Security appliance testing
Verify that your security appliances effectively cover your infrastructure.
What is a security appliance audit?
An audit of your security appliances (EDR, SIEM and others) verifies that they effectively cover your entire information system.
The goal is to make sure the tool is correctly installed and configured to detect malicious behavior.
Objectives
Our appliance audits highlight the gaps and areas for improvement along the following axes:
Actual coverage of the IT estate
Appliance configuration
Detection effectiveness
Review of the rules in place
Alert handling
The HELX approach
For every stage of a real intrusion, we maintain a set of tests that a security appliance should detect. During these audits, we run through the various scenarios and rate how well the appliance responds.
At the end of the audit, you receive concrete, tailored recommendations to strengthen the effectiveness of your detection tools and guarantee optimal protection of your equipment and your information system.
Methodology
Security appliance audits combine discussions with your teams and a set of use-case-based tests to evaluate the effectiveness of the tools in place. Our audits follow the process detailed below:
- 01
Test scenario tailoring
We adapt our use cases to your infrastructure and your needs. The tests are grouped into categories and are designed to simulate the phases of an intrusion.
- 02
Coverage analysis
We analyze the entire information system to find the machines missing the security solution and spot potential blind spots.
- 03
Unit test execution
We run through the full set of use cases representing the different attacks that can occur during an intrusion. We then analyze the alerts raised by the security tool to build a list of the attacks that went undetected.
- 04
Response analysis
We evaluate the entire process of detecting, classifying and responding to the security alerts raised.
A bit of technical detail
Our test scenarios cover the different stages of an intrusion and are based on the MITRE ATT&CK framework:
- Port scans
- User enumeration
- Identity spoofing
- Data exfiltration
- Lateral movement
- Remote command execution
- Antivirus evasion
- Exploitation of known vulnerabilities
- Persistence setup
- Disk encryption
Our other penetration tests
Frequently asked questions
How much does a security appliance test cost?
A fixed price of €6,800 excl. VAT, covering eight days of expertise, with a 15% discount for small businesses, SMBs and non-profits. The scope covers your detection and protection solutions: EDR, SIEM, firewall, proxy, EPP.
We already have an EDR managed by a provider: is this useful?
A poorly tuned EDR catches demo samples and lets real techniques through. We replay current attacker behaviors (execution, persistence, lateral movement, exfiltration) to measure what your tools actually see and what slips past them.
What is the deliverable?
A coverage matrix, technique by technique (detected / logged / missed), and above all concrete configuration recommendations your team or your managed service provider can apply directly.
Could the test trigger a cascade of alerts?
That is the point, but in a controlled way: agreed execution windows, identified test machines and coordination with your SOC teams so we do not pollute their monitoring.
Tell us about your project.
Let us talk through your needs and expectations and build the right service for you.
