Mandiant Security Validation: Step 5 - Testing

Table of Contents

Below you'll find a table of contents for the Testing journey.

msv-testing.png

 

Mandiant Security Validation utilizes an isolated virtual environment called Protected Theater to allow you to safely test the efficacy of endpoint security controls against destructive behaviors. In this section, we will walk you through the process of deploying and utilizing the Protected Theater.

Prerequisites

  • Administrative access to MSV Director.

Actions

msv-testing-deploy-protected-theater.png
Deploy Protected Theater

In this action, we will walk you through all of the decisions and steps necessary to deploy a Protected Theater.

 
Show More
Prerequisites

See the Relevant Links section for more documentation regarding the prerequisites.

  • Administrative access to MSV Director.
  • Administrative access to VMware vSphere.
  • Static IP Address for the Protected Theater.
  • An MSV license with Protected Theater as an included entitlement.
Steps
  1. Confirm that the hardware meets specifications in linked documenation. | Docs

  2. Confirm that nested virtualization is enabled for the Protected Theater VM. See linked VMware documentation for more information. | Docs

  3. Review additional information in the linked documentation to ensure that all SSL certificates and protected artifacts and services have been configured properly. | Docs

  4. Deploy the Protected Theater using OVA, see linked documentation. | Docs

  5. Register the Protected Theater with the Director, see linked documentation. | Docs

  6. Configure the customer Gold Image, see linked documentation. | Docs

  7. Import the customer gold image into the Protected Theater, see linked documentation. | Docs

  8. Review additional information for configuring user profiles and protected rule assignments. | Docs

  9. Install the MSV software agent onto the Golden Image, and register the Protected Actor to the Director.  Utilize the steps in the next section to upload the MSV installation files to the director, and access the director from the imported Golden Image to download the installation files. 

Relevant Links
msv-testing-utilize-protected-theater.png
Utilize Protected Theater

Protected Theater is an extremely powerful tool to test the efficacy of your security controls. In this section, we will walk you through uploading files to the endpoint file library, connecting to the Protected Theater using VNC or Console, and finally, creating a Protected Theater Action.

Show More
Prerequisites

See the Relevant Links section for more documentation regarding the prerequisites.

  • Administrative access to MSV Director.
  • Deployed Protected Theater.
  • Deployed Protected Actor with MSV Agent installed and connected to MSV Director.
Steps
  1. In order to upload files to the Endpoint Files Library, you'll need to navigate to the Director and sign-in.

  2. Select Library > Endpoint Files.

  3. Click Add File and select the file you want to upload.

  4. Add a description of the file.

  5. Select the lowest User Group that should have access to the file.

  6. Click Submit.

  7. To connect to the Protected Theater over Console, you will need to navigate to the Director and sign-in. Then click Environment > Protected Theaters.

  8. Click Edit next to the Protected Actor.

  9. Click Launch Console.

  10. Protected Theater Actions are a special type of Host CLI Action that includes destructive behaviors. Ensure that you've already added the file to the File Library, if your action will utilize a file.

  11. Approve the file or have your Security Validation admin approve the file.

  12. Create and save the Host CLI Action.

Relevant Links

msv-testing-testing-defense.png

Initial Baseline Testing 

The action of baselining in reference to a security validation program and using a tool like Mandiant Security Validation (MSV), is the process of running a core set of tests to evaluate the effectiveness of the controls in your environment to provide a basis of data.

 
Show More
Prerequisites
  • Administrative access to MSV Director.
  • Deployment of MSV Director, Internal Network and Endpoint Actors, and a externally hosted network actor.
  • Recommended:  Configured integrations with your security technologies, (SIEM, EDR/AV, etc.)
Steps
    1. Review the following Blog on how to develop baseline testing for new security validation deployments. | Docs
Relevant Links
 

Congratulations!

msv-journey-complete.png

 

Your Mandiant Security Validation Journey is complete!

Previous Step: Mandiant Security Validation: Step 4 - Security Content

Contributors
Version history
Last update:
‎10-11-2024 12:58 PM
Updated by:
OSZAR »