Aegis Ops Console
Live
Online
Aria Aegis — One AI. Eight Shields.
Unified cyber-defense OS · — live endpoints · SOC · Comply · Mail · Recon · Identity · Underwrite · Synthetic (preview — not deployed) · EDR (Garuda) · SIEM (Indra)
GET read-only POST action 200 success 4xx/5xx error
Shield: SOC
open investigations
Shield: Mail
messages analyzed
Shield: Recon
targets monitored
Shield: Comply
controls tracked
Shield: Identity
open takedowns
Shield: Underwrite
posture score
Shield: Synthetic NOT DEPLOYED
no endpoint — click to open →
Shield: EDR (Garuda)
agents online · open →
Shield: SIEM (Indra)
events ingested (30d) · open →
System Overview
Aggregated state across the six shields GET /aegis/overview actually measures — EDR, SIEM, Correlator, Comply, Mail, DevSec — not the eight named in the header above. GET /aegis/health reports which routers are mounted in this build; it is not a health probe and carries no breaker state.
Click "Refresh" to load live state…
SOC · Ingest Alert POST
/aegis/soc/ingest — submit a custom security alert to the SOC shield.
Output appears here…
SOC · Wazuh Webhook POST
/aegis/soc/ingest/wazuh — endpoint Wazuh posts to when an alert fires.
SOC · Decide on Action POST
/aegis/soc/actions/{id}/decide — approve or reject a proposed containment.
Mail · Analyze Message POST
/aegis/mail/analyze — BEC + phishing + link-scan + sender-reputation in one call.
Mail · Raw RFC-822 Ingest POST
/aegis/mail/ingest/raw — paste a full email (with headers) for analysis.
Mail · Webhook Status GET
Check Gmail Pub/Sub + Microsoft Graph webhook health.
Recon · Add Target POST
/aegis/recon/targets — register a domain/IP/CIDR for continuous monitoring.
Recon · Scan + DNS Audit POST
Surface scan + subdomain-takeover detection + SPF/DMARC check.
Recon · Exploit-Chain Planner POST
Defensive only — proposes attack path + remediation steps.
Recon · Scheduler POST
Run weekly scans automatically across all registered targets.
Recon · Ticket Generator POST
/aegis/recon/tickets/generate — export finding as Jira / Linear / GitHub / Markdown.
Comply · Evidence Locker GET
/aegis/comply/evidence — auto-collected compliance evidence (SOC2 / ISO / DPDP).
Underwrite · Grant Consent POST
Customer opts in to share posture data with their cyber-insurance carrier.
Underwrite · Posture & Premium Delta GET
NOT DEPLOYEDPREVIEW — NOT DEPLOYED. The /aegis/synthetic/* endpoints these buttons call are not deployed; every one returns 404. Nothing below is measured.
Synthetic Shield · Overview404
Deepfake & synthetic-media defense for Indian BFSI. Three modules: V-CIP injection detection, Synthetic Red-Team-as-a-Service, Synthetic Exposure Score (Underwrite extension). Founding-customer pilots open Q3 2026 — see /synthetic for full spec or /red-team for the service offering.
No synthetic-shield backend exists — this button returns HTTP 404.
Module 01 · V-CIP Injection Detection POST404
/aegis/synthetic/vcip/scan — frame-level synthetic-media gate that sits in front of HyperVerge / IDfy / Signzy / in-house V-CIP. Catches injection attacks (virtual cam, replay, frame-stitch) and generated faces in <60 ms p95.
Route not deployed — this button returns HTTP 404.
Module 02 · Synthetic Red Team Engagement GET404
/aegis/synthetic/red-team/engagements — quarterly Hinglish deepfake red-team drills. List active engagements, view kill-chain progress, fetch CERT-In drill log.
Module 03 · Synthetic Exposure Score GET404
/aegis/synthetic/exposure — bolt-on for the Underwrite shield. Computes synthetic-exposure sub-score (public exec footage volume, voiceprint availability, V-CIP coverage, regional voice-clone risk) and ships HMAC-signed monthly delta to your insurer.
Identity · Register Brand POST
/aegis/identity/brands — tell Aria which apex domain, social handles, developer accounts, and ad pages are legitimately yours. Every other match becomes a candidate impersonation.
Registered brands appear here.
Identity · Lookalike Hunt POST
/aegis/identity/lookalike/hunt — dnstwist-style permutations + live DNS + Certificate Transparency logs. Returns only domains that actually resolve or have been logged.
Hit "Run Hunt" to scan for lookalikes…
Identity · Social Search POST
/aegis/identity/social/search — Twitter/X + GitHub + LinkedIn (partner API).
Identity · App Stores POST
/aegis/identity/apps/search — Apple App Store + Google Play.
Identity · Ad Libraries POST
/aegis/identity/ads/search — Meta Ad Library Graph API + Google Ads Transparency Center. Needs META_ACCESS_TOKEN env var on the server for Meta.
Identity · Takedown Queue GET
/aegis/identity/takedown/cases — open cases, RDAP-resolved abuse contacts, pre-filled notices.
Identity · Open Takedown Manually POST
/aegis/identity/takedown/open — file a case when you spot something outside Aria's automated hunts.
SAMPLE DATAPREVIEW — NOT CONNECTED. This tab has no live data source. Every number, row and chart below is fixed sample content shipped with the console, not your organisation's data.
🔐 Passkey / FIDO2 Enrollment Rollout LAYER 1SAMPLE
Phishing-resistant MFA is the single largest-leverage identity control. Target: 95% enrollment in 90 days. Every unenrolled user is a password-phishable account. This panel is the board-metric source of truth.
Enrolled (FIDO2)
of users
Coverage %
target 95% · gap
Phishable-MFA users
SMS / TOTP only
No-MFA users
password only · P0
Admins enrolled
tier-0 target 100%
90-day velocity
users/week
Org-wide enrollment progress ETA —
0%Target 95%100%
Coverage by departmentSAMPLE
Any department below 80% is the next target for the rollout team.
Unenrolled users — ship the nudgesSAMPLE
Worst-first. Admins at the top. Bulk actions drive the 90-day curve.
DISABLED — not connected. These controls cannot send, change or revoke anything; nothing leaves this page. Exports are fixed sample data.
