Executive Exposure Assessment
A named campaign is in the news and someone senior needs an answer today. How to produce one that is fast, defensible, and honest about what it does not cover.
A campaign is on the front page. Your CEO forwarded the article at 07:15 with three words on top of it, and the three words mean "are we exposed". Your board briefing is on Thursday. You have a vendor report with forty hashes and a handful of domains, a fleet, and most of a day.
The trap in this request is not the searching. It is that "are we exposed" is not a question with a yes or no answer, and the two easy answers are both wrong. "No" overstates what any tool can establish. "We are still investigating" is true on Thursday and useless on Thursday. What an executive can actually act on is a scoped answer: here is what we looked for, here is what we found, here is the part of the estate this answer does not cover, and here is why the answer stays current without anyone re-running it.
Easy Mode: let Backstory run this investigation and read the report it returns.
What will I know by the end?
Whether any of the campaign's indicators has ever been in your environment and on which machines and dates, whether anything resembling the campaign's tooling is present under a different hash, what proportion of your fleet the answer covers, and a subscription that keeps answering after the briefing.
Why this works
Three ideas carry this one, and together they are why a defensible answer is possible in a day.
The answer reaches backwards. Stairwell keeps the files, so a report published this morning can be run against what your fleet held last spring. That is the half most tooling cannot give you, and it is what separates "we have no alerts" from "we checked, and here is what was there".
An indicator list is a floor, not a ceiling. A report covers the samples its author could account for, and adversaries recompile between campaigns. So the honest sweep asks what resembles the tooling as well as what matches it, which is why Step 4 exists and why a hash-only answer overstates its own confidence.
Coverage bounds the claim. Whatever you find, the sentence an executive can act on names the part of the estate the answer does not cover. A gap in forwarder rollout is a gap in the finding, and stating it is what makes the rest of the briefing credible rather than what undermines it.
If you want the instruments themselves rather than this scenario, Investigate & Hunt covers each one on its own.
Step 1: What exactly am I being asked?
Pin the question to a document before you touch the platform. Five minutes here saves you from answering the wrong question thoroughly.
- Which campaign? A press article usually names a group and describes two incidents from three different intrusion sets. Find the vendor or CERT report the article is derived from. That report, with its indicator list, is your scope statement.
- Exposed to what? The article may be about a vulnerability, a phishing wave, and a malware family at once. Stairwell answers the file and infrastructure question: has this tooling, or anything resembling it, been on our machines. That is one of the three, it is usually the one the executive means, and it is worth saying which one you are answering.
- By when, and for whom? A verbal answer in an hour and a board slide on Thursday are different deliverables. The hour version is Steps 2 and 3. Thursday's version is all of it.
Step 2: What is the fastest read?
Paste the whole report into the search bar. Do not transcribe indicators by hand.
Stairwell pulls the hashes, hostnames, and addresses out of pasted text, including defanged forms, so the fastest path from a PDF to an answer is copy, paste, search. See Hunting and Search. This is a two-minute step and it is often the whole of the verbal answer you owe by 09:00.
Read the two object tabs as two different answers, because conflating them is how a report gets embarrassed:
- My Objects is exposure. These files have been in an environment you can read.
- Global Objects is context. Stairwell holds the file, your fleet has not reported it. That is worth knowing and it is not an incident, and it must not appear in an executive summary as though it were.
A clean My Objects result at this stage is genuinely good news and it is not the finished answer. It covers the indicators the vendor published, which is a subset of the campaign, and it is bounded by your coverage. Steps 4 and 6 are what turn it into something you can defend.
Step 3: How do I make the answer keep working?
Bring the report in as a threat report rather than leaving it as a search. This is the step that separates this playbook from a search anyone could have run, and the reason is structural.
A search answers once, for the indicators you happened to paste, in the window your other tools still remember. A report is matched continuously and in both directions in time. Backward, across the files you have already collected, so a report published this morning tells you about a file that has been sitting on three of your servers since last spring, with the assets and paths attached. Forward, across everything that arrives next, so the same list keeps working next month without anyone reopening the PDF.
That second half is what makes the answer defensible on Thursday. "We are not affected" and "we are not affected, and we will know within the hour if that changes" are different statements, and only one of them survives a follow-up question.
Subscribe the environments that should be covered, and note which ones you subscribed, because that list is part of your scope statement. Then configure a trigger on the report, so a late match reaches a person by email or webhook rather than waiting to be noticed in the UI. Campaigns publish second and third waves of indicators, and a machine that comes back from a drawer next month is a real scenario.
Step 4: What did the report not tell me to look for?
Open Variants on any match, and on the campaign's samples even when nothing matched.
