Codesecure SolutionsA Codesecure Solutions product
Pillar 05 of 12

What changed, what is weak,
and what is already known bad.

Five endpoint disciplines that usually mean five agents and five consoles: file integrity, configuration assessment, vulnerability detection, asset hygiene and malware. One agent, one interface, one severity scale.

nullsoc.in / vulns
The NullSOC vulnerability view: severity KPIs, CVSS distribution, top packages and hosts, and recent detections.

Vulnerability detection with a real lifecycle: first detected, last seen, resolved, reopened.

5
Disciplines
FIM, SCA, vulnerabilities, hygiene and malware, one agent.
5
Vulnerability feeds
Ubuntu OVAL, Microsoft MSRC, OSV, NVD and snap.
3
Hash algorithms
MD5, SHA1 and SHA256, before and after every change.
6
Compliance frameworks
Carried on every finding these produce.
File integrity

Not that it changed. What it changed from.

A file integrity alert that says a path was modified is the beginning of the question. NullSOC keeps the hashes, size, permissions, owner and modification time from before and after the change, and gives every watched object its own history.

  • Before and after. MD5, SHA1, SHA256, size, permissions, owner, group, inode and modification time on both sides.
  • Files and registry. Windows registry keys carry value name, value type and architecture alongside the file fields.
  • Per object lifecycle. Click a path for its full change timeline, each event showing exactly what moved.
  • Compliance on the event. PCI DSS, HIPAA, NIST, GDPR, TSC, GPG13 and ATT&CK come from the rule that fired.
nullsoc.in / fim
The file integrity view: files added, modified and deleted, change over time and the most changed objects.

Added, modified and deleted, with the objects that change most often ranked.

Vulnerabilities

A patched CVE should not simply vanish.

Most scanners rewrite their results each run, so a vulnerability that got fixed disappears without a record and your remediation time is unmeasurable. NullSOC diffs each scan and records the transition, so first detected, resolved and reopened are real events.

  • Five live sources. Ubuntu OVAL and package comparison, Microsoft MSRC build comparison, OSV for pypi and npm, NVD by CPE, and snaps.
  • Real lifecycle. New, open, resolved and reopened, with aging buckets and mean time to resolve by severity.
  • Publish date and advisory link. Every CVE carries the date the feed published it and links out to its advisory.
  • Explore three ways. By CVE, by package or by host, each sortable and exportable, with a per agent inventory.
nullsoc.in / vulns
Vulnerability explore view with CVSS distribution, severity split and top affected packages and hosts.

By CVE, by package or by host. Fixed versions come from the feed, not a guess.

Configuration

CIS benchmarks, with the reason and the remedy.

Configuration assessment runs the real policy content and reports each check with its title, result, score, rationale and remediation text, plus the control identifiers it maps to. A failing check tells you what to change, not just that something is wrong.

  • Real check content. Title, result, score, file, rationale and remediation, exactly as the policy defines them.
  • Control mappings. Each check carries its CIS, CIS CSC v8, NIST, PCI DSS and SOC 2 identifiers.
  • Change driven. Results are reported when they change, so a stable estate does not generate daily noise.
  • Per policy and per host. Score by policy, posture by agent, and the individual checks behind both.
nullsoc.in / sca
The configuration assessment view: policy scores, pass and fail distribution and individual CIS checks.

Policy score, pass and fail, and every check with its remediation text.

Hygiene and malware

The inventory you need before an incident, not during one.

When something happens at three in the morning, the question is what was installed, what was listening and who could log in. That inventory is collected continuously per agent, so it is already there rather than something you go and gather under pressure.

  • Software inventory with package version, architecture, vendor and size per host.
  • Listening ports and processes with the owning process, its identifier and the user it runs as.
  • Local accounts, groups and services so privilege changes are visible as they happen.
  • Malware and rootcheck detections land in the same finding stream with the same severity scale.
nullsoc.in / it-hygiene
The IT hygiene view: operating system distribution, listening ports and installed package inventory per agent.

Operating systems, listening ports and package inventory, collected continuously.

Get started

Ask what changed on a host
last Tuesday at four.

Pick a server and a moment. We will show you the file hashes before and after, what was installed, what was listening and who logged in.

Powered by Codesecure Solutions. Self hosted, cloud or fully managed.