AI DEFENCEBY ALTARI SYSTEMS
Menu

Coverage / Hosts & runtime

Server security audits, from host posture to hardening.

AI Defence’s server security audit is designed to inspect operating-system configuration, packages, services, privileges and runtime evidence. The aim is a defensible host baseline and an ordered hardening plan, with customer approval before changes.

IN DEVELOPMENTExplore the specified scope. See capability availability.

Start with the operating system and its role

A host inventory should identify the operating system, version, patch level, resources, installed software, running processes and dependencies. Physical machines, virtual machines, workstations and application servers can have different roles and access requirements. The assessment must keep those roles attached to its findings.

The specified host checks include missing security updates, unsupported software, kernel settings, secure boot where applicable, system permissions, SUID/SGID exposure and writable system paths. Scheduled tasks, startup services and remote management configuration also form part of the posture review.

  • Host firewall, time synchronisation and logging or auditing configuration.
  • Unnecessary services and unexpected daemons.
  • Antivirus or EDR presence and status, where accessible.
  • Backup configuration and evidence of recovery readiness.

Look for suspicious changes without declaring every anomaly malicious

Unknown scheduled tasks, suspicious binaries, unexpected privileged users and unusual outbound connections may warrant investigation. An observation must be correlated with deployment history, authorised administration and the established baseline before it is treated as a confirmed incident.

Continuous host monitoring is designed to detect account and privilege changes, new SSH keys, unexpected processes and modified security configuration. Missing logs or a disconnected collector create detection gaps; they are not evidence that the host is clean.

Hardening must preserve the workload

Potential approved actions include patching software, correcting permissions, disabling unsafe services and strengthening SSH configuration. A patch or service restart can affect availability, and a permissions change can interrupt a worker or backup job. The recommendation should explain those dependencies and likely impact.

The existing Remedy Agent foundation uses outbound communication and capability-based permissions with local allowlists. That foundation supports controlled runtime work; it does not establish that the complete Defence host assessment is released. The supported host operating systems and checks must be confirmed for each deployment.

Questions answered

Does AI Defence need unrestricted shell access?

The intended model uses explicitly granted capabilities and bounded actions. A security assessment should request only the evidence and remediation permissions needed for the agreed scope.

Is a successful patch command proof that a server is secure?

No. The affected vulnerability, running software state, exposure and relevant application health need verification. Residual findings and unexamined areas remain part of the report.

Start with understanding

What does your environment need to defend?

Discuss the assessment scope, current capabilities and the control you need with Altari Systems.

Talk to Altari