What is Compromise Intelligence?

Prevailion map image
27 January 2020

Compromise Intelligence is a new method of information gathering sourced from the activity surrounding networks with confirmed evidence of cyber compromise. 

Instead of the conventional perspective of inside-out network visibility, it is outside-out—operating fully outside of an organization’s network, showing the activities of adversaries as they launch assaults on network defenses around the world. 

By tracking sophisticated threat actors and monitoring their command and control (C2) infrastructure, information is collected on what these adversaries are targeting and how their malicious attacks are being carried out.

Organizations can use this intelligence to:

  • Assess third-party risk by seeing compromises cascade through an industry
  • Enrich the information gathering of their existing threat hunting teams
  • Isolate the target of an impending data breach and take preventative action

What makes Compromise Intelligence Different from Threat Intelligence?

The distinguishing characteristic is the level of confidence in the intelligence being conveyed, along with the volume. 

Compromise Intelligence removes the guesswork from noisy feeds of indicators, conveying only confirmed, actionable intelligence on the activity of threat actors. Threat Intelligence encompasses all manner of indicators of potential threats to a network from a variety of sources, whether those are of low-, medium-, and high-levels of confidence. Suppliers of threat intelligence are not concerned with flooding a listener with information, but in providing a comprehensive assessment. It is like having ten thousand new browser tabs that need to be reviewed every day—forever.

The challenge for the listener is to prioritize those threat indicators into an actionable plan. Compromise Intelligence proposes to simplify that challenge by relegating the reported intelligence to only the evidence.

How does Compromise Intelligence Work?

Instead of sifting through endless amounts of data captured on-premises, proprietary beacon technology waits for a dormant threat to signal outbound from an organization, back to its home, where the telemetry (i.e. Compromise Intelligence) is captured and documented. 

Prevailion is the world’s first Compromise Intelligence solution, empowering organizations to swap the traditional roles of victims and adversaries in the dangerous world of cybersecurity. The Prevailion platform is like a search engine for discovering active and historical third-party compromises worldwide. Organizations can set it up in less than a minute and find Evidence of Compromise within their own or third-party ecosystems right away. 

The Latest

Diving Deep into UNC1151’s Infrastructure: Ghostwriter and beyond

Introduction: Prevailion’s Adversarial Counterintelligence Team (PACT) is using advanced infrastructure hunting techniques and Prevailion’s unparalleled visibility into threat actor infrastructure creation to uncover previously unknown domains associated with UNC1151 and the “Ghostwriter” influence campaign.  UNC1151 is likely a state-backed threat actor [1] waging an ongoing and far-reaching influence campaign that has targeted numerous countries across […]

Prevailion CEO, Karim Hijazi- Biden’s Cybersecurity Strategy

Prevailion CEO, Karim Hijazi, comments on lacking White House cybersecurity efforts Karim Hijazi lays out why Biden’s cybersecurity strategy lacks innovation and effectiveness to deal with modern adversaries already inside companies around the globe.    

Prevailion CEO, Karim Hijazi- Tmobile Hack

Prevailion CEO, Karim Hijazi, talks about the T-Mobile hack and cloned SIM cards Karim Hijazi says T-Mobile’s breach is the largest in carrier history and discusses SIM swapping and other forms of identity theft.    

Copyright 2021 Prevailion, Inc. All rights reserved.    

Disclaimer: Gartner “Cool Vendors in Security Operations and Threat Intelligence,” Mitchell Schneider, Ruggero Contu, John Watts, Craig Lawson, October 13, 2020. GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved. Gartner Disclaimer: The GARTNER COOL VENDOR badge is a trademark and service mark of Gartner, Inc. and/or its affiliates and is used herein with permission. All rights reserved. Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s Research & Advisory organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.