UserDepartmentRoleCurrent MFALast loginRisk
SAMPLE DATAPREVIEW — NOT CONNECTED. This tab has no live data source. Every number, row and chart below is fixed sample content shipped with the console, not your organisation's data.
🎯 Conditional Access Posture LAYER 1SAMPLE
Device posture × risk × location × user × app. Every cell should be covered by at least one block-on-noncompliant policy. The grid below is a coverage map — red cells are gaps an attacker will find.
Policies
enforced · report-only
Coverage score
target ≥ 85%
Critical gaps
cells with no block policy
Overrides (7d)
manual bypass / break-glass
Risky sign-ins (24h)
blocked / MFA-challenged
Legacy-auth attempts
should be 0
Coverage matrix — user-risk × sign-in-risk × device-stateSAMPLE
Each cell: which enforcement fires. Green = block or require FIDO2. Amber = MFA only. Red = no policy.
Conditional Access policiesSAMPLE
Git-backed policy-as-code. Report-only mode is for staging; nothing persists there forever.
DISABLED — not connected. These controls cannot send, change or revoke anything; nothing leaves this page. Exports are fixed sample data.
PolicyScopeConditionsControlStateUsersLast-fired
Override / break-glass log (last 7 days)SAMPLE
Every bypass is a human promise — documented, timeboxed, reviewed.
WhenUserPolicy bypassedReasonApproverExpires
SAMPLE DATAPREVIEW — NOT CONNECTED. This tab has no live data source. Every number, row and chart below is fixed sample content shipped with the console, not your organisation's data.
🕵 ITDR — AiTM / Session-Cookie Replay LAYER 1 · CRITSAMPLE
Evilginx / Tycoon / Caffeine steal the post-MFA session cookie. Password + MFA are already done — the attacker replays the cookie from a different browser and inherits your session. We correlate user-agent, IP-ASN, cookie-age, concurrent session, MFA-to-use delta and kill in < 90 s.
Sessions monitored
last 24h
Flagged (24h)
score ≥ 50
Auto-killed
score ≥ 80 · no human
Avg time-to-kill
detection → session revoked
Open investigations
analyst touch required
False-positive rate
rolling 7d · target < 3%
Detection signals — weighted scoringSAMPLE
Score ≥ 80 = auto-kill + revoke refresh token. 50-79 = challenge re-auth. 30-49 = monitor + enrich.
Suspicious sessions — live queueSAMPLE
Sorted by score. Green = auto-killed. Amber = awaiting decision. Click Kill to revoke + force re-auth.
DISABLED — not connected. These controls cannot send, change or revoke anything; nothing leaves this page. Exports are fixed sample data.
ScoreUserSignal summaryOriginCookie ageStateAction
💥 MFA-Fatigue / Push-Bombing Detector T023SAMPLE
Attacker has the password. Sprays push notifications until the tired user taps "Approve". Threshold: > 5 push-denies in 60s = auto-lock + force FIDO2 re-enroll. No more push once FIDO2 is enrolled.
Burst attempts (24h)
≥3 denies in 60s
Auto-locked accounts
≥5 denies / 60s
Number-matching on
of push-MFA tenants
Approve-after-deny rate
highest-risk signal
UserWindowDeniesSource ASNsOutcomeAction
✈ Impossible-Travel Detector T024SAMPLE
Same user authenticates from two cities faster than a commercial flight. Haversine-distance / min-flight-time check. Session-kill + analyst notify + alert in SOAR queue.
Events (24h)
scored
Auto-killed
velocity > 900 km/h
VPN / proxy excluded
enterprise-VPN allow-list
Avg distance flagged
km between cities
UserFromToΔtDistanceVelocityAction
SAMPLE DATAPREVIEW — NOT CONNECTED. This tab has no live data source. Every number, row and chart below is fixed sample content shipped with the console, not your organisation's data.
🧹 Identity Hygiene LAYER 1SAMPLE
The unglamorous controls. Legacy-auth blocked. Long-lived tokens rotated. OAuth consents reviewed. This is where most breaches actually start.
🔒 Legacy-Auth Kill-Switch T025 · CRITSAMPLE
Basic-auth / IMAP / POP3 / SMTP-AUTH / older EAS = MFA bypass. Must be disabled. Exceptions get a ticket, an owner, and an expiry.
Legacy-auth users
still active last 30d
Protocols in use
IMAP / POP / SMTP-AUTH / EWS
Open exceptions
with expiry
Denied attempts (24h)
block rule working
DISABLED — not connected. These controls cannot send, change or revoke anything; nothing leaves this page. Exports are fixed sample data.
UserProtocolClientLast-seenExceptionAction
🔑 Long-Lived Token Inventory T026SAMPLE
OAuth refresh tokens, PATs, service-account keys, CI secrets. Anything older than 90 days is a time-bomb. Rotate to short-lived OIDC wherever possible.
Long-lived tokens
> 90 days old
Critical
> 1 year · admin scope
Rotated (30d)
moved to OIDC / short-lived
Orphan (no owner)
revoke candidate
DISABLED — not connected. These controls cannot send, change or revoke anything; nothing leaves this page. Exports are fixed sample data.
TokenKindOwnerScopeAgeRisk
🤝 OAuth Consent Review (SSPM base) T027SAMPLE
Third-party apps users granted to their workspace — ranked by scope + last-used. Unused for 30d → auto-expire. New high-scope consent → review workflow.
Granted apps
across M365 + Google
High-scope
mail-read · drive-full
Unused 30d+
auto-expire candidate
New last 7d
awaiting review
AppPublisherScopesUsersLast usedRiskAction
📜 Identity Action Log AUDIT TRAIL
Durable record of every workflow action fired from the Identity tabs — passkey nudges, policy promotions, session kills, token rotations, dormant sweeps. Persisted server-side; survives Cloud Run restarts. Filter by type to triage what just happened.
WhenActionStatusAffectedAction IDReason
SAMPLE DATAPREVIEW — NOT CONNECTED. This tab has no live data source. Every number, row and chart below is fixed sample content shipped with the console, not your organisation's data.
💾 Immutable Backup & Recovery LAYER 5 · CRITSAMPLE
Before ransomware encrypts, it deletes your backups. If production identity can delete the backup, you don't have a backup. You have a snapshot. Fix this first — nothing else matters if we can't restore.
