LEX Risk Management Coach
بواسطة Lockbase Cyber
Prioritizes risk findings to reduce exposure across identity and critical assets.
Lockbase Exposure Agent (LEX = Lockbase EXposure) is a pre-breach risk-reduction agent that surfaces standing, reducible escalation-path preconditions across Microsoft Entra ID, on-premises Active Directory, and Azure inside Security Copilot, helping CISOs and security teams find and cut the attack paths an adversary would use before exploitation — rather than waiting for an alert and triaging after the fact.
Inputs: Microsoft Defender Advanced Hunting telemetry (identity, sign-in, audit/CloudAppEvents, Exposure Management graph, vulnerability/TVM, device, and AI-agent tables), Microsoft Graph Secure Score, read-only Microsoft Entra and Intune context, and analyst natural-language prompts (a topic such as "how is my Active Directory environment looking", an account UPN, a service-principal or application name, a device name, or a request for a risk scorecard).
Tasks: Surfaces standing, reducible escalation-path preconditions across identity and high-impact exposure by orchestrating 61 risk-reduction skills (60 Advanced Hunting KQL skills plus one Microsoft Graph Secure Score skill) — Entra application and service-principal attack paths, on-prem Active Directory privileged access and Kerberos/NTLM footprint, standing access to crown-jewel assets (Key Vaults, domain controllers, sensitive storage and SQL, Tier-0 systems), cross-subscription privilege blast radius, sign-in / Conditional Access / MFA gaps, AI-agent identity over-privilege, exploitable vulnerabilities and end-of-life software (with CVE, CVSS, and remote-code-execution context) on internet-facing or crown-jewel assets, mailbox delegation, external mail forwarding, SharePoint/OneDrive sharing exposure, and endpoint supply-chain risk. It maps each scoped question to the right skills, ranks findings P1–P4, down-ranks expected access (Microsoft first-party service principals and by-design Active Directory Tier-0 admin groups) to informational, and routes configuration hygiene to Microsoft Secure Score rather than duplicating it. It is risk reduction, not attack detection, and is not a general CVE catalog.
Outputs: Prioritized (P1–P4) risk findings presented worst-first as structured lists, each with the risk level, the escalation path and why it matters (the BloodHound/AzureHound-style standing edge to cut), and the specific reduction action (right-size, remove, harden, retire, or move to PIM-eligible just-in-time). Findings name the actionable identifiers — Entra object and application IDs, host names, source IPs, and asset names — with the precise access verb (for example "WRITE / OWNER access to a named domain controller" or "MONITORING / LOGGING WRITE to a Key Vault"), and route tenant configuration posture to Microsoft Secure Score.
Lockbase Exposure Agent consumes approximately 0.3–1.5 SCU per run, depending on review depth:
- A rapid risk scorecard (one token-capped probe per category across the full estate) runs at ~0.3–0.5 SCU.
- A single-category deep-dive that runs the 5–6 highest-priority skills for one area (for example Entra application attack paths or sign-in/MFA gaps) averages ~0.6–1.0 SCU.
- A broad, multi-category review, or a deep dive that includes one of the heavier Microsoft Exposure Management graph skills (crown-jewel standing access, cross-subscription blast radius, inherited or group-inherited access), reaches ~1.0–1.5 SCU.
- An exposure-graph skill that scans the full identity/resource graph adds ~0.2 SCU per skill beyond the lightweight behavioral and sign-in queries.
- SCU consumption scales with the number of skills invoked, how many risk categories are deep-dived, and the size of the Exposure Management graph and Advanced Hunting tables scanned during each run.