DENSEDEFENSE · The Suite
DenseDefense · The Suite + an add-on

Find it. Fix it. Prove it. Keep it.

The Full Suite is four products on one continuous engagement: ForteFide scans and fixes compliance, ForteStrike attacks to prove it independently, ForteLock — a mode of ForteStrike — holds the line, and DenseSense finds where the controlled data lives. Every ForteFide, ForteStrike and ForteLock screen in this deck is a real capture; every number is from a live run.

Full Suite: ForteFide + ForteStrike + ForteLock + DenseSenseDenseAIArmour — optional AI add-onSigned, Ed25519 evidenceAir-gap capable
The stakes · False Claims Act

A self-assessment you can defend

Under self-attestation nobody validates your SPRS score before you submit it — you sign it, and you carry the False Claims Act liability. This is the record that survives the review.

You sign it. Personally.

A senior official signs your NIST 800-171 affirmation and posts the SPRS score to the government (32 CFR 170.24; DFARS 7021/7012). With CMMC Phase II's third-party check suspended as of 2026-07-13, no C3PAO catches an inflated score first — the signature, and the liability under 31 U.S.C. 3729, are yours.

An inflated score is a false claim.

The False Claims Act does not punish being wrong — it punishes reckless disregard for whether you're right, and each invoice after can be a separate claim. Georgia Tech settled for $875K over a SPRS score of 98 it could not support; that is the case this suite exists to prevent.

We give you an honest number — not a flattering one.

The suite checks 78 of the 110 controls automatically and captures the other 32 as human attestations; no control is scored MET on evidence that cannot determine it. Tonight's fleet came in at 50.3% — 39 of 110 requirements met — with the gaps named, not buried.

Signed evidence and a chain of custody.

Every artifact is signed, hashed, offline-verifiable, and traceable to its origin, so the affirming official, counsel, or a DIBCAC reviewer can walk the chain and see the score reflects the machine's real configuration. A tamper-evident record is what rebuts the 'knowingly false' element the FCA requires.

So the submission survives a review.

A documented, good-faith basis for every determination — and a POA&M that honestly tracks the open items instead of hiding them — is what converts 'your score was wrong' into an honest, defensible assessment when DoJ's Civil Cyber-Fraud Initiative or DIBCAC comes asking.

Why the suite, not a spreadsheet

They monitor. We fix — and sign it.

Every GRC tool finds the gap and hands it back; this suite hardens the host, re-scans to prove it, and packages signed evidence a C3PAO can trace.

Attack-proven, not checkbox-proven.

ForteStrike runs Metasploit's non-destructive check against your own hosts, so a finding is confirmed exploitable — not a config scanner's 'looks vulnerable.'

Evidence a C3PAO verifies offline.

Signed, hashed, air-gap-verifiable artifacts an assessor can trust without ever calling us — the record you defend an FCA claim with, not a screenshot folder.

An honest score, or none.

No control is ever scored MET on evidence that cannot determine it, and the 32 human-only controls are put to a person — never assumed by a scanner.

Fixes it, then proves the fix.

Remediation changes real host state with a stored rollback, then re-scans on the identical yardstick — 50.3% to 80.1% this run, measured, not promised.

Reversible by design.

Every change is backed up before it's made and restorable to exactly where we found it, so hardening never becomes the outage that locks you out.

The expert's outcome, as software.

A $50k consultant walks out at the end of the engagement; this collapses that quarter of dread into an afternoon and is still here at renewal.

Built for the signature you carry.

Accuracy, signed evidence, and chain of custody are legal protection under self-attestation — not audit-prep polish — because the SPRS affirmation is yours to defend.

ForteFide · FIND LIVE

Discovery

Find every computer that touches CUI — before an assessor finds the one you missed.
Who
The IT lead at a defense sub who isn't even sure how many machines are in scope.
How
A network sweep, an Active Directory pull, or a remote-gateway reach into a site you can't touch directly — and nothing gets installed on your endpoints.
What
We sweep your network, read the operating system off every host, and hand back the in-scope list.
Why
An assessment covers every asset that stores, processes, or transmits CUI. Miss one and the whole score is a false claim you signed your name to.
Result
This run found 29 computers and put 22 in scope — a boundary you can defend, not a guess.
The advantage
Sweeps the network and reads the OS off every host to hand back a defensible in-scope boundary, so the assessment covers every asset that touches CUI.
Doing it unguided
You scope from memory and miss a host that stores CUI, so the SPRS score you sign leaves an in-scope asset out entirely — a false claim under 31 U.S.C. 3729 that you carry personally.
f01a-configured
ForteFide

Discovery

1
Configured
Point it at the network. That's the whole setup.
  • One field, pre-filled with a typical example
  • Sweep the network, pull Active Directory, or reach through a gateway
  • Nothing to push to your computers
f01d-ad
ForteFide

Discovery

1
Option · Active Directory
Option · Active Directory
f01e-gateway
ForteFide

Discovery

1
Option · Remote gateway
Option · Remote gateway
f01b-inaction
ForteFide

Discovery

1
In action
One sweep names every machine and what it runs.
  • Finds each live host on the range
  • Tells Windows from Linux, per computer
  • Flags the gateway that reaches a site you can't get to directly
f01c-result
ForteFide

Discovery

1
Result
A scope a C3PAO will accept.
  • 29 computers found, 22 in scope this run
  • Every host tagged with its operating system
  • Gateway-reached hosts marked — nothing hides off-list
f01c-hood
ForteFide

Discovery

1
Hood — the engine
Pop the hood: ARP, LDAP, and port fingerprints under the glass.
  • ARP + LDAP + port discovery, with an NTLM-to-SIMPLE bind fallback for hardened directories
  • Domain controllers detected and kept in scope
  • Each host's OS carried forward so the scan never has to re-guess it
ForteFide · SET UP LIVE

