Purpose
Hardening evaluates endpoint security posture against standardized policies. By automatically checking system configuration, password policy, user rights assignment, registry settings, and auditing settings, it lets you:- identify misconfigurations across Windows, Linux, and other enterprise operating systems;
- measure compliance scores per endpoint and per benchmark;
- track remediation using check-level descriptions, rationales, and step-by-step remediation commands.
Key concepts
- Policy / benchmark — a structured set of security recommendations from a standards body, such as the CIS Microsoft Windows 11 Enterprise Benchmark, or defined internally. Policies group checks by platform and functional domain.
- Check — a single security configuration rule evaluated on an endpoint, for example “Ensure ‘Enforce password history’ is set to ‘24 or more password(s)’”.
- Custom policy — your own benchmark, built by selecting a subset of checks from a base benchmark and applying them to chosen endpoints.
Check statuses
Pass score
The overall compliance percentage. Not Applicable checks are excluded from the calculation entirely:Controls and filtering
- Select Policy — the combobox in the top header filters every chart and summary statistic to one benchmark, such as CIS Microsoft Windows 11 Enterprise Benchmark v3.0.0, or shows aggregate data across All Policies.
- Endpoint / hostname filter — narrows results to specific hostnames or IP addresses.
- Advanced Filters — multi-criteria filtering across endpoints, connectivity status, and score ranges.
Related modules
- Endpoints — inventory, connectivity, and system details for every monitored agent.
- Approved software — software inventory compliance and baseline rules.
- Integrity monitoring — file and registry integrity changes.

