Assessment

Security appliance testing

Verify that your security appliances effectively cover your infrastructure.

§ 01 · Overview

What is a security appliance audit?

An audit of your security appliances (EDR, SIEM and others) verifies that they effectively cover your entire information system.

The goal is to make sure the tool is correctly installed and configured to detect malicious behavior.

Objectives

Our appliance audits highlight the gaps and areas for improvement along the following axes:

  • Actual coverage of the IT estate

  • Appliance configuration

  • Detection effectiveness

  • Review of the rules in place

  • Alert handling

§ 02 · Approach

The HELX approach

For every stage of a real intrusion, we maintain a set of tests that a security appliance should detect. During these audits, we run through the various scenarios and rate how well the appliance responds.

At the end of the audit, you receive concrete, tailored recommendations to strengthen the effectiveness of your detection tools and guarantee optimal protection of your equipment and your information system.

§ 03 · Methodology

Methodology

Security appliance audits combine discussions with your teams and a set of use-case-based tests to evaluate the effectiveness of the tools in place. Our audits follow the process detailed below:

  1. 01

    Test scenario tailoring

    We adapt our use cases to your infrastructure and your needs. The tests are grouped into categories and are designed to simulate the phases of an intrusion.

  2. 02

    Coverage analysis

    We analyze the entire information system to find the machines missing the security solution and spot potential blind spots.

  3. 03

    Unit test execution

    We run through the full set of use cases representing the different attacks that can occur during an intrusion. We then analyze the alerts raised by the security tool to build a list of the attacks that went undetected.

  4. 04

    Response analysis

    We evaluate the entire process of detecting, classifying and responding to the security alerts raised.

§ 04 · Use cases

A bit of technical detail

Our test scenarios cover the different stages of an intrusion and are based on the MITRE ATT&CK framework:

  • Port scans
  • User enumeration
  • Identity spoofing
  • Data exfiltration
  • Lateral movement
  • Remote command execution
  • Antivirus evasion
  • Exploitation of known vulnerabilities
  • Persistence setup
  • Disk encryption

Our other penetration tests

FAQ

Frequently asked questions

How much does a security appliance test cost?

A fixed price of €6,800 excl. VAT, covering eight days of expertise, with a 15% discount for small businesses, SMBs and non-profits. The scope covers your detection and protection solutions: EDR, SIEM, firewall, proxy, EPP.

We already have an EDR managed by a provider: is this useful?

A poorly tuned EDR catches demo samples and lets real techniques through. We replay current attacker behaviors (execution, persistence, lateral movement, exfiltration) to measure what your tools actually see and what slips past them.

What is the deliverable?

A coverage matrix, technique by technique (detected / logged / missed), and above all concrete configuration recommendations your team or your managed service provider can apply directly.

Could the test trigger a cascade of alerts?

That is the point, but in a controlled way: agreed execution windows, identified test machines and coordination with your SOC teams so we do not pollute their monitoring.

Tell us about your project.

Let us talk through your needs and expectations and build the right service for you.