Secure Access

A temporary, least-privilege key onto each machine — gone the moment we're done.
Who
The admin who keeps a file of vendors that pushed accounts they didn't advertise.
How
Per-OS credentials, strongest auth the host allows, and a teardown that leaves a clean diff.
What
We create one predictable, documented service account per host, authenticate with a certificate or key, and remove it on command.
When
Certificates rotate every 30 days, automatically — no stale credential left behind.
Why
You can't run an authenticated scan without access — and you can't keep a standing vendor account without failing your own access-control controls.
Result
Access strong enough to read all 110 controls, and gone when the scan is — the teardown diff is yours to check.
The advantage
Establishes a temporary, least-privilege key onto each machine and removes it when done, so you can run an authenticated scan without leaving a standing account behind.
Doing it unguided
You either can't run an authenticated check and end up scoring off a spreadsheet, or you leave a standing vendor/admin account that fails your own least-privilege control (AC.L2-3.1.5) an assessor will find.
f02a-configured
ForteFide

Secure Access

1
Configured
Give it admin once. It sets up its own key.
  • Enter credentials per operating system
  • It picks the strongest authentication that host supports
  • The account is named predictably and documented
f02d-permissions
ForteFide

Secure Access

1
What it needs
Cert, key, or password — strongest the host allows.
  • Tier 1 certificate on Windows (incl. Server 2012 R2) and Linux
  • Tier 2 key as the fallback
  • Password used only to bootstrap, then eliminated
f02b-inaction
ForteFide

Secure Access

1
In action
Certificate first, key second, password last.
  • Derives an SSH certificate authority from your license
  • Issues a 30-day certificate to each host
  • The password path closes once the keys are in place
f02c-result
ForteFide

Secure Access

1
Result
Done means gone.
  • Teardown removes the account, its sudoers rule, and its keys
  • Prepare-then-teardown leaves a clean diff on the host
  • You free a seat the moment you're finished with a machine
f02c-hood
ForteFide

Secure Access

1
Hood — the engine
The admin sees the whole account lifecycle.
  • fortefide-svc: create → use → teardown, fully auditable
  • CA derived from license HKDF; the CA private key is wiped from memory after issuing
  • sshd edits captured with rollback, a port-22 smoke test, and auto-revert if the host goes dark
ForteFide · CHECK LIVE

Compliance Scan

All 110 controls, checked against the real machine — no agent, no guesswork.
Who
The buyer whose only compliance artifact so far is a consultant's spreadsheet.
How
Authenticated over the key from setup, reading real configuration, with no persistent agent left behind.
What
We run an authenticated check of all 110 CMMC Level 2 controls on every in-scope host.
Why
A spreadsheet says what you intended. An authenticated scan says what the machine is actually doing — which is exactly what the assessor tests.
Result
78 of the 110 we check automatically; the other 32 only a human can answer, and we say which is which.
The advantage
Checks all 110 controls against the real machine with no agent — 78 automatically and 32 flagged for a human — so the score reflects what the host is actually doing.
Doing it unguided
Hand-checking 110 controls across a fleet, you sample a few machines and assume the rest, so your score reflects what you intended rather than what the machines actually do.
f03a-configured
ForteFide

Compliance Scan

1
Configured
Nothing to configure. It already knows the 110.
  • All 110 Level 2 controls built in
  • Runs over the key established at setup
  • Every in-scope host, one button
f03b-inaction
ForteFide

Compliance Scan

1
In action
Reads the real setting on the real machine.
  • Authenticated — not a port-scan guess
  • Firewall state, audit policy, lockout, encryption: actual values
  • No agent installed, nothing left running
f03c-hood
ForteFide

Compliance Scan

1
Hood — the engine
The admin sees per-control TEST evidence.
  • Control-by-control determination: MET / NOT MET
  • The scanner itself is an assessment object (RA.L2-3.11.2)
  • Reads the OS Discovery already captured — never re-asked
ForteFide

Detailed in the walkthrough alongside.

ForteFide

Compliance Scan

1
Result
78 checked for you, 32 flagged for a person.
  • 78 of 110 auto-checked on both Windows and Linux
  • 32 are policy, training, and physical — human-only, never faked
  • No control silently marked as passing
ForteFide · RESULTS LIVE

Results & Asset Scorecards

One score you understand in a second — and the engine underneath if you want it.
Who
Larry, at 6pm, asking one question: am I OK?
How
A single score, plain-English checks, a card per host — with control IDs and SPRS weights one keystroke under the hood.
What
We turn the scan into a plain-English score — per computer and per rule family.
Why
A number between -203 and 110 means nothing after a long day. "You're not ready to bid yet, here's what to fix" means everything.
Result
This fleet came in at 50.3% — 39 of 110 requirements met — with the exact gaps named, not buried.
The advantage
Turns the raw -203-to-110 SPRS math into a plain 'ready or not, here's what to fix,' with every gap named, so the number is one you can reconstruct and defend.
Doing it unguided
You tally the SPRS score by hand and mis-weight it — the DoD Annex A weights are fixed per control, not a criticality guess — and post a number you can't reconstruct under review.
f04a-result
ForteFide

Results & Asset Scorecards

1
Configured
It builds itself from the scan. You just read it.
  • One score at the top
  • A card for every computer
  • Plain words, no control codes on the glass
2
The checks
The checks
3
By family
By family
4
Per host
Per host
f04a-result
ForteFide

Results & Asset Scorecards

1
In action
Green, yellow, red — and what each one means.
  • A breakdown per rule family
  • An asset scorecard per host
  • Every check written in language you can act on
f04a-result
ForteFide

Results & Asset Scorecards

1
Result — the score
Know exactly where you stand.
  • 50.3% baseline this run
  • 39 of 110 requirements fully met
  • The failing rules named — not hidden in a log
f04a-hood
ForteFide

Results & Asset Scorecards

1
Hood — the engine
Ctrl+Alt+Shift+V — the console the admin lives in.
  • Control IDs (AC.L2-3.1.1, AU.L2-3.3.1, …) per host
  • SPRS weights (5 / 3 / 1) straight from DoD Annex A
  • Same data, expert depth — and nothing on Larry's glass changed
ForteFide · ATTEST LIVE