🔐 Object-Lock (WORM) Coverage T170SAMPLE
Every backup bucket must have Object-Lock / GCS-retention / Azure-immutability enabled with MFA-delete. Stored in a separate cloud account from production.
Backup targets
across all clouds
Immutable
Object-Lock on
MFA-delete
required for deletion
Gaps
mutable / no-MFA
Isolated account
separate billing
Air-gapped (tier-0)
offline weekly
TargetCloudSizeObject-LockMFA-deleteIsolated acctRetentionStatus
🧪 Restore-Test Tracker T173SAMPLE
A backup you have never restored is fiction. Monthly random-sample restore test per tier; measure wall-clock time-to-restore. Board metric.
Tests this month
completed
Success rate
rolling 90 days
Avg restore time
tier-0 + tier-1
Overdue
no test in 30d
DISABLED — not connected. These controls cannot send, change or revoke anything; nothing leaves this page. Exports are fixed sample data.
WhenTargetTierBytesDurationIntegrityVerdict
SAMPLE DATAPREVIEW — NOT CONNECTED. This tab has no live data source. Every number, row and chart below is fixed sample content shipped with the console, not your organisation's data.
🗝 IAM Ops LAYER 1SAMPLE
PAM, IGA, access reviews, dormant sweep, admin segregation, and honey-accounts — the unsexy identity plumbing that moves breach probability the most.
🧑‍✈️ PAM / JIT Admin Workflow T028SAMPLE
Time-boxed elevation with ticket + approver. Full keystroke recording. Auto-revoke on expiry. Tier-0 only.
Active JIT sessions
avg TTL 47m
Pending approvals
SLA 15m
Recorded today
sessions w/ keystroke log
Standing admins
to be eliminated
UserScopeTicketApproverGrantedExpiresRecord
🎣 Honey-Account Tripwires T036SAMPLE
Plausible admin accounts, never used. Any auth attempt = P0 incident. Zero false-positive detect.
Deployed
canary identities
Tripped (30d)
P0 incidents
False positives
0
by design
Last rotation
stay fresh
Canary accountTenantPrivilege lureLast tripState
🔄 IGA — Joiner / Mover / Leaver T029SAMPLE
HRIS-driven lifecycle. Birthright roles. On-move entitlement diff. Termination SLA < 15 min.
Events (7d)
J · M · L
Termination p95
HR signal → revoked
Stuck in queue
> 15m
Access diff on move
over-permissioned
WhenEventUserChangeLatencyState
📋 Quarterly Access Review Campaigns T030SAMPLE
Managers attest entitlements per quarter. Auto-revoke non-attested. Evidence to compliance.
Campaign Q2-26
attested
Revocations
stale entitlement removed
Overdue managers
SLA 14d
Evidence bundle
auto-packaged
ManagerReportsEntitlementsAttestedRevokedDue
💤 Dormant / Orphan Account Sweep T031SAMPLE
No login > 30d or no owner. Disable → delete after grace. Includes service accounts.
Dormant (>30d)
no login
Orphan (no owner)
service accts
Scheduled-disable
in next 7d
Reactivations (30d)
FP control
DISABLED — not connected. These controls cannot send, change or revoke anything; nothing leaves this page. Exports are fixed sample data.
AccountKindOwnerLast loginAction
🧯 Break-Glass Vault + 2-Person Rule T037SAMPLE
Offline-printed creds in a sealed envelope. Every retrieval alerts CEO + board SMS. Quarterly test-retrieval proves the process still works.
BG accounts
2
Entra GA · AWS root
Sealed in safe
dual-custody · tamper-evident
Last test-retrieval
62d ago
quarterly drill
Unauthorised opens
0
all-time
AccountTenantDual custodyEnvelope sealAlert on use
breakglass-global-adminEntra IDCISO + CFOintact · serial 042✓ CEO + board SMS
breakglass-aws-rootAWS Org rootCISO + CTOintact · serial 043✓ CEO + board SMS
🤖 Non-Human Identity (NHI) Inventory T038SAMPLE
Service accounts · workload identities · bot accounts · CI runners · LLM agents. Every NHI has an owner + rotation SLA + scope cap.
NHIs in inventory
842
all tenants
With owner tag
98%
14 orphan · triage
Workload-identity (OIDC)
78%
short-lived preferred
Over-scoped (wildcard)
12
tightening
NHIKindOwnerScopeRotationState
svc-ci-deployGitHub Actions · OIDCplatformdeploy:prod · scopedephemeralOK
workload-api-roleAWS workload-identityapi-engs3:GetObject · one bucketephemeralOK
sa-billing-bqGCP service-accountdata-engbigquery.dataOwner (wildcard)180dSCOPE TIGHTEN
bot-slack-opsSlack botsrechannels:read · chat:writeOAuthOK
agent-aria-triageLLM agentai-platformdata_lake.read (ephemeral)per-task · 10mOK
svc-legacy-etlSA-key · AWSorphans3:* (wildcard)842dORPHAN · REVOKE
⚡ Session-Hijack Revocation — One-Click Kill T039SAMPLE
Analyst picks user → sees active sessions → revokes + rotates refresh + forces re-auth with FIDO2. Primary response action for AiTM / session-theft / MFA-fatigue outcomes.
Kills (30d)
47
analyst + auto
Mean time-to-kill
38s
click → revoked
Reversed (false-pos)
3
user re-auth restored
IdPs covered
4 / 4
Okta · Entra · Google · AWS
StepActionSystemRollback
1Find user → list active sessionsidentity graphn/a (read-only)
2Kill selected session · invalidate access tokenOkta · Entra · Googleuser re-auth restores access
3Rotate refresh token · revoke OAuth grantsIdPre-grant via new session
4Force FIDO2 on next login (CAP flag)Conditional Accessflag clears when attested
5Log to audit (T436) + attach to incidentsecops graph
🪜 Admin-Tier Segregation T032SAMPLE
Tier-0 / 1 / 2 separate accounts. admin- prefix. No tier-0 login from non-PAW.
Tier-0 accts
target < 10
Prefix compliance
admin-* naming
PAW login share
of tier-0 sessions
Cross-tier violations
same-acct daily + admin
TierAccountsPrefix OKPAW-onlyViolations 7d
SAMPLE DATAPREVIEW — NOT CONNECTED. This tab has no live data source. Every number, row and chart below is fixed sample content shipped with the console, not your organisation's data.
