What changed, what is weak,
and what is already known bad.
Five endpoint disciplines that usually mean five agents and five consoles: file integrity, configuration assessment, vulnerability detection, asset hygiene and malware. One agent, one interface, one severity scale.
Vulnerability detection with a real lifecycle: first detected, last seen, resolved, reopened.
Not that it changed. What it changed from.
A file integrity alert that says a path was modified is the beginning of the question. NullSOC keeps the hashes, size, permissions, owner and modification time from before and after the change, and gives every watched object its own history.
- ▸Before and after. MD5, SHA1, SHA256, size, permissions, owner, group, inode and modification time on both sides.
- ▸Files and registry. Windows registry keys carry value name, value type and architecture alongside the file fields.
- ▸Per object lifecycle. Click a path for its full change timeline, each event showing exactly what moved.
- ▸Compliance on the event. PCI DSS, HIPAA, NIST, GDPR, TSC, GPG13 and ATT&CK come from the rule that fired.
Added, modified and deleted, with the objects that change most often ranked.
A patched CVE should not simply vanish.
Most scanners rewrite their results each run, so a vulnerability that got fixed disappears without a record and your remediation time is unmeasurable. NullSOC diffs each scan and records the transition, so first detected, resolved and reopened are real events.
- ▸Five live sources. Ubuntu OVAL and package comparison, Microsoft MSRC build comparison, OSV for pypi and npm, NVD by CPE, and snaps.
- ▸Real lifecycle. New, open, resolved and reopened, with aging buckets and mean time to resolve by severity.
- ▸Publish date and advisory link. Every CVE carries the date the feed published it and links out to its advisory.
- ▸Explore three ways. By CVE, by package or by host, each sortable and exportable, with a per agent inventory.
By CVE, by package or by host. Fixed versions come from the feed, not a guess.
CIS benchmarks, with the reason and the remedy.
Configuration assessment runs the real policy content and reports each check with its title, result, score, rationale and remediation text, plus the control identifiers it maps to. A failing check tells you what to change, not just that something is wrong.
- ▸Real check content. Title, result, score, file, rationale and remediation, exactly as the policy defines them.
- ▸Control mappings. Each check carries its CIS, CIS CSC v8, NIST, PCI DSS and SOC 2 identifiers.
- ▸Change driven. Results are reported when they change, so a stable estate does not generate daily noise.
- ▸Per policy and per host. Score by policy, posture by agent, and the individual checks behind both.
Policy score, pass and fail, and every check with its remediation text.
The inventory you need before an incident, not during one.
When something happens at three in the morning, the question is what was installed, what was listening and who could log in. That inventory is collected continuously per agent, so it is already there rather than something you go and gather under pressure.
- ▸Software inventory with package version, architecture, vendor and size per host.
- ▸Listening ports and processes with the owning process, its identifier and the user it runs as.
- ▸Local accounts, groups and services so privilege changes are visible as they happen.
- ▸Malware and rootcheck detections land in the same finding stream with the same severity scale.
Operating systems, listening ports and package inventory, collected continuously.
Ask what changed on a host
last Tuesday at four.
Pick a server and a moment. We will show you the file hashes before and after, what was installed, what was listening and who logged in.
Powered by Codesecure Solutions. Self hosted, cloud or fully managed.