Attestation

The 32 questions only a human can answer — asked in plain English, captured as evidence.
Who
The buyer who dreads the policy, training, and physical controls a scanner can't judge.
How
One guided question per control, in plain English, captured into the evidence package.
What
For the 32 controls no scan can determine, we ask you the question and record your answer as evidence.
When
Your affirmation runs on a yearly clock — the signature has to stay current.
Why
A false "yes" on a policy control carries the same False Claims Act exposure as a false scan result. We make you answer it honestly, on the record.
Result
32 human-only controls answered and recorded — no scanner pretending it knows.
The advantage
Puts the 32 human-only controls to a person in plain English and records the answers as evidence, so policy and physical controls are attested honestly, on the record.
Doing it unguided
You let a scanner assume the 32 human-only controls and attest 'yes' to policy, training, and physical controls no tool can verify — a false 'yes' carries the same FCA exposure as a false scan.
f05b-esign-inaction
ForteFide

Attestation

1
In action — e-sign, under FCA penalty
Answer in plain English. It records it.
  • Asks plainly what the control needs
  • Your answer becomes signed evidence
  • No control left blank
f05a-attestation
ForteFide

Attestation

1
Result
Honest answers, on the record.
  • 32 attestation items captured
  • Nothing auto-marked MET that a machine can't prove
  • Your yearly affirmation backed by real answers
f05a-hood
ForteFide

Attestation

1
Hood — the engine
The admin sees the determination logic.
  • The always-applicable set — AT, PS, IR — can never be N/A'd away
  • The SSP (CA.L2-3.12.4) is the eligibility gate, not a scored line
  • Two clocks tracked: signature age and evidence age
ForteFide

Detailed in the walkthrough alongside.

ForteFide

Attestation

1
Configured
It knows which 32 need you.
  • Training, personnel, physical, incident response — the human controls
  • One question at a time
  • No jargon in the question
ForteFide · PROVE LIVE

Signed Evidence

Evidence a C3PAO can verify offline — signed, hashed, and yours.
Who
The buyer who's been burned by a folder of undated screenshots.
How
Ed25519 signatures and SHA-256 hashes, verifiable offline and inside an air-gapped enclave.
What
We package the scan and attestations into evidence, sign every artifact, and hash it so tampering shows.
Why
Under self-attestation you carry the FCA liability personally. Signed, traceable evidence is your defense; a screenshot folder is not.
Result
Every artifact signed and hashed, verifiable offline — evidence built to be checked without taking our word for it.
The advantage
Produces a signed, hashed evidence package a C3PAO can verify offline, so under self-attestation you hold the traceable record that defends the score.
Doing it unguided
Your evidence is a folder of undated screenshots a C3PAO or DIBCAC reviewer can't trace or trust, so you have nothing to walk the chain with when the score is questioned.
f06a-evidence
ForteFide

Signed Evidence

1
Result
Verifiable offline, inside your enclave.
  • A C3PAO checks it with no internet
  • Any tampering breaks the hash
  • Ready for the 6-year retention duty
2
What's inside
What's inside
f06a-hood
ForteFide

Signed Evidence

1
Hood — the engine
The admin traces the chain.
  • The bundled public key is signed inside the payload — so the key itself is authenticated, not just appended
  • Every handler and action logged, integrity verifiable by hash
  • Hashing aligns to the 32 CFR 170.17 retention requirement
ForteFide

Detailed in the walkthrough alongside.

ForteFide

Signed Evidence

1
Configured
It packages itself from the run.
  • Pulls in the scan and the attestations
  • Nothing assembled by hand
  • Built for the C3PAO, not for show
ForteFide

Detailed in the walkthrough alongside.

ForteFide

Signed Evidence

1
In action
Every artifact signed and hashed.
  • Ed25519 signature over the manifest
  • SHA-256 hash on each artifact
  • A chain of custody from scan to file
ForteFide · FIX LIVE

Remediation

The part nobody else does: we fix the misconfigurations — reversibly, with you in control.
Who
The buyer weighing us against Vanta, Drata, or a $50k consultant.
How
A dark severity console — critical, high, medium, low — and nothing runs until you authorize it. Reversibility is the bar every automated fix is written to.
What
We fix the misconfigurations that are safe to fix, re-check every one afterwards, and name the ones that still need a person — you authorize what runs.
Why
Every competitor finds the gap and hands it back. They monitor. We fix — a quarter of consultant time collapsed into an afternoon.
Result
Of 1095 problems this run, we can auto-fix 555 and flag the other 540 for a person. We never claim to fix all 110.
The advantage
Fixes the misconfigurations that are safe to fix — reversibly, with a stored rollback — and flags the rest for a person, collapsing consultant time into an afternoon.
Doing it unguided
A hand-run firewall or SSH change locks you out of the box with no rollback, or you 'fix' a control the check still fails and never know — a silent success that leaves the gap open under your signature.
f07a-safe-default
ForteFide

Remediation

1
What we offer by default
What we offer by default
f07a-configured
ForteFide

Remediation

1
Configured — everything selected
Pick what to fix. Critical stays off until you say so.
  • Severity checkboxes: critical, high, medium, low
  • Critical unchecked by default
  • Danger mode is deliberate — a decision, not a trap
f07b-inaction
ForteFide

Remediation

1
In action
It backs up, changes, then re-checks — each one.
  • A pre-change backup captured first
  • Applies the fix on the host
  • You approve each change before it runs
f07c-result
ForteFide

Remediation

1
Result
555 fixable now, 540 flagged for a human.
  • 1095 problems found across 22 computers
  • 555 safe to auto-fix
  • 540 need a person — and we tell you which
f07a-hood
ForteFide

Remediation

1
Hood — the engine
The admin sees the exact command before it runs.
  • Per-control command visible up front — nothing the assessor hasn't seen
  • sshd and firewall edits captured with auto-revert on failure
  • Never applies a change that would break its own re-scan
ForteFide

Detailed in the walkthrough alongside.