🏰 Active Directory / Entra ID Posture LAYER 1SAMPLE
Where attackers build their campaign. Kerberoast, ADCS misconfigs, and attack-path graph. Shrink the graph monthly or lose ground.
🎟 Kerberoast / AS-REP-roast Detector T033SAMPLE
TGS-REQ to odd SPNs + AS-REP with no pre-auth. Honey-SPN seeded for zero-FP alerting.
Roastable SPNs
with weak RC4
AS-REP-roastable
DONT_REQ_PREAUTH
TGS bursts (24h)
anomaly
Honey-SPN hits
P0 if non-zero
WhenDetectorTarget SPN / PrincipalSourceSeverity
📜 ADCS Misconfig Scanner (ESC1-15) T034SAMPLE
Certipy-style weekly scan. Flag templates allowing subject supply + client-auth EKU.
Templates scanned
all CAs
Exploitable
ESC1/4/6/9
Mitigated (30d)
closed
Signed forward
owner + deadline
TemplateCAFindingESC classEnrolleesStatus
🗺 Attack-Path Graph (BloodHound-style) T035SAMPLE
Shortest paths to Domain Admin / Global Admin. Shrink count + avg length month-over-month.
Paths to DA/GA
from any user
Shortest
hops
Avg length
↓ from last month
Top chokepoint
remove = kill N paths
Start nodeEnd nodeHopsPathAction
SAMPLE DATAPREVIEW — NOT CONNECTED. This tab has no live data source. Every number, row and chart below is fixed sample content shipped with the console, not your organisation's data.
🖥 Endpoint Posture LAYER 2SAMPLE
EDR coverage, ASR enforcement, LSASS/Credential Guard. These three controls kill 80% of commodity malware.
🛰 EDR Coverage & Drift T070SAMPLE
Target >99.5% coverage across Win / Mac / Linux. Alert on >4h offline. Reconcile to CMDB + DHCP.
Coverage
target > 99.5%
Offline > 4h
hosts stale
CMDB drift
in CMDB, no agent
Unknown hosts
agent, no CMDB
OSTotalWith EDRCoverageOffline > 4hStatus
🛡 ASR Rules Enforcement T071SAMPLE
Block Office child-process · LSASS cred-steal · webmail macro · obfuscated scripts · USB exec. Audit-then-enforce.
Rules enforced
of 17
Audit-mode
ready to promote
Blocks (7d)
rule-hit events
Exceptions
with expiry
RuleIDModeBlocks 7dExceptionsAction
📄 Macro-from-Internet Hard-Block T072SAMPLE
Office macros from MoTW-tagged files are blocked by GPO/Intune. Named exceptions carry an owner + expiry. Monthly review.
Policy status
ENFORCED
all tenants
Open exceptions
with expiry
Blocks (7d)
macro exec denied
Expired exceptions
must be closed
ExceptionOwnerReasonScopeExpiresState
👑 Local-Admin Removal Progress T074SAMPLE
LAPS / Intune-driven. Elevation on-demand via ticket. Target: 95%+ users without permanent local admin.
Users w/o local admin
target ≥ 95%
LAPS-managed hosts
unique random pw
Legacy admins
standing elevation
JIT elevations (7d)
time-boxed
OSHostsStanding-adminLAPSJIT-onlyStatus
🧱 WDAC / AppLocker Rollout T075SAMPLE
Start audit-mode, weekly diff, move tier-0 hosts to enforce first. Block everything not signed or published.
In enforce
of target fleet
In audit
ready to promote
Unsigned events (7d)
blocked or audited
Policies signed
tamper-resistant
CohortPolicy versionHostsModeViolations 7dNext
🔌 USB Device-Control Allow-List T076SAMPLE
Mass-storage default-block. Ticketed exceptions by VID/PID. Alert on BadUSB HID typing-speed patterns.
Allow-list entries
VID:PID pairs
Mass-storage blocks
this week
BadUSB HID alerts
rapid-type pattern
Pending exceptions
ticketed
WhenHostUserDeviceVID:PIDVerdict
🧨 BYOVD — Vulnerable-Driver Block-List T078SAMPLE
Microsoft vulnerable-driver blocklist enforced. Any unsigned kernel-load + known-bad hash alerts loudly.
Blocklist version
auto-updated
Load attempts blocked
last 30d
Unsigned load alerts
P0 triage
Allow-list drivers
business-critical
WhenHostDriverSHA-256ClassificationVerdict
🍏 macOS Fleet Hardening T081SAMPLE
TCC · SIP · Gatekeeper · FileVault · XProtect. Jamf/MDM profile diff. 100% FileVault key escrow.
FileVault on
of fleet
Key escrow
MDM-recoverable
SIP enabled
system integrity
Profile drift
from MDM baseline
macOSHostsFileVaultSIPGatekeeperDrift
🐧 Linux Server Coverage (osquery + auditd) T082SAMPLE
Wazuh/Falco runtime. Cron/systemd-timer enumeration diff. SUID/SUID-over-time drift detect.
osquery agents
of linux fleet
auditd baseline
loaded rules
SUID drift (30d)
new SUID binaries
Cron/timer diff
unsigned added
DistroHostsosqueryauditdSUID driftState
🧩 Browser Extension Allow-List T083SAMPLE
Chrome Enterprise / Edge policy. Block install from unmanaged stores. Monthly review of installed extensions.
Allow-listed exts
approved
Blocked installs (7d)
attempts denied
High-risk perms
tab-read · all-URLs
Review due
this cycle
ExtensionPublisherInstall basePermissionsRiskState
🔏 LSASS-Protection & Credential Guard T073SAMPLE
RunAsPPL + VBS + HVCI. Mimikatz becomes a doorstop. Reconcile incompatibilities (USB tokens, VPN drivers).
RunAsPPL
of Win hosts
VBS + HVCI
virtualization-based
Credential Guard
full deployed
Incompatible
remediation backlog
BuildHostsRunAsPPLVBSHVCICred GuardBlocker
SAMPLE DATAPREVIEW — NOT CONNECTED. This tab has no live data source. Every number, row and chart below is fixed sample content shipped with the console, not your organisation's data.
🛰 SSPM — SaaS Security Posture LAYER 1SAMPLE
Our real perimeter lives in 30 vendor consoles. CIS / Secure Score equivalent pulled nightly from every critical SaaS. Drift alerts. Evidence auto-packaged to compliance.
