Actions

msv-testing-deploy-protected-theater.png
Deploy Protected Theater

In this action, we will walk you through all of the decisions and steps necessary to deploy a Protected Theater.

 
Show More
Prerequisites

See the Relevant Links section for more documentation regarding the prerequisites.

  • Administrative access to MSV Director.
  • Administrative access to VMware vSphere.
  • Static IP Address for the Protected Theater.
Steps
  1. Confirm that the hardware meets specifications in linked documenation. | Docs

  2. Confirm that nested virtualization is enabled for the Protected Theater VM. See linked VMware documentation for more information. | Docs

  3. Review additional information in the linked documenation to ensure that all SSL certificates and protected artifacts and services have been configured properly. | Docs

  4. Deploy the Protected Theater using OVA, see linked documentation. | Docs

  5. Register the Protected Theater with the Director, see linked documentation. | Docs

  6. Configure the customer Gold Image, see linked documentation. | Docs

  7. Import the customer gold image into the Protected Theater, see linked documentation. | Docs

Relevant Links

 

msv-testing-utilize-protected-theater.png
Utilize Protected Theater

Protected Theater is an extremely powerful tool to test the efficacy of your security controls. In this section, we will walk you through uploading files to the endpoint file library, connecting to the Protected Theater using VNC or Console, and finally, creating a Protected Theater Action.

Show More
Prerequisites

See the Relevant Links section for more documentation regarding the prerequisites.

  • Administrative access to MSV Director.
  • Deployed Protected Theater.
Steps
  1. In order to upload files to the Endpoint Files Library, you'll need to navigate to the Director and sign-in.

  2. Select Library > Endpoint Files.

  3. Click Add File and select the file you want to upload.

  4. Add a description of the file.

  5. Select the lowest User Group that should have access to the file.

  6. Click Submit.

  7. To connect to the Protected Theater over Console, you will need to navigate to the Director and sign-in. Then click Environment > Protected Theaters.

  8. Click Edit next to the Protected Actor.

  9. Click Launch Console.

  10. Protected Theater Actions are a special type of Host CLI Action that includes destructive behaviors. Ensure that you've already added the file to the File Library, if your action will utilize a file.

  11. Approve the file or have your Security Validation admin approve the file.

  12. Create and save the Host CLI Action.

Relevant Links

msv-testing-testing-defense.png

Testing Ransomware Defense

Ransomware Defense Validation (RDV) is available for Mandiant Security Validation customers. It delivers a "low touch", safe, and continuous test of whether your security controls can prevent the latest ransomware.

 
Show More
Prerequisites

See the Relevant Links section for more documentation regarding the prerequisites.

  • Administrative access to MSV Director.
  • Ensure you've met the prerequisites.
Steps
  1. In order to run RDV actions, you will need to log in to the MSV Director. Navigate to Library > Actions.

  2. On the Actions Library page, add Ransomware Defense Validation as a tag to filter on the RDV content.

  3. Get a list of ransomware Actions available in the library.

  4. Select the Action that you want to run and then click Run.

  5. Select Actors to choose the Actor to run the Action against.

  6. Click Run Now or Schedule.

Relevant Links

Congratulations!

msv-journey-complete.png

 

Your Mandiant Security Validation Journey is complete!

Version history
Last update:
a month ago
Updated by: