A guide to hardening the email and DNS layer. DMARC enforcement (p=reject) on top of SPF/DKIM, MTA-STS/TLS-RPT and BIMI, secure email gateway (Safe Links/Attachments, anti-impersonation), blocking automatic forwarding, DNSSEC, protective DNS (PDNS), and registrar/registry lock. Significantly reduces phishing, BEC, and domain spoofing.


HARDEC — Hardening, Detection, Compare
Compare your environment to what it should be. See the gap. Harden it.
- AD-PRIV-01 · Tier-0 account separation
- AD-CS-01 · AD CS certificate security
- AD-LOG-01 · Advanced audit logging
- M365-IDN-01 · MFA enforcement
- M365-PRIV-02 · Privileged access with PIM
- M365-CA-01 · Conditional Access policies
- LNX-SSH-01 · SSH hardening
- LNX-NET-04 · Kernel / sysctl hardening
- LNX-LOG-01 · auditd monitoring
- CLD-IAM-01 · Root / owner account protection
- CLD-DAT-01 · Block public storage access
- CLD-LOG-01 · Cloud audit logging
Controls can be mapped to CIS, NIST 800-53/800-171, NIST CSF, and ISO 27002.
Closed field test — offline tool
We have not tested the tool enough across different environments. Request it with a company email; we will send a free build for the platforms you ask for. Run it, evaluate it, and share logs and feedback.
Other environmentsComing soon
Visible in the list; control bodies are not open yet. Comparison is available for the four open environments.
Techniques
Actively Exploited Vulnerabilities
Vulnerabilities under active exploitation in CISA KEV.
Response Playbooks
What to do when an incident occurs — step by step, aligned with NIST SP 800-61 phases. 78 playbooks · 1984 response steps.



