Platform modules
Every module writes to the same evidence store, review queue and audit trail. Which modules are available depends on your suite.
Continuous compliance
Scans run on a schedule or on demand, across the whole estate, one host or a chosen set. Each score decomposes into per-control, per-host results with timestamps. A host that could not be reached counts as not assessed, so a partial scan reports a lower score rather than a perfect one.
Between scans, drift detection compares each result with the last one and records every control that changed. Drift that needs attention goes to the review queue.
Frameworks and benchmarks
| Group | Content |
|---|---|
| Standards | CIS Controls v8, NIST SP 800-53 Rev. 5, NIST CSF, ISO/IEC 27001:2022, ISO/IEC 27701, PCI DSS v4.0, SOC 2 Type II, HIPAA Security Rule, GDPR technical controls, CMMC 2.0 |
| Linux benchmarks | CIS Linux, CIS RHEL and CentOS, CIS Debian and Ubuntu, CIS Arch Linux, DISA STIG Linux |
| Windows benchmarks | CIS Windows 10 and 11, CIS Windows Server 2019 and 2022, DISA STIG Windows Server |
| macOS benchmarks | CIS macOS |
Automated checks for the standards run on Linux hosts.
Scheduled reports
Dated reports per framework over a period. A framework that was not scanned in that period is shown as not assessed, never left out.
Evidence bundles
Collect evidence across scans, drift, remediation and attestations into one bundle, and export it as JSON or a standalone HTML report. Secrets are redacted, and the SHA-256 of every referenced artefact is recorded alongside it.
Hardening
Remediation runs on the host through the agent, with approval before and rollback after. A control is marked compliant only when a re-check passes, never because a fix was attempted. Changes to critical assets need extra approval.
SIEM
Receives syslog (RFC 5424 and RFC 3164), CEF, LEEF and JSON. Detection rules come in five kinds: threshold, sequence, first seen, went quiet and spike. Events can be forwarded to your own SIEM; see forwarding.
Log collection and detection are in the Operate and Complete suites. Forwarding to an external SIEM is in every suite.
File integrity monitoring
Agents watch the paths you choose and report every addition, change and deletion with the old and new hash, in a hash-chained history per file. Events link to the compliance controls they affect and have an analyst workflow.
Data loss prevention
Detects credentials and personal data, blocks inline where content is inspected, and stores findings redacted. Incidents move through an analyst workflow from new to closed.
Active defence
Quarantine a file, kill a process, block an IP, isolate a host, disable a user or reset credentials, on Linux, Windows and macOS. Each action is a signed command. The console shows it as dispatched until the agent confirms it ran.
Digital forensics
Cases with chain of custody. Uploaded artefacts get YARA scanning and static analysis: strings, entropy and extraction of IP addresses, domains, URLs, email addresses and file hashes.
Network discovery
Twelve techniques: ARP, routing table, ICMP, TCP connect, service banners, TLS certificates, reverse DNS, mDNS, SSDP, NetBIOS, SNMP system description and MAC vendor lookup. Switches, printers and appliances are identified rather than listed as unknown.
Firewall governance
Full rule parsing for Cisco ASA and iptables, and policy parsing for FortiGate. Rule sets are checked for any-any rules, duplicates and shadowed rules. Configurations can be fetched over SSH from ASA, FortiGate, PAN-OS and Junos.
Review queue
One deduplicated queue of what needs a decision, across compliance, FIM, DLP, forensics, hardening, firewall and intelligence. Every decision is recorded. Nothing is remediated automatically.
Asset intelligence and audit trail
An inventory of every managed host with its criticality, which feeds risk scoring and gates critical hardening. The audit trail records every action, who took it and who approved it, and can be filtered and exported.

