Compromise Assessment: Could an attacker still be inside?

What a compromise assessment is, what it covers, and when an organisation should consider one to find evidence of current or past attacker activity.

·2 min read·MetaCyber

Silence from your security tools does not mean there is no attacker in your environment. In targeted attacks, the time between initial access and detection is often measured in weeks or months, and during that time an attacker can move quietly using legitimate administration tools.

A compromise assessment sets out to answer one question directly: Is there, or has there been, an attacker in our environment?

How is it different from a penetration test?

A penetration test checks whether an attacker could get in. A compromise assessment investigates whether an attacker already has. The first focuses on vulnerabilities, the second on the traces an attacker leaves behind. They complement each other rather than replace one another.

What does it cover?

A typical compromise assessment consists of:

  1. Scoping and collection: Forensic artefacts from endpoints, logs from identity infrastructure (Active Directory, Entra ID), and SIEM and network data are collected.
  2. Threat hunting: Beyond known malware signatures, analysts look for persistence mechanisms, unusual account activity, lateral movement and signs of data exfiltration.
  3. Analysis and validation: Every finding is reviewed by an analyst, false positives are removed and confirmed findings are placed on a timeline.
  4. Reporting: Traces found, affected systems and prioritised remediation steps are reported separately for leadership and technical teams.

When is it needed?

A compromise assessment is worth considering:

  • Before a merger or acquisition, to confirm the integrity of the infrastructure being acquired,
  • When an attack campaign targeting your sector becomes public,
  • When a new security leader takes over and needs an independent baseline,
  • When unexplained performance issues, unexpected account lockouts or unusual traffic appear,
  • As part of periodic assurance.

Conclusion

A compromise assessment answers “are we safe?” with evidence rather than assumptions. A clean result gives measurable assurance; a finding allows response before an attack grows.

MetaCyber’s analyst team delivers compromise assessments, incident response and forensics end to end. See our DFIR service page or get in touch.

← All posts

Let's review your infrastructure and security posture together.

Tell us briefly what you need and the right team will get in touch.