AI DEFENCEBY ALTARI SYSTEMS
Menu

Coverage / Network & attack surface

Network security audits that put exposure in context.

A network security audit identifies reachable assets, exposed services and the paths between security zones. AI Defence is designed to connect that exposure to host, identity and vulnerability evidence, so teams can prioritise the routes that create material risk.

IN DEVELOPMENTExplore the specified scope. See capability availability.

Map reachable services and security boundaries

The assessment starts with network interfaces, internal and external addresses, routing and DNS. The scope includes subnets, reachable hosts, listening ports and internet-facing endpoints, with attention to IPv4 and IPv6. An organisation can close an IPv4 route while unintentionally leaving the equivalent IPv6 service reachable.

Discovery also considers NAT, VPNs, VLANs and security zones. The purpose is to understand which services can reach each other, including east-west traffic between internal systems, and identify shadow devices or unexpected services.

  • Firewall configuration and accidental exposure through UPnP or port forwarding.
  • Administration panels, remote access, container APIs and orchestration interfaces.
  • DNS exposure, dangling records and domain or email controls where applicable.

A reachable port is a finding, not a complete risk assessment

A public service may be intentional. Risk depends on its authentication, software version, privileges and relationship to other systems. A development endpoint on an internet-facing host deserves different treatment from the same service on an isolated test network.

AI Defence’s risk-correlation design combines external and internal attack surface with trust boundaries. For example, an exposed management service becomes more urgent when its account can change production deployments or reach a sensitive database. This is contextual analysis, not an assertion that a particular path has been exploited.

Verify the intended restriction and the surviving access

A recommendation may be to restrict a management interface, remove an unnecessary port or adjust a firewall rule. Any such change requires explicit authority and a plan to preserve legitimate traffic and administrator access. Existing routes and dependencies should be recorded before modification.

Post-change checks need to establish both that the unwanted path is closed and that required application and management paths still work. Continuous monitoring is then designed to identify newly opened ports, unexpected devices, changed routes and weakened firewall configuration.

Questions answered

Does read-only discovery mean unrestricted scanning?

No. Targets, network scope and assessment methods must be authorised. Read-only assessment avoids configuration changes, but discovery traffic still needs limits appropriate to the environment.

Can AI Defence replace a network firewall?

The design assesses firewall posture and supports governed configuration changes. It is not a claim to replace the network’s firewall, VPN or routing infrastructure.

Start with understanding

What does your environment need to defend?

Discuss the assessment scope, current capabilities and the control you need with Altari Systems.

Talk to Altari