ForteFide

Remediation

1
Options
Reversible by design.
  • Every change carries a stored rollback
  • Roll back one host or the whole fleet
  • An on-machine failsafe if a host ever goes dark
ForteFide · REPORT LIVE

Prove the Fix

Same 110, same yardstick — proof the score moved, not a promise.
Who
The CISO who needs a before-and-after they can put in front of a prime.
How
The same authenticated scan, the same controls, the same hosts — only the fixes have changed.
What
We re-run the exact same 110-control scan and show the measured lift.
Why
A fix you can't measure isn't evidence. The identical yardstick before and after is what makes the improvement defensible.
Result
Baseline 50.3% climbs to 80.1% after the fixes, measured on the identical scan.
The advantage
Re-runs the identical 110-control scan after remediation, so the improvement is proven on the same yardstick — 50.3% to 80.1% this run — not asserted.
Doing it unguided
You assert the fix worked without re-measuring on the identical yardstick, so an improvement you can't prove becomes an unsupported claim on the affirmation you signed.
f08a-inaction
ForteFide

Prove the Fix

1
In action
Re-checks the machine, not the intent.
  • Reads the real settings again
  • Scores against the same yardstick
  • Every fixed control re-verified
f08b-result
ForteFide

Prove the Fix

1
Result — the lift
Proof, not a promise.
  • Baseline 50.3%
  • After fixes: 80.1%
  • A measured lift of +29.8 points points
f08b-hood
ForteFide

Prove the Fix

1
Hood — the engine
The admin sees per-control before and after.
  • MET / NOT MET delta on every control
  • The SPRS score movement, control by control
  • The fleet stays prepared for the next pass — no re-setup
f08c-postrem-evidence
ForteFide

Prove the Fix

1
Evidence, re-signed
Evidence, re-signed
f08c-hood
ForteFide

Prove the Fix

1
Hood — evidence re-signed
The admin sees per-control before and after.
  • MET / NOT MET delta on every control
  • The SPRS score movement, control by control
  • The fleet stays prepared for the next pass — no re-setup
ForteFide

Detailed in the walkthrough alongside.

ForteFide

Prove the Fix

1
Configured
Same scan, one button.
  • The identical 110 controls
  • Same hosts, same authentication
  • Nothing changed but the fixes
ForteStrike · AUTHORIZATION LIVE

You can't test what you never authorized

A signed Rules-of-Engagement gate that has to say YES before a single packet leaves the box — and denies everything it wasn't told to touch.
Who
The security lead who's been told to "just run a pentest" and knows that sentence carries no legal cover.
How
Fail-safe DENY on an allow-list, exploit and lockdown behind separate switches that default off, per-OS credentials bound to the engagement, and an append-only log with the operator's and the signatory's names on it.
What
We refuse to send a single packet until a signed scope names the hosts we may touch — and we deny everything it doesn't name.
Why
Scanning a host you weren't authorized to touch is a federal computer-crime question, not a scheduling one. A hand-run tool pointed at "the network" leaves you no way to prove where you stopped.
Result
Every engagement runs behind a signed, fail-safe-DENY scope, so the assessment stays authorized and leaves an immutable audit trail an assessor can read.
The advantage
Nothing runs until a signed, fail-safe-DENY scope says yes, and the high-impact phases sit behind ROE switches that default off, so every action is authorized and logged.
Doing it unguided
You point a hand-run pentest tool at 'the network' with no signed scope and wander onto a host you weren't authorized to touch — a CFAA exposure with no log to prove you didn't.
fs9a-roe-configured
ForteStrike

You can't test what you never authorized

1
Configured — the ROE
Sign the scope before anything can move.
  • Fail-safe DENY: only named hosts are reachable — unlisted is blocked, not 'probably fine'
  • Exploit and Lockdown gated behind separate ROE switches, both default OFF
  • Per-OS credentials attached up front so Windows and Linux are reached under the correct accounts
fs9b-scope-loaded
ForteStrike

You can't test what you never authorized

1
Scope loaded
An authorized attack you can defend in writing.
  • Append-only audit log (NIST 800-171 AU family) proves what was and wasn't touched
  • CFAA posture: the allow-list is documented, signed, and enforced in code
  • You control the blast radius — recon-only, or full exploit-and-lock, by switch
ForteStrike

Detailed in the walkthrough alongside.

ForteStrike

You can't test what you never authorized

1
In action
The gate holds on every phase, not just the first.
  • Any target or action outside scope is refused and written to the log
  • No telemetry, no external calls — the run stays on your network
  • Operator and signatory are bound to the engagement, so every action has a name on it
ForteStrike · RECON LIVE

It finds the hosts your inventory forgot

Network, Active Directory, and jump-host discovery that surfaces the machines an attacker would find — including the quiet ones with no open port.
Who
The engineer whose asset inventory was last accurate the day it was written.
How
A TCP-connect sweep plus an ARP pass, so machines that are up with no open port still surface, each carrying its MAC and tagged silent. No Npcap, no special drivers.
What
We sweep the range, pull Active Directory, reach through a jump host, and hand back the machines that actually answer.
Why
An attacker doesn't consult your inventory. The host nobody remembers — no ticket, no owner, still plugged in — is the one they find first, and it's the one your test skips.
Result
Surfaces the reachable hosts your inventory forgot — the machines an attacker finds first — so nothing exposed goes untested.
The advantage
Network, Active Directory, and jump-host discovery surfaces the reachable machines your inventory forgot, so the attacker's-eye assessment covers what's actually exposed.
Doing it unguided
You test only the hosts your inventory remembers and leave the forgotten, exposed machine — the one an attacker finds first — untested.
fs10a-recon-config
ForteStrike

It finds the hosts your inventory forgot

1
Configured
Point it at the range; it does the enumeration.
  • TCP-connect sweep plus an ARP pass — no Npcap, no special drivers
  • Active Directory (LDAP/NTLM) and jump-host (SSH) discovery included
  • Runs async with live progress so a long sweep never looks frozen
fs10b-recon-result
ForteStrike

It finds the hosts your inventory forgot

1
Result — hosts found
Discovery becomes scope with one click.
  • Found hosts feed the allow-list directly — no CSV, no retyping
  • Your real attack surface, not the inventory's optimistic version
  • Ready to hand straight to the scan phase
ForteStrike

Detailed in the walkthrough alongside.

