What it inspects
- Installed EDR — SentinelOne, CrowdStrike, Tanium, Elastic Agent, Cortex, Carbon Black and more
- AV and other protection software, with live status and definition age
- Microsoft Defender state, including real-time and tamper protection
- Group Policy, MDM profiles and GRC-relevant policy compliance
- Active Directory / Entra membership and join type
- Firewall, disk encryption and patch currency
- Secure boot, TPM and firmware state
- Logging: audit configuration, log agents, whether anything is forwarded off the host
- Certificate trust store, proxy inspection, backup and cloud management
- Remote-access paths, browsers and installed software
- Local administrators and account hygiene
- Platform, hardware details and attached USB devices
- A set of CIS-aligned hardening controls, mapped onto CIS v8, ISO 27001, NIS2 and SOC 2