Tenants monitored
4
M365 · Google · GitHub · Okta
Critical findings
open
Score trend (7d)
↑ 4.2
avg across tenants
Auto-remediated (30d)
drift corrected
🪟 Microsoft 365 Posture (T050)SAMPLE
CIS Microsoft 365 benchmark + Secure Score. Daily pull. Diff. Alert on regression. Evidence bundled to compliance.html.
Secure Score
of max
CIS pass-rate
L1 + L2
Regressions (7d)
blocked drift
Super-admins
target ≤ 5
ControlStatusScoreDrift (7d)Action
🔍 Google Workspace Posture (T051)SAMPLE
2SV/FIDO coverage · less-secure-app · external-share defaults · super-admin count · Chrome policy sync.
2SV coverage
enforced
FIDO required
org-wide
External-share default
off
warn-on-share
Less-secure-app
blocked
enforced
ControlStatusCoverageDriftAction
🐙 GitHub Org Posture (T052)SAMPLE
SSO required · branch protection · signed commits · secret-scan push-protection · Dependabot. Every repo reconciled nightly.
Repos enforced
branch-protection
Signed commits
of repos
Push-protection
ON
org-wide
Outside collabs
review quarterly
RepoSSOBranch protSignedPush-protOutsideState
🔑 Okta / Entra ID Tenant Hardening (T053)SAMPLE
Legacy-auth blocked · conditional-access coverage · break-glass guardrails · social-login exposure.
Legacy auth
blocked
org-wide
CAP coverage
of apps
Break-glass
2
accounts · monitored
Social login
off
not allowed
CheckStatusDetailLast verified
💬 Slack / Teams / Zoom Posture (T054)SAMPLE
Guest-account audit · external-file-share · retention · unmanaged-app install · E2EE availability.
Guest accounts
needs quarterly review
External shares (7d)
auto-logged
Unmanaged apps
approve-list pending
E2EE available
Zoom
enabled for exec calls
PlatformGuestsExt-shareRetentionAppsStatus
🎯 Salesforce / HubSpot / CRM Posture (T055)SAMPLE
API-user scopes · session timeout · IP allow-list · export rate-limit · profile-clone alerts.
API users
with scoped roles
Session timeout
2h
auto-lock
Mass-export alerts
rate-limit triggered
Profile changes
privileged-change log
CRMAPI usersIP allow-listSessionMass-exportStatus
🔀 OAuth App Marketplace Drift (T056)SAMPLE
Any new high-scope app consented in last 24 h triggers a review workflow. Paired with the Hygiene pane's consent review.
New grants (24h)
queued for review
High-scope blocked
auto-deny policy
Pending approval
owner waiting
Revoked on review
last 30d
AppTenantScopesGranted byWhenState
👻 Shadow-SaaS Discovery (T057)SAMPLE
Derived from SSO + DNS + expense data. Identifies unsanctioned apps + owners. Classifies + gates to approved-vendor list.
Shadow apps (30d)
discovered
Onboarded
moved to approved
Blocked
DLP + DNS
Signal sources
3
SSO · DNS · expense
AppSourceUsersData classVerdict
🕸 SaaS-to-SaaS Integration Map (T058)SAMPLE
Graph of Zapier / Make / webhooks / API-keys between apps. Flags transitive-admin chains (e.g. low-priv Zapier with high-priv creds).
Integrations mapped
live connections
Transitive-admin
privilege chains
Stale bots
no run 30d
Long-lived creds
for integrations
SourceDestinationViaScopeRisk
👥 Admin-Count Baseline + Drift (T059)SAMPLE
Target < 5 super-admins per SaaS. Alert on add. Quarterly certify.
SaaS monitored
critical tenants
Over baseline
admin-count drift
Added (30d)
new admins
Certified
this quarter
TenantCurrent adminsTargetAdded 30dStatus
SAMPLE DATAPREVIEW — NOT CONNECTED. This tab has no live data source. Every number, row and chart below is fixed sample content shipped with the console, not your organisation's data.
🌐 Network Detection & Response LAYER 3SAMPLE
East-west & egress visibility. Every block, every beacon, every DNS-tunnel bucket.
Default-deny egress
of subnets
Block-hits (24h)
net-new dests
Beacon candidates
score > 60
Auto-isolated
confirmed
🚪 Egress Allow-List (T100)SAMPLE
Default-deny outbound from workload subnets. Explicit FQDN list. Alert on block-hits to new destinations.
Subnets enforced
workload VPCs
Allow-listed FQDNs
global catalog
Blocks (24h)
denied
New destinations
triage
WhenSourceDestinationProtocolVerdict
🧭 DNS Security — NRD · DGA · DoH bypass (T101)SAMPLE
Umbrella / Quad9 / internal RPZ with block-log. Newly-registered-domain block. DGA scoring. DoH-bypass detect + block.
Queries (24h)
observed
NRD blocked
newly-registered
DGA detections
high-entropy
DoH-bypass blocks
1.1.1.1 · 8.8.8.8 by-IP
QueryTypeSourceClassificationVerdict
📡 Beaconing Detector (T102)SAMPLE
Per-source entropy on inter-request timing. Flags Cobalt / Sliver / Havoc jitter profiles. Filters out CDN + health-checks.
Conversations scored
24h rolling
Flagged beacons
score > 60
Confirmed C2
auto-isolated
FP rate
2.1%
target < 5%
SourceDestinationIntervalJitterScoreVerdict
🪤 DNS Tunneling Detector (T103)SAMPLE
Per-subdomain volume + label entropy + TXT-size + NULL-query anomaly. Per-host baseline.
Suspect zones
above baseline
Confirmed tunnels
blocked
TXT record spikes
investigate
NULL-query volume
baseline 0
HostZoneVolumeEntropyClassification
🕋 ZTNA / SASE Rollout (T104)SAMPLE
App-level access + device-posture gate + per-app policy. Removing network-level VPN where possible.
Apps on ZTNA
of internal apps
Users migrated
off flat VPN
Device-posture gate
ON
compliance required
Legacy VPN users
remaining
AppModePosture gatePolicyUsers
🔓 SSL/TLS Inspection on Corp Egress (T105)SAMPLE
Managed CA + pinned-app exception list. Inline DLP on inspected traffic.
