Mandiant describes the unit as providing rapid evidence discovery. The product consists of three components: agent software that goes on a computer of interest; a controller that gathers and analyzes data provided by the agents; and a console. The red box, which costs upwards of $80,000, is aimed at large companies as one part of a comprehensive security infrastructure.
Intelligent Response is not an intrusion detection/prevention device. It comes into play after those devices detect suspicious activity, collecting and analyzing data and spitting out reports in the process.
Mandiant officials present themselves as crime fighters. "We find evil," they say. Just don't ask about specific examples. Their best customers are their most embarrassed customers.