Infrastructure Defense
Host security posture for your servers. The Sentinel Host agent inventories each machine, the cloud correlates vulnerabilities and misconfigurations, the Viking Exposure Score prioritizes them, and Resolve executes approved fixes with a measured risk reduction.
WASViking® Infrastructure Defense is the security posture of the servers running your business, in one place: what you have, where it is vulnerable, which fixes matter most, and how much risk each executed fix actually removed. It works from facts a lightweight agent collects on each host and it never ends at "N vulnerabilities found"; the cycle only closes when a later inventory proves the risk dropped.
How it works
A small agent, the WASViking Sentinel Host, runs on each enrolled server and reports a security posture inventory over mutual TLS: operating system and kernel, installed packages, running services and listening ports, pending updates, and security configuration such as the firewall state and the SSH hardening options. The asset inventory also carries the machine facts an operator expects on an asset record: naming (FQDN, DNS hostname, and on Windows the NetBIOS name), IPv4 and IPv6 addresses, manufacturer and model, processor and total memory, fixed volumes with free space, and the local account names as the operating system reports them. It reads posture only; it never opens user files or content, and account names are collected without any profile data or per-user activity.
Every inventory is correlated in the WASViking cloud:
- Installed packages are matched against the OSV vulnerability database, qualified by the exact distribution release so a patched host is never flagged for another branch's bug. Windows security updates come from the platform's own update service, macOS updates from the published security releases, and third-party Windows applications from the package manager inventory.
- Each vulnerability carries its CVSS severity, its EPSS exploitation probability, and whether it appears in the CISA Known Exploited Vulnerabilities catalog.
- Pending security updates become "missing patch" context: which open vulnerabilities a published fix would close.
- An operating system or a tracked software product past its vendor's end of support is flagged from published lifecycle data, with the date on the label, because no patch is coming for it.
- A configuration check subset aligned with CIS benchmark sections evaluates the collected settings and scores each host with a compliance percentage, with a PCI DSS mapping of the same results. Platform posture is collected alongside: disk encryption, Secure Boot and TPM state on Windows, System Integrity Protection, Gatekeeper and MDM enrollment on macOS.
- The platform's own attack surface discovery proves internet exposure: when a discovered public asset resolves to an address assigned to the host, the exposure flag lights with the proof named, and a manual decision by your team always wins over the automation. Edge telemetry adds an active attack factor when blocked attack-grade traffic hit a hostname the server serves in the last seven days; the factor decays on its own when the traffic stops.
The Viking Exposure Score
Each host gets a Viking Exposure Score from 0 to 100. The worst open vulnerability sets the base; exploitation evidence (KEV, EPSS), proven internet exposure, active attack traffic seen at the edge, end of life state, business criticality, and environment adjust it. The score is never a black box: every screen shows the exact factors and points behind the number, so "why is this critical" always has a concrete answer.
Resolve: remediation with proof
WASViking Resolve turns the priorities into work under your control:
- Recommended actions group the pending security updates of each host, ranked by the score reduction they are expected to deliver.
- Scheduling an action freezes it as a job with the exact package list, so the approver signs off on a concrete change.
- A person with the Remediate permission approves the job, optionally inside a maintenance window defined by the host policy. Automatic deployment and automatic reboot are off by default.
- The agent runs pre-checks, applies the updates through the native mechanism of each platform (the system package manager on Linux, the update service on Windows, software updates on macOS), and reports the outcome per item.
- The next inventory is the verdict: the job completes only when the reassess shows which vulnerabilities closed and how far the score dropped. The before and after numbers are measured, never estimated, and when a reboot is still pending the job says so instead of declaring victory early.
Policies decide how far the platform may go on each group of hosts: what gets assessed, whether jobs need manual approval, and when changes are allowed. Every action lands in the audit trail, and the patch job outcome can notify your Slack, Teams, email, or webhook channels.
Reporting
The Overview screen answers the ten second question: overall infrastructure risk, the fleet numbers, and the top risks with their reasons. A branded PDF report exports the same story for stakeholders: fleet posture, verified risk reduction, top vulnerabilities, misconfigurations, and per host compliance.
Set up
Infrastructure Defense is an add-on module enabled per organization. Once it is on, open Infrastructure Defense → Sentinel Hosts in the portal. For a single server, enroll a host to get its one time credentials and run the two commands shown on the enrollment card (register, then run). For a fleet, open the Activation keys tab, generate a reusable key (with an optional agent cap and expiry), pick the platform on its install page, download the agent package for Windows, Linux or macOS and run the install command shown there: it carries the key, registers the host and starts the service in one step. Windows fleets can use the standard MSI package with the mass deployment tooling they already run, and enrolled agents keep themselves current with one-click self-update from the console. Either way the host appears on the Assets screen with its first inventory within minutes and its score follows the first assessment. For the whole flow with screenshots, from the first activation key to the first verified patch job, follow the step by step setup guide; the module activation checklist covers turning the module on.
