Home Defensive Audit INTERACTIVE ARCHITECTURE DIAGNOSTIC
Would Your Defensive Stack Survive?
Check off the security controls currently enforced in your production environment. Our simulation engine tests your stack against 59 landmark primary-sourced cyberattacks, pinpointing exact bypass vectors and fatal architectural gaps.
Interactive diagnostic evaluating your defense stack against 59 landmark primary-sourced cyberattacks. Identifies exact bypass vectors across historical incidents including Change Healthcare, NotPetya, and MGM Resorts. Provides prioritized remediation actions to close fatal perimeter and lateral traversal gaps. Stack Resilience Score 0%
Select your deployed security controls below to begin the assessment.
Attacks Neutralized
0
out of 59 cases
Fatal Gaps Remaining
59
breaches would succeed
Select All Controls
Reset Stack
Export Gap Assessment (Markdown)
1. Select Enforced Defensive Controls
0 of 12 active
Identity & Access
Hardware FIDO2 MFA Across 100% of External Ingress
Enforces phishing-resistant hardware security keys across all VPN, Citrix, VDI, email, and administrative portals without exception.
Identity & Access
Out-of-Band Multi-Party Helpdesk Verification
Requires in-person or cryptographically verified callback approval before resetting MFA tokens or granting temporary access codes.
Cloud & SaaS Security
Strict IP & Network Allowlisting for Cloud Data Warehouses
Blocks API queries and logins to cloud repositories (Snowflake, AWS S3, Azure) originating outside approved corporate IP ranges.
Cloud & SaaS Security
Automated OAuth App Auditing & Least-Privilege Scoping
Prohibits tenant-wide application permissions (e.g. full_access_as_app) and revokes dormant service principals quarterly.
Perimeter & Edge
Edge Gateway Critical CVE Patching SLA Under 24 Hours
Automated patching or immediate isolation for internet-exposed appliances (Citrix ADC, Ivanti, Fortinet, MOVEit) upon KEV catalog addition.
Endpoint Security
EDR with Anti-Tamper & Immediate Host Isolation
Modern endpoint detection agent with behavioral blocking, process memory inspection, and cloud connectivity tamper protection.
Endpoint Security
PowerShell Constrained Language Mode & Script Block Logging
Enforces Device Guard / AppLocker policies restricting PowerShell execution to signed scripts and enabling centralized Event ID 4104 ingestion.
Endpoint Security
Kernel Driver Blocklist (Anti-BYOVD Protection)
Enforces hypervisor-protected code integrity (HVCI) and the Microsoft Recommended Driver Blocklist to stop vulnerable signed drivers.
Active Directory & Network
Active Directory Tiered Administration & Privileged Workstations
Tier 0 Domain Admin credentials never touch or authenticate to Tier 1 servers or Tier 2 user workstations, eliminating Mimikatz harvesting.
Active Directory & Network
Internal Subnet Microsegmentation & SMB/RPC Filtering
Restricts TCP port 445 (SMB) and 135 (RPC) traversal between workstation subnets, halting automated worm and PsExec propagation.
Disaster Recovery & Extortion
Immutable / Air-Gapped Offline Backups Tested Quarterly
Write-once-read-many (WORM) cloud vaults or physically disconnected storage that cannot be modified or encrypted via domain credentials.
Disaster Recovery & Extortion
Canary Credentials & Honey Token Traps
Deploys bogus high-privilege credentials in LSASS memory and cloud buckets that generate instantaneous alerts upon unauthorized use.
2. Landmark Attack Simulation Results
All (59)
Fatal Gaps Only
Neutralized