Services / Security analysis

Current-state assessment

Security analysis - a risk map and an order of work

Cloudflare shows what is exposed to the internet. ntopng shows traffic on the network. OpenVAS shows known gaps. Wazuh shows signals from hosts. We put this into one risk map, with an order of work. Layer deployment and on-call are a separate security service.

Map Surface, traffic, gaps, and signals in one picture
Risk Weight together with exposure and data, not CVSS alone
Order What to close first, with a justification
Next step Hardening, audit, or on-call, according to the result
How it fits together

Four views, one risk map

A scan without traffic guesses exposure. Traffic without the host does not say what happened on the machine. The edge without the rest sees only the internet. Analysis joins these four views and leaves an order of work.

  • The result is a map and a backlog, not a Wazuh deployment or 24/7 on-call.
  • A compliance audit maps that state to ISO, SOC 2, or DORA. Analysis first says what is there.
Cloudflare Security Analytics, bot score, WAF and request log
01, Cloudflare

What is public, before we enter the network

Analysis starts at the edge. DNS, certificates, WAF, Access, and whether origin still listens on a public address. Cloudflare Security Analytics shows bot score, rules, and the request log. From that we know what is actually visible from the internet.

Surface

Hostname, ports, panels, API. A list of what should be public. The rest behind Access or VPN.

Internet traffic

Bot score, a scan, a flood, login attempts. Whether the edge stops the mass, or passes it to origin.

Identity

Grafana, cloud, and staging through SSO. A panel on a password on the internet is a finding.

Gap

Origin beside Cloudflare, a stale DNS record, an open admin port. That is exposure, not a network detail.

ntopng, flows, applications and traffic classification
02, ntopng

Traffic that leaves the known profile

ntopng classifies flows, applications, and hosts. Analysis compares an ordinary day with a deviation: a new destination, a scan, large egress, traffic between machines that should not talk. Without this picture a gap scan says what can be attacked, not whether someone already walks the network.

Profile

Who talks to whom, which protocols, which volume. A baseline, not a one-off dump.

Deviation

A new ASN, unusual DNS, a connection outside the known set of services, a jump in volume.

Segmentation

Whether staging sees production, whether the database is reachable from a laptop, whether the jump host is the only path.

Correlation

A flow is lined up with a host alert and with the edge. One event, three views.

Greenbone OpenVAS, scan dashboard, CVE and NVT
03, OpenVAS

Known gaps with exposure, not only a numeric score

OpenVAS gives a list of known gaps. Analysis weights them together with exposure and data. A public application and a card dataset before a host with no internet traffic. The result enters the risk map, it does not stay a separate PDF.

Scope

Hosts, panels, databases, staging, and production. A separate policy for what is visible from the internet.

Priority

CVSS together with traffic and data. A critical gap on a host with no exposure does not outrank a medium on origin.

Authentication

A scan after login shows real package versions. Without that the report guesses.

Next step

A remediation queue with an owner is already hardening or audit. Analysis says where to start.

Wazuh console, Debian endpoint, MITRE, SCA and vulnerabilities
04, Wazuh

Signals that are already on the machines

If agents already run, we look at alerts, FIM, and SCA. If not, we still write down which logs exist and which are missing. Analysis does not deploy a SIEM. It shows whether an incident can be seen today, or only reconstructed after the fact from a few files.

Coverage

Which hosts have an agent or a log. Production and the jump host before a test machine.

SCA and FIM

Drift against CIS, a file change outside the window. Material for configuration risk.

Alerts

Noise versus an event that needs a response. A missing playbook is a finding, the same as a missing log.

Audit trail

Whether we can say who, when, and from which source. Log retention and access enter the map too.

The run

From scope to an order of work

First critical systems and data. Then collection from the edge, the network, the scan, and hosts. Finally a report and a decision on what to deploy.

  1. Scope Systems, data, who signs, what is out of scope.
  2. Collection Surface, traffic, a gap scan, logs, and configuration.
  3. Report Risk, exposure, order, a justification for the board and a list for engineering.
  4. Decision Hardening, a compliance audit, or on-call, according to what came out.
Questions

Analysis scope and split of work

How is analysis different from a compliance audit?

Analysis describes the state: what is exposed, what the traffic is, which gaps are known, which signals are visible on hosts. An audit maps that state to ISO 27001, SOC 2, DORA, or KNF controls and leaves a backlog for certification. Analysis is often the first step, the audit the second.

Is this a penetration test?

No. A penetration test composes several gaps into one attack scenario, usually less often and with more depth. Analysis uses a scan of known gaps, traffic, and logs. It gives a map and an order for today. The test says how those gaps can be used together.

Do we already need Cloudflare, ntopng, OpenVAS, and Wazuh?

No. If the tools are there, we use them. If not, we still write down the surface, the logs that exist, and a scan we can run in scope. A missing tool is part of the picture, not a block on the analysis.

What remains after the analysis?

A risk map, an order of work, and a recommendation for the next service: security and hardening, audit, or administration. Layer deployment and on-call are scoped separately, on the basis of that report.

Talk

We will discuss the analysis scope and critical systems

On that basis we will prepare a risk map and an order of work.

Contact us