Evidence-driven cybersecurity assurance

Start with your environment. End with a reviewed control result.

Choose the role and technologies you actually operate. Then select a control pack to see what evidence to provide, which platform-specific query applies, how it is monitored, and what the result means.

13control objectives
3platform paths
39reference queries
6evidence input contracts

Queries run in your environment. We do not collect credentials, tenant data, or production evidence. Validate each query before using it.

What this is

Ready-made checks for specific problems: access that stayed active, an exposed service, or a backup that failed. Each check explains what it finds and what it cannot prove.

Why bother

These checks are based on real incidents and exploited flaws reported by public sources. The Signals page links each report to the check that can look for the related condition.

Already know what you need? The three steps below take you from the technologies you operate to a query you can run and a result you can review.

Environment profile

Tell us what you operate before choosing a pack.

Your choices decide which platforms, sources, and packs are available.

How do you work?Choose the closest operating model.

What technologies are in scope?Select every relevant source, including more than one cloud.
What do the badges mean?Every technology below states how it reaches a published query

Queries only ever run in Microsoft Sentinel, AWS, or Splunk. Other selections are data sources or evidence systems. The badge shows how each one connects.

Direct query
The query reads this technology's own tables or API. Nothing to export or forward.
Via Splunk
Forward the product's records to Splunk using the listed sourcetype and fields. The existing SPL query can then use them without a new query.
Via CSV export
Export the needed fields into one of the six open CSV schemas. This is how CMDBs, ticketing systems, and similar sources provide evidence.
Roadmap
Named and scoped, but nothing in this release reads it. Listed so the gap is stated rather than left for you to discover.

Open How this connects for the exact source, fields, or file.

Implementation pack library

Choose a category, then a control.

Choose an area. Packs are filtered to your profile, with an option to view everything.

Implementation guide

Follow the selected pack from requirement to review.

Five steps from the requirement to a result. Switch platforms without changing the objective.

Selected pack
1

Step 1 · The requirement

Source requirement vs. local implementation choice

Organization-defined parameters

2

Step 2 · What you must supply

Evidence inputs

Instructions shown for Microsoft Sentinel.

3

Step 3 · How it is monitored

Platform-native detection query

The query below follows the working platform selected above and updates automatically.

Customise this query

Adjust the available settings. The query updates automatically as you type or change platforms.

Your input stays in this browser
Values supplied or changed Source read by this query
4

Step 4 · How it runs continuously

Show continuous monitoring configuration
Continuous monitoring configuration
5

Step 5 · What the analyst sees

Console preview and human review

Open this workspace when you are ready to generate a synthetic console preview and review the possible implications.

Open analyst review workspaceGenerate the preview only when needed

As it would appear in the console

All simulated alerts for this control

What a reviewer still has to decide

    Implementation snapshot

    Know what the query needs before you run it.

    See the data, evidence, permissions, and platform used by this control.

    The JSON profile carries the objective, organization-defined parameters, evidence contract, platform implementation, monitoring configuration, outcome vocabulary, human-review boundary, and validation status as one structured artifact. It is OSCAL-informed and is not an OSCAL document. It contains no credentials, tenant data, query results, or evidence values.

    Reference

    Every control, on every platform

    A page per control with the requirement, the query, the evidence it needs, and what a result does not prove — readable without running anything. Browse the full library, where you can search and filter by platform, family and validation status.

    Evidence record inspector