An indicator list is a list of the files the vendor happened to obtain. The family is always larger, and the gap is not an oversight: an exact hash stops matching the moment the operator recompiles, repacks, or pads a file, which costs them minutes and costs a hash-based sweep everything.
Variant Discovery answers the other question, "what else looks like this", across the entire corpus, both your own private files and the global malware corpus, and it traverses between them:
- A file A from the campaign sits in the global malware corpus.
- A has its own relatives there: earlier builds, repacks, the rest of the family.
- One of those relatives leads back to a file B, on a machine inside your own environment.
- A and B may not resemble each other closely enough to connect directly.
Searching only your own files, and only for the published hashes, would never have surfaced B. The global corpus is the bridge, and this is the step that most often turns a clean sweep into a real finding. It is also the sentence worth putting in the briefing, because it is the difference between checking a list and assessing exposure.
Variant Discovery runs automatically for threat reports and Backstory investigations, and on demand from the UI and the API.
Step 5: How do I keep a false positive out of the briefing?
Check prevalence on every match before it reaches a slide. This is the cheapest quality gate on the page and skipping it is the most common way an exposure assessment goes wrong in public.
A match on a file present in most environments Stairwell observes is almost never the campaign. Broad indicators and reused infrastructure find popular software: a shared hosting address, a content delivery network, a legitimate administration tool the operators also used. Read which indicator linked each match, because a hash link is a strong statement and an address link on shared hosting usually is not.
Campaigns lean on legitimate tooling deliberately, so expect at least one match to be your own remote monitoring agent or archiver. The Alert Is a Legitimate IT Tool is that decision in full. Adjudicate it before Thursday rather than in the room, and record the call as an opinion with a comment, which also takes the file out of the report's match count so the number on your slide is the number you meant.
Step 6: What does my answer not cover?
Establish this before you write anything, because it is the part an executive answer is judged on later and the part nobody asks for up front.
- Fleet coverage. How many machines report against how many you have. Open Assets and check recent check-ins. A clean result across 70 percent of the estate is a clean result across 70 percent of the estate, and saying so is what makes the other 70 percent believable.
- What is collected. Roughly 65 executable and script formats by default, tunable by your team. If the campaign turns on a malicious document or a configuration change, that is outside the default collection set and your answer should say so rather than imply coverage it does not have.
- Presence, not execution. Stairwell establishes that a file was on a machine at a path from a date. It is not inline and is not a network enforcement point, so it does not tell you the file ran. For an exposure question presence is usually the right answer anyway, and stating it precisely is what stops the finding being discounted later.
- The indicator scope. You searched the indicators in one report plus what resembles them. Another vendor's write-up of the same campaign may carry indicators this one does not, and adding a second report is cheap.
Step 7: How do I write the answer?
Short, in the order an executive reads, with the scope attached rather than appended as a disclaimer.
- The answer, in one sentence. "We found no files associated with this campaign on our fleet" or "we found three files on two machines, first present on 4 March".
- What was searched. The report you used, the number of indicators, the environments subscribed, and that the search covered files already collected as well as everything arriving since. This sentence is what makes the first one worth anything.
- What was found, if anything. Machines, paths, dates. Presence and timing, phrased as presence and timing.
- What the answer does not cover. Step 6, in two lines. Fleet coverage as a number, and the collected-formats limit if it is relevant to this campaign.
- What happens next without anyone doing anything. The report stays subscribed, matching continues in both directions, and a trigger notifies a named person. This is the line that ends the follow-up questions.
If you found something, the exposure assessment is over and you have an incident. An EDR Alert Just Fired picks up from a single confirmed file, and Ransomware Hit a Host if the campaign is that kind.
Can Backstory do this for me?
For the investigation half, yes, and it is worth reaching for when the clock is the constraint. Seed Backstory with one of the campaign's hashes, or with a hostname or address from the report, and it establishes what the file is, expands across variants, runs Run-to-Ground, and pulls in sightings, prevalence, resolution history, and published intelligence, returning a report rather than a dashboard. See Starting an Investigation.
Two things it does not do for you. It does not decide your scope statement, which is Steps 1 and 6 and is the part that makes the answer defensible. And it does not replace an analyst: what to tell the board, and what to do about it, is your judgment. Note also that a Backstory seed is a hash, a hostname, or an IPv4 address rather than an asset, so seed it with an indicator from the report.
If the finished investigation needs to go to someone who does not use Stairwell, it downloads as a single self-contained HTML file. See Sharing a Backstory Report.
What should I read next?
- New IOCs Were Published, the same work as a routine, on the days nobody is watching.
- What Is a Threat Report?, for why Step 3 is the step that matters.
- Write It Up, for turning what you found into coverage other teams can use.
- Prevalence, for the quality gate in Step 5.
Updated 19 days ago