Inspected
of corp egress
Pinned bypasses
allowed by policy
DLP hits (7d)
content-redacted
Cert errors
pre-deploy check
App / domainInspectionReasonDLP (7d)
↔️ East-West Traffic Baseline (T106)SAMPLE
Zeek / Suricata + per-subnet service-pair baseline. Alert on net-new conversation patterns.
Service pairs
baselined
New talk (24h)
investigate
Policy violations
flow to DMZ
Lateral candidates
admin-svc hops
Source subnetDest subnetServiceStateAction
🛡 WAF + Bot-Management Signals (T107)SAMPLE
Top blocked ASNs · rule-hit heatmap · FP queue · ML bot-score.
Blocked (24h)
requests
Top ASN blocked
AS45090
HK datacenter
Rule-hit heat
SQLi
most-triggered
Bot score > 80
auto-challenge
RuleHits (24h)Top ASNCountryAction
💥 DDoS Mitigation Health + Runbook (T108)SAMPLE
Anycast + volumetric + L7. Origin rate-limit. Table-top twice a year.
Provider tier
Enterprise
always-on
Volumetric cap
10 Tbps
network
L7 cap
20 M rps
application
Last table-top
54d ago
due in 128d
EventVectorPeakMitigated inImpact
🎭 Domain-Fronting / CDN-Abuse Detector (T109)SAMPLE
SNI vs Host-header divergence. Classic C2 hiding behind trusted CDNs (Cloudfront/Fastly/Akamai).
SNI mismatches (24h)
scored
Confirmed abuse
blocked
CDN vendors
6
CloudFront · Fastly · Azure · Akamai · Cloudflare · GCDN
False positives
1.6%
rolling 7d
SourceSNIHost headerCDNVerdict
📣 Responder / LLMNR / NTLM-Relay Detect (T110)SAMPLE
mDNS/LLMNR poisoning + WPAD abuse signatures on the LAN. SMB-signing coverage tracked.
LLMNR off
of Win hosts
SMB-signing required
DC policy
WPAD fake-proxy
blocked
static-none entry
Responder signatures
24h · alert
WhenDetectionSource hostTargetVerdict
🚨 Exposed Admin-Port Sweep (T111)SAMPLE
Nightly internet-scan from external vantage for RDP / SSH / WinRM / K8s-API / Docker sockets. Instant Slack + ticket.
Prefixes scanned
18
all announced
Admin ports exposed
P0 if any
Auto-closed (30d)
SG revert
Scan source
external
third-party vantage
WhenIPPortServiceVerdict
☁️ CNAPP — Live CSPM Scan LIVE
Runs a real cloud security posture scan via POST /api/v1/modules/cspm/scan against the provider and credentials below — covering what the old Multi-Cloud Inventory (T150) and CIS/NIST/PCI Benchmark (T151) sample panels used to show, with an actual scan result in place of fixed rows. Credentials are sent once for this scan only; the secret fields are cleared from this page the moment Run Scan is clicked, and nothing is stored or logged.
Nothing here is sample data — a real scan hits your cloud provider with the credentials you enter.
No scan has been run yet.
Risk score
not yet scanned
Checks run
total
Passed / Failed
of evaluated
Errors
could not evaluate
CheckResourceSeverityStatusRemediation
Run a scan to see real findings here.
🔄 Drift vs your last scan LIVE
Compares this scan to the last one your org ran for this provider via POST /api/v1/modules/cspm/drift — a real per-org baseline stored server-side (backend/src/modules/cspm.py::compute_drift), diffed on each resource's pass/fail status, not a simulated timeline. Each click both reads the stored baseline and replaces it with this scan, so the next check compares against this one.
No drift check has been run yet.
New risks
pass → fail
Remediated
fail → pass
Resources added
newly seen
Resources removed
no longer seen
ChangeCheckResourceWasNow
Run a drift check to compare against your last scan.
SAMPLE DATAPREVIEW — NOT CONNECTED. This tab has no live data source. Every number, row and chart below is fixed sample content shipped with the console, not your organisation's data.
🌥 CNAPP — CSPM + CWPP + CIEM LAYER 5SAMPLE
Unified cloud posture: config + workload runtime + identity entitlement. One view, one attack-path engine.
Cloud accounts
AWS + GCP + Azure
Critical findings
open
Auto-remediated (30d)
drift corrected
Attack paths to crown jewels
shrink monthly
🌍 Public Bucket / DB / IP Scanner (T152)SAMPLE
Drift-to-public auto-revert in < 30s. Slack + ticket with owner. Zero tolerance on buckets holding PII.
Public buckets allowed
tagged intentional
Drift events (30d)
auto-reverted
Public DBs
0
target 0
Unexpected public IPs
on workload subnets
WhenResourceChangeOwnerResponse
🕸 CIEM — passRole / AssumeRole Graph (T154)SAMPLE
Transitive permission graph. Find role-to-admin paths. Tighten trust policies.
Roles indexed
across accounts
Paths to admin
from low-priv
Shortest path
hops
PassRole on *
danger
Start roleEnd roleHopsViaAction
📦 CWPP — Container Runtime (Falco / Tetragon) (T155)SAMPLE
Privileged-pod · hostPath · exec-into-pod · secret-read events streamed in real time.
Clusters covered
with runtime agent
Privileged pods
must trend to 0
exec-into-pod (24h)
logged
Secret-read events
baselined
WhenClusterEventActorVerdict
⎈ Kubernetes Hardening (T156)SAMPLE
Pod-Security-Admission restricted · OPA/Kyverno policies · network-policy default-deny · image-admission signed-only.
Namespaces restricted
PSA-restricted
NetworkPolicy default-deny
of clusters
Image signing required
cosign verify
OPA / Kyverno policies
enforced
ClusterPSANet-policyImg-signKyvernoStatus
🔑 KMS / Envelope-Encryption Audit (T157)SAMPLE
All data stores envelope-encrypted at rest with customer-managed keys. Per-key usage + rotation policy tracked.
Stores encrypted (CMK)
of data stores
Keys with rotation
≤ 365d
HSM-backed
tier-0 data
Keys stale
> 1y
Key aliasCloudHSMRotationUsage 30dState
🗺 Attack-Path Engine (T158)SAMPLE
Public-to-crown-jewel paths. Ranked by reachability × impact × exploit-probability. Monthly shrinkage metric.
