Does AI Defence need unrestricted shell access?
The intended model uses explicitly granted capabilities and bounded actions. A security assessment should request only the evidence and remediation permissions needed for the agreed scope.
Coverage / Hosts & runtime
AI Defence’s server security audit is designed to inspect operating-system configuration, packages, services, privileges and runtime evidence. The aim is a defensible host baseline and an ordered hardening plan, with customer approval before changes.
A host inventory should identify the operating system, version, patch level, resources, installed software, running processes and dependencies. Physical machines, virtual machines, workstations and application servers can have different roles and access requirements. The assessment must keep those roles attached to its findings.
The specified host checks include missing security updates, unsupported software, kernel settings, secure boot where applicable, system permissions, SUID/SGID exposure and writable system paths. Scheduled tasks, startup services and remote management configuration also form part of the posture review.
Unknown scheduled tasks, suspicious binaries, unexpected privileged users and unusual outbound connections may warrant investigation. An observation must be correlated with deployment history, authorised administration and the established baseline before it is treated as a confirmed incident.
Continuous host monitoring is designed to detect account and privilege changes, new SSH keys, unexpected processes and modified security configuration. Missing logs or a disconnected collector create detection gaps; they are not evidence that the host is clean.
Potential approved actions include patching software, correcting permissions, disabling unsafe services and strengthening SSH configuration. A patch or service restart can affect availability, and a permissions change can interrupt a worker or backup job. The recommendation should explain those dependencies and likely impact.
The existing Remedy Agent foundation uses outbound communication and capability-based permissions with local allowlists. That foundation supports controlled runtime work; it does not establish that the complete Defence host assessment is released. The supported host operating systems and checks must be confirmed for each deployment.
The intended model uses explicitly granted capabilities and bounded actions. A security assessment should request only the evidence and remediation permissions needed for the agreed scope.
No. The affected vulnerability, running software state, exposure and relevant application health need verification. Residual findings and unexamined areas remain part of the report.
Start with understanding
Discuss the assessment scope, current capabilities and the control you need with Altari Systems.