Does read-only discovery mean unrestricted scanning?
No. Targets, network scope and assessment methods must be authorised. Read-only assessment avoids configuration changes, but discovery traffic still needs limits appropriate to the environment.
Coverage / Network & attack surface
A network security audit identifies reachable assets, exposed services and the paths between security zones. AI Defence is designed to connect that exposure to host, identity and vulnerability evidence, so teams can prioritise the routes that create material risk.
The assessment starts with network interfaces, internal and external addresses, routing and DNS. The scope includes subnets, reachable hosts, listening ports and internet-facing endpoints, with attention to IPv4 and IPv6. An organisation can close an IPv4 route while unintentionally leaving the equivalent IPv6 service reachable.
Discovery also considers NAT, VPNs, VLANs and security zones. The purpose is to understand which services can reach each other, including east-west traffic between internal systems, and identify shadow devices or unexpected services.
A public service may be intentional. Risk depends on its authentication, software version, privileges and relationship to other systems. A development endpoint on an internet-facing host deserves different treatment from the same service on an isolated test network.
AI Defence’s risk-correlation design combines external and internal attack surface with trust boundaries. For example, an exposed management service becomes more urgent when its account can change production deployments or reach a sensitive database. This is contextual analysis, not an assertion that a particular path has been exploited.
A recommendation may be to restrict a management interface, remove an unnecessary port or adjust a firewall rule. Any such change requires explicit authority and a plan to preserve legitimate traffic and administrator access. Existing routes and dependencies should be recorded before modification.
Post-change checks need to establish both that the unwanted path is closed and that required application and management paths still work. Continuous monitoring is then designed to identify newly opened ports, unexpected devices, changed routes and weakened firewall configuration.
No. Targets, network scope and assessment methods must be authorised. Read-only assessment avoids configuration changes, but discovery traffic still needs limits appropriate to the environment.
The design assesses firewall posture and supports governed configuration changes. It is not a claim to replace the network’s firewall, VPN or routing infrastructure.
Start with understanding
Discuss the assessment scope, current capabilities and the control you need with Altari Systems.