ForteStrike

It finds the hosts your inventory forgot

1
In action
Even the silent hosts show up.
  • ARP finds machines that are up but expose no open port
  • Every host carries its MAC; ARP-only hosts are tagged 'silent'
  • AD and jump-host paths reveal the pivot routes an attacker would use
ForteStrike · SCAN LIVE

Every open port gets a name and a CVE

Service-version fingerprinting with CVE enrichment — up to 8 hosts at once — so you see the specific vulnerabilities on the specific services you're running.
Who
The lead staring at a list of open ports, deciding which ones actually matter.
How
nmap service detection at intensity 7 across a superset that includes WinRM, RDP, SMB and RPC, with vulners, SSL-cipher, SSL-cert, HTTP and SMB scripts per host, up to eight hosts at once.
What
We fingerprint the service behind every open port, match its version to the CVEs that hit it, and rank what we find by what it exposes.
Why
"445 is open" is not a finding — the version answering on it is. Guess wrong and you spend the quarter chasing noise while the genuinely exploitable service stays open.
Result
192 findings named across the fleet, 27 of them critical, each tied to the exact service and CVE that exposes it.
The advantage
Service-version fingerprinting with CVE enrichment names every open port and the exposure behind it, so you see which findings are real, not just which ports are open.
Doing it unguided
You eyeball open ports without version-plus-CVE correlation and misjudge which exposures matter, chasing noise while a genuinely exploitable one sits open.
fs11a-scan-inaction
ForteStrike

Every open port gets a name and a CVE

1
In action — scanning
Versions become CVEs.
  • Top CVE + CVSS placed right in the finding title; all CVEs listed
  • Public-exploit availability flagged on each finding
  • Slow host times out to a fast port-only pass — the run keeps moving
fs11b-scan-results
ForteStrike

Every open port gets a name and a CVE

1
Result — 115 findings, CVE-attributed
Ranked, attributed, honestly labeled.
  • Version-inferred CVEs marked 'confirm' — not asserted as proven
  • Severity-ranked so the worst service is the first thing you see
  • Feeds directly into the exploit phase for confirmation
ForteStrike

Detailed in the walkthrough alongside.

ForteStrike

Every open port gets a name and a CVE

1
Configured
Explicit ports, real service detection.
  • nmap -sV --version-intensity 7 over a superset incl. WinRM, RDP, SMB, RPC
  • vulners, SSL-cipher, SSL-cert, HTTP and SMB scripts run per host
  • Up to 8 hosts scanned in parallel
ForteStrike · EXPLOIT LIVE

Don't take our word for it. We attack it.

A config scanner says 'looks vulnerable.' ForteStrike runs Metasploit's non-destructive check and proves it — then captures the raw evidence.
Who
The buyer holding a scanner report full of "potentially vulnerable" and unable to act on any of it.
How
A check, never a payload. Detonation stays manual and per-finding, behind an ROE switch that's off until you turn it on, and an inconclusive check labels itself instead of rounding up.
What
We run Metasploit's non-destructive check against the finding and let the result set the severity.
Why
They find and leave. A config scanner's "looks vulnerable" is a guess you have to defend in the room; confirmed exploitable is a fact — and here only confirmed earns CRITICAL.
Result
Against 115 detected findings on the Metasploitable2 target, 5 were Metasploit-confirmed exploitable, with the raw exploit evidence attached — proof, not a maybe.
The advantage
Runs Metasploit's non-destructive check against the finding, so an exposure is confirmed exploitable with attached evidence instead of a config scanner's guess.
Doing it unguided
You accept a config scanner's 'looks vulnerable' as fact and either over-report findings you can't prove or dismiss a truly exploitable hole — guessing where proof was available.
fs12a-exploit-confirmed
ForteStrike

Don't take our word for it. We attack it.

1
Result — msf-confirmed criticals
A CRITICAL list you can actually defend.
  • Every critical is attacker-proven, not scanner-assumed
  • Raw Metasploit evidence attached to the finding for the assessor
  • No overclaim: 5 confirmed out of 115 findings tells the true story
ForteStrike

Detailed in the walkthrough alongside.

ForteStrike

Don't take our word for it. We attack it.

1
Configured
Confirmation, gated and non-destructive.
  • Metasploit 'check' per finding — proof of exposure, not a payload
  • CVE map plus a service-signature map for CVE-less services
  • Gated behind the allow_validation ROE switch — off until you authorize it
ForteStrike

Detailed in the walkthrough alongside.

ForteStrike

Don't take our word for it. We attack it.

1
In action
Confirmed exposure earns CRITICAL — and only confirmed does.
  • A vulnerable result is elevated to CRITICAL with raw check output captured
  • Never auto-fires an exploit — detonation stays manual, per-finding
  • Inconclusive checks fall back to detection-confirmed and label themselves as such
ForteStrike · REPORT LIVE

The report writes itself — every scan, every time

A formed pentest deliverable auto-saved on every run: exec summary, priority remediation, per-host findings, and the Metasploit evidence behind each critical.
Who
The buyer who paid a consultant and waited three weeks to read what the network looked like on day one.
How
Formed HTML and structured JSON auto-saved on every scan and exploit, a 12-field schema on every finding, downloadable as branded PDF, HTML or JSON whenever you need it.
What
We write the deliverable on every run — exec summary, priority remediation, per-host findings, and the evidence behind each critical.
Why
A report assembled by hand after the fact drifts from what actually ran. The assessor reads the report; if it doesn't match the engagement, the engagement may as well not have happened.
Result
A formed pentest deliverable auto-saves on every run, so the report an assessor reads matches exactly what was tested.
The advantage
A formed pentest deliverable — exec summary, priority remediation, and detail — auto-saves on every run, so the record always matches what was tested.
Doing it unguided
You assemble the deliverable by hand after the fact and the record drifts from what actually ran, so the report an assessor reads doesn't match the engagement.
fs13a-report
ForteStrike

The report writes itself — every scan, every time

1
Result — the deliverable
The consultant's report, on demand.
  • Download as branded PDF, HTML, or JSON whenever you need it
  • Findings sorted by host and by priority automatically
  • Fresh on every run — never a three-week-old snapshot
ForteStrike

Detailed in the walkthrough alongside.

ForteStrike

The report writes itself — every scan, every time

1
Configured
Auto-saved, no export step to forget.
  • Formed HTML + structured JSON written on every Scan and Exploit
  • 12-field finding schema on every entry — assessor-grade, not a bullet list
  • Built-in report is the default deliverable; SysReptor is optional
ForteStrike

Detailed in the walkthrough alongside.