Paths open
to crown jewels
Closed this month
shrinkage
Avg length
hops
Top chokepoint
fix = kill N paths
StartCrown jewelHopsChainAction
💎 DSPM — Crown-Jewel Data (T159)SAMPLE
Classify PII / PHI / secrets in stores. Alert on large export or cross-region copy.
Stores classified
PII / PHI / secrets
Anomaly exports (24h)
under review
Cross-region copies
policy-aware
Crown-jewel stores
high-value
StoreClassesSizeLast scanMovement alerts (30d)
💸 Billing-Anomaly / Cryptomining Early-Signal (T160)SAMPLE
Per-project $/hr baseline. Spike alert. Auto-freeze path to SOAR.
Spike alerts (30d)
investigated
Confirmed mining
auto-frozen
$ saved (30d)
early-detect
Baseline coverage
of accounts
WhenProjectSpikeClassificationAction
🔄 Terraform Drift Detector (T161)SAMPLE
Nightly plan. Out-of-band changes flagged. Owner notification + revert option.
Workspaces
under drift-watch
Drifted (24h)
manual changes
Auto-reverted
policy-allowed
Tickets opened
owner-acknowledged
WorkspaceResourceDriftActorAction
SAMPLE DATAPREVIEW — NOT CONNECTED. This tab has no live data source. Every number, row and chart below is fixed sample content shipped with the console, not your organisation's data.
🏭 OT / IoT / Mobile FORGOTTEN PLANESAMPLE
Printers, HVAC, PLCs, cameras, phones — every chip is an un-monitored computer. This is where state-level actors live quietly.
Devices discovered
passive fingerprint
Unknown on corp LAN
triage · isolate
Default-pw hits
last sweep
Mobile MTD-enrolled
of corp devices
🔍 IoT / OT Device Inventory — Passive Discovery (T330)SAMPLE
NDR + NAC fingerprinting. Owner + firmware version + default-pw flag per device.
KindCountFirmware avg ageDefault-pwOwner tag
IP cameras21814 mo0facilities
Network printers31222 mo4IT-ops
Badge readers8418 mo0facilities
HVAC / BMS controllers424 yr ⚠2facilities
Conference-room AV3812 mo0IT-ops
PLCs (plant floor)686 yr ⚠0OT-eng
Unknown · un-tagged14
🧱 IoT / OT VLAN Segmentation + Egress-Deny (T331)SAMPLE
Cameras / printers / badge readers can't reach corp servers or the internet. Each device class on its own VLAN with strict allow-list.
VLANClassAllowed egressCorp reachableInternet
VLAN-400 · camerascamerasNVR only
VLAN-410 · printersMFPsprint-server only
VLAN-420 · badgeaccess-controlACS controller
VLAN-430 · HVACBMS controllersBMS head-end✗ (vendor tunnel via jump)
VLAN-500 · OT plantPLCs · HMIsengineering WS only · diode to data-lake
VLAN-900 · guest-wifivisitor devicesInternet only
🔓 Default-Password Scanner (T332)SAMPLE
Nightly auth-attempt with vendor-default credentials across IoT fleet. Force change + track in CMDB. Findings feed owner via ticket.
WhenDeviceModelDefault credsState
2h agoprinter-floor4-hpHP LaserJet M452admin / (blank)OPEN · ticket
2h agoprinter-floor2-xeroxXerox Phaser 6510admin / 1111OPEN
ydayhvac-ctrl-03Honeywell WEB-8000admin / adminOPEN · facilities
ydayhvac-ctrl-07Trane Tracer SCadmin / adminOPEN · facilities
3d agoprinter-old-canonCanon iR-ADV7654321FIXED
5d agoav-room-204Crestron DM-MDadmin / adminFIXED
🪜 OT Jump-Host PAM + Session Recording (T333)SAMPLE
The IT-to-OT bridge is the holy grail — treat it as tier-0. Every session brokered, recorded, keystroke-logged.
Jump hostTierMFARecordingLast session
ot-jump-plant-01Tier-0FIDO2 + PAMkeystroke + video2h ago · ot-eng-3
ot-jump-plant-02Tier-0FIDO2 + PAMkeystroke + video6h ago · ot-eng-7
ot-jump-hmiTier-0FIDO2 + PAMkeystroke + videoyday · vendor-esc (escorted)
ot-jump-scadaTier-0FIDO2 + PAMkeystroke + video3d ago
🧠 OT-Aware NDR — Modbus · DNP3 · BACnet (T334)SAMPLE
Alert on unauthorised write · unusual function-code · new talker on the OT segment.
WhenProtocolSourceTargetFunctionVerdict
12m agoModbus/TCPeng-ws-03PLC-14read (FC3)baseline
1h agoDNP3scada-hmi-01RTU-06direct-operateinvestigate · unusual hour
ydayModbus/TCPunknown · 10.50.4.42PLC-22write (FC6)BLOCKED · new talker
2d agoBACnetbms-head-endHVAC-12set-pointbaseline
🏗 Purdue-Model Segmentation Visualiser (T335)SAMPLE
Levels 0-5 with allowed flows. Diff actual vs policy. Any cross-level flow not in policy is a violation.
LevelZoneAllowed upAllowed downViolations (7d)
L0 physicalsensors / actuatorsto L1 only0
L1 basic-controlPLCs · RTUsto L2 engineeringto L00
L2 area supervisoryHMIs · SCADAto L3 via brokerto L10
L3 site opshistorian · MESto L3.5 DMZ · one-way diodeto L2 via broker0
L3.5 DMZ (ICS-DMZ)data-diode + proxiesto L4 via proxyone-way only0
L4 / L5 enterprisecorp ITinternetto L3.5 DMZ0
📱 MDM + Mobile-Threat-Defense (T336)SAMPLE
Intune / Jamf + Lookout / Zimperium. Attestation required. Smishing-block on corp mail app.
FleetCountMDM-enrolledMTD-activeLast threat (30d)
iOS (corp-owned)1,842100%100%12 smishing · 2 side-load (blocked)
Android (corp-owned)312100%100%14 smishing · 4 rooted (blocked)
iOS (BYOD)88498%92%18 smishing · 0 jailbroken accepted
Android (BYOD)41294%88%22 smishing · 2 rooted (blocked)
✅ Device Attestation — Play Integrity / DeviceCheck Gate (T337)SAMPLE
Conditional-access rejects jailbroken / rooted. Warns on older-OS. Attestation freshness checked per login.
