What we check
Coverage grows with the tier. Everything below is read-only collection.
EXTERNAL
Public surface
- DNS records and subdomain exposure
- TLS certificates and expiry
- Open ports and reachable services
- Email authentication: SPF, DKIM, DMARC
- Remote access and VPN endpoints
- Breached-credential exposure for your domain
INTERNAL
Endpoints and identity
- Patch level and unsupported operating systems
- Local administrator sprawl
- Password and lockout policy
- SMB and RDP exposure on the LAN
- Endpoint protection status
- Backup presence and last successful run
FULL ENTERPRISE
Estate systems
- Active Directory: privilege, delegation, stale objects
- Exchange: mail flow, permissions, transport rules
- SQL Server: authentication, roles, encryption
- VMware: host and cluster configuration
- Firewalls: rule base, any-any rules, logging
Templates, not improvisation
At Full Enterprise tier each system type has a collection template: a declared list of queries, the read-only permissions they need, and the data they return. You review and approve the template before the run, and the report states which template version was used.