ForteStrike

The report writes itself — every scan, every time

1
In action
Written for three readers at once.
  • Exec-summary risk rating for the board
  • Priority remediation list for the engineers
  • Metasploit evidence section for the assessor
ForteStrike · RETEST LIVE

Fixed on paper, or closed to an attacker?

Re-run the same engagement after remediation and ForteStrike diffs it — fixed, new, and persisting — because a control only counts as closed when it can no longer be exploited.
Who
The CISO whose team reported the finding remediated, with no way to know whether that's true.
How
Every run is snapshotted under its engagement name, so re-running that name triggers the diff. No re-scoping; the baseline is remembered.
What
We re-run the same engagement after the fix and diff it into fixed, persisting, and new.
When
After every remediation cycle — the baseline is already there, so the retest costs one click.
Why
"Fixed on paper" and "closed to an attacker" are two different claims, and under self-attestation you sign the second one. A control is closed when it can no longer be exploited — not when a ticket closed.
Result
On retest, 27 findings independently confirmed closed, 4 newly surfaced, and 165 still open — compliant-on-paper vs closed-to-an-attacker, measured.
The advantage
Re-runs the same engagement after remediation and diffs it into fixed, new, and persisting, so you know what's closed to an attacker, not just fixed on paper.
Doing it unguided
You assume remediation closed the finding and never re-attack, so 'fixed on paper' and 'closed to an attacker' quietly diverge and you attest to the wrong one.
fs14a-retest-diff
ForteStrike

Fixed on paper, or closed to an attacker?

1
Result — the diff
Compliant-on-paper vs closed-in-reality.
  • Per-finding retest status on the deliverable
  • Independent proof your remediation actually held
  • The honest measure of progress between two dates
ForteStrike

Detailed in the walkthrough alongside.

ForteStrike

Fixed on paper, or closed to an attacker?

1
Configured
Every engagement is a reusable baseline.
  • Each run is snapshotted under its engagement name
  • Re-run the same name after a fix to trigger the diff
  • No re-scoping — the baseline is remembered
ForteStrike

Detailed in the walkthrough alongside.

ForteStrike

Fixed on paper, or closed to an attacker?

1
In action
Three columns that end the argument.
  • Fixed: the exploit no longer confirms — closed to an attacker
  • Persisting: marked 'remediated' but still reachable
  • New: anything that opened since the last run
ForteLock · ACTIVE-PROTECT LIVE · mode of ForteStrike

ForteStrike finds the lock. ForteLock throws it.

It adopts your approved exposure as the standing allowlist — the one baseline everything new is measured against.
Who
The admin who set the firewall baseline by hand a year ago and can't now say which openings were ever approved.
How
A baseline scan adopts the open services as the allowlist, gated behind the active-protect and remediation ROE toggles. Containment only — no exploitation in this loop.
What
We adopt your approved exposure as a standing allowlist, then measure everything that opens afterwards against it.
When
Continuously. This is a standing guard, not a one-shot engagement.
Why
Drift with no reference point isn't drift — it's just the network. Until approved is written down, a new opening looks exactly like an old one.
Result
Adopts your approved exposure as a 6-service standing allowlist — the single baseline every later sweep is judged against.
The advantage
Adopts your approved exposure as a standing allowlist, giving drift a single reference baseline so any new opening stands out immediately.
Doing it unguided
You set a firewall baseline by hand and lose track of which exposure was actually approved, so drift has no reference point and new openings look normal.
fs15a-guard-config
ForteLock

ForteStrike finds the lock. ForteLock throws it.

1
Configured — active protect
Your approved exposure becomes the rule.
  • A baseline scan adopts open services as the allowlist
  • Gated by active_protect + allow_remediation ROE toggles
  • Containment only — no exploitation, no Metasploit in this loop
fs15b-guard-armed
ForteLock

ForteStrike finds the lock. ForteLock throws it.

1
In action — armed
Known-good, written down and enforced.
  • Approved services are recorded and never touched
  • Every future sweep is measured against this baseline
  • Distinct from an offensive run — this is a standing guard, not a one-shot
ForteLock

Detailed in the walkthrough alongside.

ForteLock

ForteStrike finds the lock. ForteLock throws it.

1
Result
A boundary that holds when you're not looking.
  • The approved posture becomes the continuously enforced rule
  • New exposure now has a definition to violate
  • Foundation for automatic containment
ForteLock · CONTAINMENT LIVE · mode of ForteStrike

A new port opens. It's shut in one cycle.

Every 300 seconds it sweeps the full range, and any exposure that isn't on the allowlist gets a reversible DROP — unattended, on Windows and Linux alike.
Who
The team whose alerting works perfectly and whose exposure window is still measured in days.
How
A 1-65535 sweep diffed against the allowlist each cycle, containing Windows with netsh and Linux with iptables in the same pass. Every DROP reverses cleanly, and approved services are never touched.
What
We sweep the full port range every 300 seconds and shut anything that isn't on the allowlist.
When
Every 300 seconds by default, and configurable.
Why
They alert and wait for a human. Between a Friday review and Monday morning a new port stays open all weekend — and closing it by hand risks dropping a service you needed, with no clean way back.
Result
Every 300 seconds it re-sweeps the full range and shuts any off-allowlist exposure with a reversible DROP (ok=True) — contained in one cycle, never a one-way change.
The advantage
Every 300 seconds it re-sweeps the full range and contains any off-allowlist exposure with a reversible DROP, shutting a new port in one cycle without a one-way change.
Doing it unguided
A new port opens between your manual reviews and stays open for days, and if you do slam it shut by hand you may drop a service you needed with no clean way back.
fs16a-containment-events
ForteLock

A new port opens. It's shut in one cycle.

1
Result — contained
Contained in a cycle, reversible on command.
  • Exposure window bounded to one 300s sweep instead of 'until noticed'
  • Live-fire validated: caught in-list and out-of-list rogue ports in one cycle
  • Every DROP undoes cleanly — result was ok=True, approved services preserved
ForteLock

Detailed in the walkthrough alongside.

ForteLock

A new port opens. It's shut in one cycle.

1
Configured
Set the cadence; walk away.
  • Full-range 1-65535 sweep every 300s, configurable
  • Diffed against the approved allowlist each cycle
  • One sweep contains Windows (netsh) and Linux (iptables) correctly
ForteLock

Detailed in the walkthrough alongside.