ControlStatusScopeFailures (7d)
Play Integrity verdict (Android)ENFORCEDall Android6 blocked
DeviceCheck / App Attest (iOS)ENFORCEDall iOS0
Min OS version (iOS 16 / Android 12)ENFORCEDall corp18 warned · 4 blocked
Attestation freshness < 24 hENFORCEDall corp
Jailbreak / root detectHARD BLOCKall8 blocked
SAMPLE DATAPREVIEW — NOT CONNECTED. This tab has no live data source. Every number, row and chart below is fixed sample content shipped with the console, not your organisation's data.
🎯 CTEM — Continuous Threat Exposure Management LAYER 7SAMPLE
A CVE list is not a risk report. An attack-path is. CTEM unifies CVE + config + identity + exploit-probability into the paths attackers actually walk.
Attack paths
to crown-jewel
KEV in edge
exploit-in-wild CVEs
Edge patch SLA
18h
p95 · target < 24h
Paths shrunk (30d)
↓ 14%
month over month
🔥 Vuln Feed — EPSS · KEV · Exploit-in-Wild (T350)SAMPLE
Rank by exploited-in-wild first, CVSS last. KEV matches are automatic P0.
CVEProductCVSSEPSSKEVAffectedState
CVE-2026-1841libxml2 2.9.149.80.94YESplatform · 12 hostsP0 · patched
CVE-2025-52812golang 1.21.48.20.71YESinfra · 8 hostsPATCHING
CVE-2026-2018axios 0.21.47.50.18noapi · 6 reposauto-PR
CVE-2024-47178cups-filters9.90.08no0 hosts (not installed)N/A
CVE-2024-6387 (regreSSHion)OpenSSH8.10.89YES0 (already patched)CLEAN
⏱ Edge Patch SLA 24 h with Virtual-Patch Fallback (T351)SAMPLE
Internet-facing critical CVE → patched or WAF virtual-patched in 24 h. Exceptions require an owner + expiry.
CVEAssetDisclosedPatched / virtual-patchedSLAStatus
CVE-2026-1841edge LB · nginxtoday 04:20today 07:383 h 18 mMET
CVE-2025-52812api-gatewayydayWAF virt-patch · 42 minMET · virt
CVE-2026-2018marketing site2d agodependency PR18 hMET
CVE-2024-legacyold-vpn (scheduled decom)weeks agovirt-patch + maintenance winopen · exceptionEXCEPTION · expires 30 Apr
🗺 Unified Attack-Path Engine (T352)SAMPLE
CVE + config + identity + exposure combined. Path rank = reachability × impact × exploit-probability. Monthly shrinkage is the KPI.
StartCrown jewelHopsChainRankAction
InternetPII store4ELB → app (CVE-1841) → role → passRole → s3:pii98patch + scope passRole
InternetCrown DB5ELB → api → lambda → sts → db-admin → rds86scope lambda
PhishSource repo4user → GH-app → CI → deploy → write-all82scope GH-app
InternetSecrets manager3ELB → app → SecretsMgr wildcard78ARN-pin
InternetK8s admin3Jira bot → CI → cluster-admin74rotate bot token
📉 Exposure Diff Week-Over-Week (T353)SAMPLE
Path count, avg length, % Internet-to-crown-jewel. Board-metric: "are we getting better?"
Measure12 wks ago8 wks ago4 wks agoNowTrend
Path count to crown-jewel42342824↓ 43%
Avg path length (↑ is better)3.23.63.94.2↑ longer
% internet-to-crown-jewel38%30%24%18%↓ 20pp
Top chokepoint fixes (cumulative)471114compounding
💎 Crown-Jewel Classification (T354)SAMPLE
Per-data-class + per-system tag drives attack-path weighting. "What must never be lost" is a short list, reviewed quarterly.
Crown jewelClassOwnerBlast-radius capRecovery RTO
Customer PII DBTier-0 · PIICPO1 incident / 5y< 4 h
KYC document storeTier-0 · PII + docsCPO1 / 5y< 4 h
Payment processing keysTier-0 · cryptoCTO0 compromise< 15 min
Source-code + CI keysTier-0 · IPCTO0 exfil< 1 h (restore)
Finance data (board-reporting)Tier-0 · financialCFO1 / 5y< 8 h
Brand credentials (domain · SSL · GitHub · SaaS super-admin)Tier-0CISO0 compromiseimmediate
🤺 Continuous External Pentest / Autonomous Red-Team (T355)SAMPLE
Weekly safe-run against external surface. Findings diffed; promoted to CTEM + detection-as-code.
RunScopeFindingsNew detections createdDelta
This weekpublic IP ranges + SaaS2 medium · 0 high1stable
Last weekpublic + auth-replay1 high (BOLA · fixed 24h)1closed
2 wks agoexternal attack surface1 medium (subdomain takeover)0closed
3 wks agoOAuth / consent surface00clean
Quarterly human red-teamfull scope · 5d engagement3 medium + report4all closed
🟣 Internal Purple-Team Cadence — Quarterly (T356)SAMPLE
Named ATT&CK scenario · pre-agreed window · findings → detection-as-code PRs. Each quarter rotates tactic focus.
QuarterScenarioATT&CK focusDetections improvedOutcome
Q2-26 (planned)Cloud-first ransomware kill-chainCred Access + Impactin-planning
Q1-26AiTM + session-replay + graph-API exfilInitial Access + Collection+ 6 rulesdwell 32m → 8m
Q4-25Supply-chain implant via CI runnerPersistence + Exfil+ 4 rulesdetect < 60s
Q3-25Kerberoast + ADCS ESC1 chainPrivEsc+ 5 rules · honey-SPNzero-FP detect
Q2-25BEC + wire-fraud end-to-endInitial Access + Impact+ 3 rules + policydual-control adopted
The Fleet — Aria Search · Classify · Respond GET
/aegis/fleet — public catalog of the agent roles that power every shield. Each agent delegates to one or more internal Claude-powered agents.
Demo Seed POST
/aegis/demo/seed — populate all six shields with realistic sample data so every endpoint shows output.
Click to populate 6 Wazuh alerts, 4 email samples, 2 recon targets, Underwrite consent.