Control checks

Every published run also checks a curated set of CIS-aligned hardening controls — audit policy, script-block logging, SMBv1, LSA protection, SSH hardening, sudo rules and the rest. This is how often each one is actually configured the way it should be.

No published control checks yet

Control-check rates appear once 3 runs carrying them have been published. Only clients from the expanded release collect them, so older reports contribute nothing here.

What gets checked, and what the result means

Roughly forty checks per platform, drawn from the CIS Benchmark Level 1 recommendations for Windows, macOS and Linux, plus a few Level 2 items that decide whether the trigger tests could succeed at all. Each result carries the value actually observed next to the value the control wants, so a verdict can be disagreed with rather than merely trusted.

A check the client could not evaluate — no administrative rights, a missing command — is recorded as unknown and excluded from every rate on this page. That is deliberate: counting it as a failure would make an unprivileged run look like a badly configured host.

This is described as CIS-aligned, not as a certified CIS benchmark run, and the check set carries a version so scores stay comparable when it changes.