On the free plan? Get it on its own for
£19/mo per server — no need to subscribe to external scanning first. Install it on a server from your dashboard. Runs continuously, read-only, source published.
How it works →
Pending security patches
Flags OS and package updates that haven't been installed yet.
SSH / RDP hardening
Checks for weak remote-access settings like password-only login or missing Network Level Authentication.
Local firewall & antivirus status
Confirms the server's own firewall and (on Windows) Defender are actually turned on.
File permissions & local accounts
Flags world-writable system files, the Guest account being enabled, and other local misconfigurations a remote scan can't see.
Encoded PowerShell & LOLBAS abuse NEW
Hunts the last 24h of the server's own event log for obfuscated commands and abuse of tools like mshta, wevtutil, or certutil.
Pass-the-Hash, RID hijacking & brute force NEW
Detects stolen-credential lateral movement, hidden admin accounts, login brute-force bursts, and new scheduled tasks — each finding mapped to its MITRE ATT&CK technique with a response playbook.