ForteLock

A new port opens. It's shut in one cycle.

1
In action
They alert and wait. We drop it.
  • New unapproved port gets a reversible DROP, not just a notification
  • Approved services are never touched
  • Every containment writes a ledger entry and fires an alert
ForteLock · EVIDENCE LIVE · mode of ForteStrike

Containment you can hand to an assessor

Every containment ships as control-mapped evidence with chain of custody — so 'we stopped it' becomes a defensible, mapped record.
Who
The engineer who stopped the exposure and then couldn't prove it to the assessor.
How
Each containment lands in the evidence package mapped to SC.L1-3.13.1, CM.L2-3.4.7 and SI.L2-3.14.6, cross-walked to NIST 800-53 SC-7 / SI-4 and ATT&CK T1571. Append-only, no telemetry, air-gappable.
What
We write every containment as control-mapped evidence carrying its own chain of custody.
Why
Under self-attestation you sign the score, and accuracy is the defense. An action you can't map to a control and can't trace to its origin counts for nothing when someone asks for the record.
Result
Each containment ships as control-mapped evidence (SC.L1-3.13.1 / CM.L2-3.4.7 / SI.L2-3.14.6) with chain of custody, so the protection itself becomes assessor-ready proof.
The advantage
Every containment ships as control-mapped evidence with chain of custody, so 'we stopped it' becomes proof an assessor can verify against SC.L1-3.13.1 / CM.L2-3.4.7 / SI.L2-3.14.6.
Doing it unguided
You stop the exposure but can't map the action to a control or prove chain of custody, so the containment counts for nothing when an assessor asks for the record.
fs17a-evidence-chain
ForteLock

Containment you can hand to an assessor

1
Result — assessor-ready evidence
Defensible where it matters most.
  • Chain of custody traceable to origin — not a bare screenshot
  • Directly supports the boundary and monitoring controls an assessor examines
  • Under self-attestation, accuracy IS the FCA defense — mapped evidence backs the score
ForteLock

Detailed in the walkthrough alongside.

ForteLock

Containment you can hand to an assessor

1
Configured
Evidence is a byproduct, not a chore.
  • Each containment written to fortelock_containment.json in the evidence package
  • Mapped to SC.L1-3.13.1, CM.L2-3.4.7, SI.L2-3.14.6
  • Cross-walked to NIST 800-53 SC-7 / SI-4 and ATT&CK T1571
ForteLock

Detailed in the walkthrough alongside.

ForteLock

Containment you can hand to an assessor

1
In action
Every action carries its own record.
  • Ledger captures what, when, which host, and the rule applied
  • Records that approved services were preserved through the action
  • Append-only, no telemetry, air-gappable
DenseSense · CUI DISCOVERY IN PROGRESS · landing

DenseSense — Find the CUI

The fourth Full-Suite product, landing now: find where the controlled work actually lives — by the government's markings and your declared documents — before the assessment grades the boundary.
Who
The compliance lead about to grade a boundary nobody has actually drawn.
How
Zero-guess: we read the markings, match copies of the documents you declared controlled, and — without opening a single drawing — flag the unmarked files sitting beside marked ones. Every file we cannot open is listed with its reason. Silence is never reported as clean.
What
Before we grade a single control, DenseSense walks the trusted fleet and finds where the controlled work actually lives — by the government's own markings, by the documents you have declared controlled, and by the folders that hold them.
When
Continuously. Acquisition in progress, forever — the fleet is re-swept as the work moves, because CUI is a moving target.
Why
A score is only honest against the right boundary. Grade the wrong scope and every control you pass is measured against the wrong thing — the scoping gap that turns a clean-looking number into False Claims Act exposure. They are still asking where to look. DS already found it.
Result
A map of where your CUI concentrates and the unmarked drawings sitting beside controlled paperwork — so the baseline scan that follows grades the real boundary, not a guess.
In progress · landing. These are real captures of the product run against a staged demonstration corpus (a fictional machine shop) — not a customer and not the live fleet. DenseSense does not claim detection coverage or accuracy it has not measured: a search that comes back empty is not proof there is nothing there.
d9-ds-config
DenseSense

DenseSense — Find the CUI

1
Configured
Point it at scope — the shares that hold your work, and the customers who send you government work
d9-ds-teach
DenseSense

DenseSense — Find the CUI

1
Teach it
Teach it your own controlled forms — drop a doc, paste text, or a pattern; it never keeps the file
d9-ds-result
DenseSense

DenseSense — Find the CUI

1
Result
Where the CUI concentrates, and the unmarked drawings sitting beside marked paperwork
  • DS already found it — where your controlled work actually lives, while they are still asking where to look
  • Unmarked drawings flagged where they sit beside marked, controlled paperwork — never opened, never guessed
  • Every file type we could not open is declared, with the reason — silence is a listed gap, not a clean bill
  • Acquisition in progress, forever — a search that comes back empty is not proof there is nothing there
Optional add-on · not part of the Full Suite WIRED · assess-only

DenseAIArmour — assess your AI posture

DenseAIArmour is bought and licensed separately, after the fact — it is not one of the four Full Suite products. It walks a host's AI estate read-only and hands back a signed record of what it found. It assesses posture; it does not secure or seal AI. The console is wired and the screens below are authentic captures of the tool itself.

What it does

Host-local, credentialed, read-only enumeration of local models, vector stores, and agent / MCP configs — metadata endpoints only, never inference and never a document read.

What it does not claim

Assess-only. It reports Observed / Attested / Not assessed and states what it did not reach, rather than implying a clean bill. It does not protect or seal an AI system.

