LawlietLAWLIET
Book a demo

Platform modules

Every module writes to the same evidence store, review queue and audit trail. Which modules are available depends on your suite.

Continuous compliance

Scans run on a schedule or on demand, across the whole estate, one host or a chosen set. Each score decomposes into per-control, per-host results with timestamps. A host that could not be reached counts as not assessed, so a partial scan reports a lower score rather than a perfect one.

Between scans, drift detection compares each result with the last one and records every control that changed. Drift that needs attention goes to the review queue.

Frameworks and benchmarks

GroupContent
StandardsCIS Controls v8, NIST SP 800-53 Rev. 5, NIST CSF, ISO/IEC 27001:2022, ISO/IEC 27701, PCI DSS v4.0, SOC 2 Type II, HIPAA Security Rule, GDPR technical controls, CMMC 2.0
Linux benchmarksCIS Linux, CIS RHEL and CentOS, CIS Debian and Ubuntu, CIS Arch Linux, DISA STIG Linux
Windows benchmarksCIS Windows 10 and 11, CIS Windows Server 2019 and 2022, DISA STIG Windows Server
macOS benchmarksCIS macOS

Automated checks for the standards run on Linux hosts.

Scheduled reports

Dated reports per framework over a period. A framework that was not scanned in that period is shown as not assessed, never left out.

Evidence bundles

Collect evidence across scans, drift, remediation and attestations into one bundle, and export it as JSON or a standalone HTML report. Secrets are redacted, and the SHA-256 of every referenced artefact is recorded alongside it.

Hardening

Remediation runs on the host through the agent, with approval before and rollback after. A control is marked compliant only when a re-check passes, never because a fix was attempted. Changes to critical assets need extra approval.

SIEM

Receives syslog (RFC 5424 and RFC 3164), CEF, LEEF and JSON. Detection rules come in five kinds: threshold, sequence, first seen, went quiet and spike. Events can be forwarded to your own SIEM; see forwarding.

Log collection and detection are in the Operate and Complete suites. Forwarding to an external SIEM is in every suite.

File integrity monitoring

Agents watch the paths you choose and report every addition, change and deletion with the old and new hash, in a hash-chained history per file. Events link to the compliance controls they affect and have an analyst workflow.

Data loss prevention

Detects credentials and personal data, blocks inline where content is inspected, and stores findings redacted. Incidents move through an analyst workflow from new to closed.

Active defence

Quarantine a file, kill a process, block an IP, isolate a host, disable a user or reset credentials, on Linux, Windows and macOS. Each action is a signed command. The console shows it as dispatched until the agent confirms it ran.

Digital forensics

Cases with chain of custody. Uploaded artefacts get YARA scanning and static analysis: strings, entropy and extraction of IP addresses, domains, URLs, email addresses and file hashes.

Network discovery

Twelve techniques: ARP, routing table, ICMP, TCP connect, service banners, TLS certificates, reverse DNS, mDNS, SSDP, NetBIOS, SNMP system description and MAC vendor lookup. Switches, printers and appliances are identified rather than listed as unknown.

Firewall governance

Full rule parsing for Cisco ASA and iptables, and policy parsing for FortiGate. Rule sets are checked for any-any rules, duplicates and shadowed rules. Configurations can be fetched over SSH from ASA, FortiGate, PAN-OS and Junos.

Review queue

One deduplicated queue of what needs a decision, across compliance, FIM, DLP, forensics, hardening, firewall and intelligence. Every decision is recorded. Nothing is remediated automatically.

Asset intelligence and audit trail

An inventory of every managed host with its criticality, which feeds risk scoring and gates critical hardening. The audit trail records every action, who took it and who approved it, and can be filtered and exported.