Compromise Check

β€œAre we already breached?” A focused hunt for intruder evidence β€” persistence, suspicious access, and the things your alerts missed.

Why this matters: The average intruder sits in a network for months before anyone notices β€” the Velvet Ant backdoors survived since 2016 inside trusted authentication binaries. If the question keeping you up is β€œare they already inside?”, a scan will not answer it. This is a targeted hunt for the evidence an intruder leaves behind.

What we cover

  • Persistence hunting: accounts, tasks, services, authentication tampering
  • Suspicious authentication patterns and impossible-travel access
  • EDR/AV blind-spot review and tamper checks
  • Key artifact review: logs, memory, and persistence locations
  • Exfiltration indicators in egress and DNS patterns
  • Clear verdict: evidence found, or clean with confidence bounds

How we test

1Hypothesis setup

We start from realistic intrusion scenarios for your stack β€” what would an attacker have done to stay?

2Artifact hunting

Targeted review of the locations and artifacts those scenarios touch.

3Timeline analysis

Anything suspicious gets reconstructed into a timeline: what happened, when, from where.

4Verdict & response

A clear answer with evidence β€” and immediate containment steps if we find something.

What you get

  • Clear compromise verdict with evidence
  • Reconstructed timelines for anything found
  • Immediate containment recommendations
  • Detection improvements so it cannot repeat silently

The engagement at a glance

πŸ“ž Free scoping call

A short conversation about your environment. You receive a written scope, timeline, and fixed quote β€” no obligation.

✍️ Signed authorization

Testing begins only with your written permission and agreed rules of engagement. Always.

⏱️ Time-boxed delivery

A calendar agreed before we start, with an agreed communication plan while testing runs.

πŸ” Retest included

A verification pass over everything you fix β€” included in the price, not an add-on.

See the full engagement process β†’ and how pricing is scoped in our public pricing guide.

Related research from Hmmnm

Common questions

How is this different from a penetration test?

A pentest simulates a future attack from outside. A compromise check hunts for an attack that may already have happened β€” persistence, tampering, and missed evidence.

What access do you need?

Read access to key systems and logs: authentication logs, EDR console, and selected hosts for artifact review. We agree the exact scope beforehand.

What if you find something?

You get immediate containment steps, a reconstructed timeline, and β€” if you want β€” hands-on help executing the response.

Authorization first, always. Testing happens only with your written permission and agreed rules of engagement β€” the same ethics that govern responsible disclosure on this site.

Want this assessed for your environment?

A short scoping conversation is enough to get a fixed quote. No obligation β€” a researcher replies.

Start the conversation β†’