DenseAIArmour · DISCOVERY WIRED · assess-only

The AI nobody assessed

Point it at a host and it walks the AI estate the host is actually running — local models, vector stores, agent and MCP configs — read-only, and hands back a signed record of what it found.
Who
The security lead at a shop where engineering stood up local LLMs and RAG stores faster than anyone could review them, and who has no inventory of what AI is running or how exposed it is.
How
It connects over SSH or WinRM under the operator's own credential, enumerates the AI services on the host's own loopback, and probes metadata endpoints only — never inference, never a document read.
What
A host-local, credentialed, read-only assessment of the AI estate — what services are up, whether they demand a credential, what an agent is allowed to do.
When
On demand, or scheduled. It spends no model compute, writes nothing to the host, and phones home to nothing — air-gap capable.
Why
None of this shows up in a network scan and none of it has an owner. An unauthenticated model or a wide-open vector store is a breach waiting to be found, and today no tool is even looking.
Result
A per-host posture: what was observed, what is a gap, and what could not be assessed — stated honestly, never over-claimed.
g20a-configured
DenseAIArmour

The AI nobody assessed

1
Configured
Aim it at a host under your own credential.
  • One target, one credential — SSH on Linux, WinRM on Windows, the same control set on both
  • Licence-gated: assessment does not start without a valid DenseAIArmour licence
  • Read-only by contract — metadata endpoints only, no inference and no content read
g20b-inaction
DenseAIArmour

The AI nobody assessed

1
In action
It enumerates the host's own AI estate on loopback.
  • Finds local model runtimes and vector stores on their known ports — Ollama, Chroma, and more
  • Reads agent and MCP configs for tool scope and embedded credentials
  • Every probe is one unauthenticated metadata GET, bounded by a short timeout
g20c-result
DenseAIArmour

The AI nobody assessed

1
Result
A signed posture, honest about its own coverage.
  • Observed / Attested / Not assessed — every control counted once, never blended into a single vanity score
  • On a live Chroma host: 7 gaps found, 3 controls in place, 11 observed, 33 not assessed — read straight off the report
  • The tool states the 75% it did not assess rather than implying a clean bill
DenseAIArmour · LEAST-PRIVILEGE PROBE WIRED · assess-only

It reads a locked-down box without touching it

The probe uses the lightest thing already on the host that can measure the endpoint, and steps up only when it must. Nothing is installed, on Linux or Windows.
Who
The platform owner whose hardened hosts have curl and python stripped out, and who will not allow a scanner to install anything on a production machine.
How
Linux: /dev/tcp, then curl, then python3. Windows: a .NET socket, then curl.exe, then Invoke-WebRequest. First one that can measure wins; a TLS or IPv6 endpoint the light method can't read makes it step aside, not guess.
What
A least-privilege ladder for the one thing the probe needs — an HTTP status — that reaches for a shell built-in first and a full client only as a fallback.
When
Every probe, automatically. For the rare host with none of the three, an operator can opt in to a staged, integrity-checked binary that is removed when the probe is done.
Why
A scanner that demands a tool be present, or that installs one, either fails on a stripped host or violates the read-only promise. Neither is acceptable on a customer's box.
Result
The endpoint is measured on whatever the host already has, installing nothing — proven live on both Linux and Windows PowerShell.
g21a-configured
DenseAIArmour

It reads a locked-down box without touching it

1
Configured
Nothing to choose — least privilege is the default.
  • auto walks the ladder from the lowest-footprint method up
  • An operator can force a single method, or opt in to a staged binary, but never has to
  • The method that got the status is recorded in the evidence, so fidelity is auditable
g21b-inaction
DenseAIArmour

It reads a locked-down box without touching it

1
In action
It falls back rather than failing.
  • Proven live: an IPv6-bound model made the socket probe step aside and a full client read it anyway
  • A host missing curl is still assessed — the shell built-in carries it, installing nothing
  • Windows validated on real PowerShell 5.1: socket, curl.exe, and the cmdlet all measured the endpoint
g21c-result
DenseAIArmour

It reads a locked-down box without touching it

1
Result
Read-only kept, on every host.
  • No process left running, no binary installed, no file left behind
  • The same control means the same thing on Linux and Windows
  • Air-gap capable end to end
DenseAIArmour · SIGNED EVIDENCE WIRED · assess-only

Every finding is signed, and anyone can re-check it

Each scan writes an Ed25519-signed manifest over every artifact it produced. An assessor re-hashes the files in one command; a single changed byte fails the check.
Who
The assessor or the customer's compliance lead who has to trust a report they did not run — and who has been handed unverifiable PDFs before.
How
verify opens every file the manifest names, hashes it again, and confirms the signature — returning 0 on a clean package and 1, naming the file and both hashes, on a tamper.
What
A chain of custody: every artifact hashed, the manifest signed with the org's own key, and a standalone verifier that re-derives the key from the licence.
When
Handed off with the report, and re-run by the assessor any time. It is the same verifier that covers ForteFide's C3PAO evidence.
Why
An AI-security finding is only worth what it can prove. Evidence that cannot be re-checked is an opinion, and opinions do not survive an audit.
Result
A record the customer can defend: measured, signed, and re-checkable by anyone, forever.
g22a-inaction
DenseAIArmour

Every finding is signed, and anyone can re-check it

1
In action
One command re-hashes the whole package.
  • verify re-opens every named artifact and hashes it again
  • The signing key is re-derived from the licence, not read out of the file
  • Clean package returns rc 0 — 'every file re-hashed, matches'
g22b-result
DenseAIArmour

Every finding is signed, and anyone can re-check it

1
Result
Tamper is caught, byte for byte.
  • One flipped byte returns rc 1, naming the file and both hashes
  • Proven on the installed build, not asserted on a slide
  • The same chain of custody an assessor already trusts from ForteFide

How the suite grows

Four products, one chain of custody

ForteFide, ForteStrike, ForteLock and DenseSense are each licensed on their own; a suite purchase stamps one shared identity across them. An assessor learns one verifier, not four.

ForteLock is a mode, not a fifth SKU

ForteLock is ForteStrike's active-protect mode — the same engine holding the line after the attack proves the gap. Nothing extra to license.

DenseSense — landing now

Data-boundary discovery is in progress and shown here on a staged demo corpus, not yet the live fleet. It draws the boundary the assessment then grades — no coverage claimed it has not measured.

DenseAIArmour — an add-on when you need it

AI-posture assessment drops in as its own licensed add-on with its own signed evidence, without changing the four suite products.

They monitor. We fix — and prove it.

The Full Suite finds it, fixes it, proves it under a real attacker, and keeps it that way — with DenseSense landing to draw the boundary first. When you need it, DenseAIArmour assesses the AI estate the same way, as an add-on.

contact@densedefense.com