Step 1 · The requirement
—
—
—
Source requirement vs. local implementation choice
—
Evidence-driven cybersecurity assurance
Choose the role and technologies you actually operate. Then select a control pack to see what evidence to provide, which platform-specific query applies, how it is monitored, and what the result means.
Queries run in your environment. We do not collect credentials, tenant data, or production evidence. Validate each query before using it.
Ready-made checks for specific problems: access that stayed active, an exposed service, or a backup that failed. Each check explains what it finds and what it cannot prove.
These checks are based on real incidents and exploited flaws reported by public sources. The Signals page links each report to the check that can look for the related condition.
Already know what you need? The three steps below take you from the technologies you operate to a query you can run and a result you can review.
Environment profile
Your choices decide which platforms, sources, and packs are available.
Queries only ever run in Microsoft Sentinel, AWS, or Splunk. Other selections are data sources or evidence systems. The badge shows how each one connects.
Open How this connects for the exact source, fields, or file.
Implementation pack library
Choose an area. Packs are filtered to your profile, with an option to view everything.
Implementation guide
Five steps from the requirement to a result. Switch platforms without changing the objective.
Step 1 · The requirement
—
—
—
Step 2 · What you must supply
—
Step 3 · How it is monitored
The query below follows the working platform selected above and updates automatically.
Adjust the available settings. The query updates automatically as you type or change platforms.
—
Step 4 · How it runs continuously
—
—
Step 5 · What the analyst sees
Open this workspace when you are ready to generate a synthetic console preview and review the possible implications.
—
Send feedback here without leaving the page. Submissions are recorded with the selected pack and platform. Do not include identifiers, query results, or production evidence.
Did this pack run in your environment?
Implementation snapshot
See the data, evidence, permissions, and platform used by this control.
The JSON profile carries the objective, organization-defined parameters, evidence contract, platform implementation, monitoring configuration, outcome vocabulary, human-review boundary, and validation status as one structured artifact. It is OSCAL-informed and is not an OSCAL document. It contains no credentials, tenant data, query results, or evidence values.
Reference
A page per control with the requirement, the query, the evidence it needs, and what a result does not prove — readable without running anything. Browse the full library, where you can search and filter by platform, family and validation status.