Mandiant Security Validation measures how effective your security controls actually are — with automated, real-world attack emulation instead of assumptions.
What Is Mandiant Security Validation?
Mandiant Security Validation proactively tests and validates the effectiveness of security controls. Technically, you deploy a director as the central instance and agents (actors) onto SIEM, EDR, DLP, or other security controls. The director provides the emulation content; the agents perform configuration verification and automated security control testing.
Google Cloud distinguishes this from pure breach and attack simulation (BAS): emulation goes beyond BAS and includes Protected Theater for safely running destructive endpoint tests as well as email-based tests onsite or in the cloud with the Cloud Validation Module (CVM).
Core Features
- MITRE ATT&CK framework mapping: Assess whether tools and processes effectively protect against real-world targeted attacks; Mandiant frontline intelligence provides the latest adversary tactics, techniques, and procedures (TTPs), mapped to frameworks such as MITRE ATT&CK and NIST
- Advanced Environmental Drift Analysis (AEDA): Continuous testing for historical and new threats with timely alerts on defensive regressions
- Real-world attack emulation: Protected Theater for destructive endpoint tests, Cloud Validation Module for email tests
- Automated, continuous testing: Repeatable checks instead of point-in-time assessments
Typical Use Cases
Test Network, Endpoint, and Email Controls
Continually monitor firewalls, IDS/IPS, proxy servers, DLP, EDR, and uncorrelated SIEM events for risk, and automatically detect environmental drift so that improvements are maintained over time.
Test for Human Error
Running multiple systems across multiple environments adds complexity. Security Validation finds human errors in configurations, settings, and inconsistent testing scenarios.
Mitigate Acquisition Risk
During the due diligence period of mergers and acquisitions, check the target’s posture and security controls for gaps and critical misconfigurations.
Benefits
- Measurable effectiveness: Quantifiable insight into security control performance under attack
- Intelligence-based testing: TTPs from current Mandiant incident response engagements
- Framework alignment: Assessment along MITRE ATT&CK and NIST
- Reporting for decision makers: Quantitative reporting for executives and non-technical stakeholders
Integration with innFactory
As a certified Google Cloud partner, innFactory supports you with Mandiant Security Validation: designing test scenarios, deploying director and agents, and evaluating and acting on the results.
Typical Use Cases
Technical Specifications
Frequently Asked Questions
What is Mandiant Security Validation?
According to Google Cloud, Mandiant Security Validation proactively tests and validates the effectiveness of your security controls to help protect your organization's critical assets. It leverages timely threat intelligence and automated, continuous testing of security controls using real-world attack simulations.
How does it work technically?
You deploy a director and agents (or actors) to a SIEM, EDR, DLP, or any other security control. The director acts as the brains of the operation, providing emulation content to the agents, which perform configuration verification and automated security control testing.
What outcomes does Security Validation deliver?
Per Google Cloud, the captured data enables security teams to identify gaps, misconfigurations, redundancies, and a lack of accurate SIEM correlation and alerting within a security program, and to measure improvement over time.
Can malware and ransomware attacks be tested safely?
Google Cloud states that Mandiant Security Validation can safely test an organization's ability to detect or prevent malware and ransomware attacks. Protected Theater is available for destructive endpoint tests.
What is environmental drift?
Advanced Environmental Drift Analysis (AEDA) continuously tests the environment for both historical and new threats, providing timely alerts for any defensive regressions.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.
