Company intelligence
LevelBlue
LevelBlue. Secure What's Next.
About LevelBlue
LevelBlue. Secure What's Next. LevelBlue reduces risk and builds lasting resilience so organizations can innovate and advance their mission with confidence. As the world’s most analyst-recognized and largest pure-play managed security services provider, LevelBlue elevates client outcomes that matter: stronger defense, faster response, and sustained business continuity. LevelBlue combines AI-powered security operations, advanced threat intelligence, and elite human expertise to provide the most comprehensive portfolio of strategic advisory, managed security, offensive security, and incident response services. Learn more at levelblue.com.
Verified activity
Signals from LevelBlue
23 published signals
Research & Knowledge
LevelBlue researchers traced the full chain of a CrySome RAT investigation found by Sean Shirley.
Reported by LevelBlue
Research & Knowledge
LevelBlue DFIR teams observed that attackers often use a single identity to connect to multiple systems, including Salesforce, SharePoint, OneDrive, HR systems, and SaaS platforms, leading to an efficient attack tour.
Reported by Paul Roberts
Customers & Market
LevelBlue achieved one of the highest retention rates on the industry for MDR/MXDR and vSOC.
Reported by Brian Winkler
Presence & Recognition
LevelBlue participated in the 17th Annual Billington CyberSecurity Summit via the Whova event app.
Reported by Brian Winkler
Presence & Recognition
LevelBlue participated in the 17th Annual Billington CyberSecurity Summit via the Whova event app.
Reported by Brian Winkler
Presence & Recognition
LevelBlue participated in the 17th Annual Billington CyberSecurity Summit via the Whova event app.
Reported by Brian Winkler
Research & Knowledge
LevelBlue published a research paper by ShieldBreak that makes a strong case for looking at sequences rather than individual indicators.
Reported by Paul Roberts
Partnerships
LevelBlue has been named SentinelOne’s premier remediation partner for Wayfinder Frontier AI Services.
Reported by LevelBlue
Presence & Recognition
LevelBlue is participating in a conversation with Resilience on quantifying downtime, prioritizing response investments, and risk conversations across the business.
Reported by Paul Roberts
Research & Knowledge
LevelBlue reports that threat actors are moving past standard phishing pages and using fake app update flows to push unauthorized ScreenConnect clients.
Reported by Paul Roberts
Research & Knowledge
LevelBlue DFIR teams observed that attackers often use a single identity to connect to multiple systems, including Salesforce, SharePoint, OneDrive, HR systems, and SaaS platforms, leading to an efficient attack tour.
Reported by Eric Olmstead
Research & Knowledge
LevelBlue researchers Karl Sigler, Nolen J., and Nikita Kazymirskyi are unpacking the technical mechanics behind the campaign targeting internet-exposed PLCs across water utilities.
Reported by LevelBlue
Research & Knowledge
LevelBlue SpiderLabs team breaks down the attack and provides practical YARA rules and SentinelOne searches to hunt for Microsoft Defender placing malicious files into trusted Windows system folders
Reported by Eric Olmstead
Products & Services
LevelBlue launched a new Sydney SOC combining local analysts, onshore escalation, global threat intelligence, and around-the-clock monitoring to support SOCI compliance and cyber resilience.
Reported by Todd Waskelis
Partnerships
LevelBlue is teaming up with Resilience to walk through a framework for calculating business interruption exposure, prioritizing incident response investments, and communicating cyber decisions in language every finance team can understand.
Reported by LevelBlue
Research & Knowledge
LevelBlue published a research piece by SpiderLabs detailing the design of Raven, an offensive security tool that uses three safety gates before destructive actions can execute.
Reported by Paul Roberts
Presence & Recognition
LevelBlue is attending the Gartner Security & Risk Management Summit in London with a strong lineup including AI-powered MDR/MXDR, managed network and cloud security, and incident response expertise.
Reported by Paul Roberts
Presence & Recognition
LevelBlue is celebrating Women in Cybersecurity Day on Women in Cybersecurity Day
Reported by LevelBlue
Research & Knowledge
LevelBlue published research showing that threat actors are using fake application updates to install unauthorized ScreenConnect clients instead of traditional phishing pages.
Reported by Eric Olmstead
People
LevelBlue appointed Ritika Dey as Managing Security Consultant.
Reported by Ritika Dey
Presence & Recognition
LevelBlue is recognized as a Major Player in the space by IDC
Reported by LevelBlue
Partnerships
LevelBlue and SentinelOne Wayfinder Frontier AI Services formed a partnership to accelerate vulnerability discovery and prioritize remediation.
Reported by Eric Olmstead
Research & Knowledge
LevelBlue published findings from ongoing RAVEN research showing that some Elasticsearch DoS techniques barely depend on data volume, with a 60-second test creating hours of recovery work regardless of document count.
Reported by Eric Olmstead