Monitoring & operations

Signal that scales with your fleet. Not a firehose.

Skans watches every device on the enclave — Windows endpoints through the agent, cameras, PLCs, switches and firewalls through the collector — and turns the raw stream into a small, correlated worklist bounded by the number of devices affected, never a wall of events. Alert rules decide what fires, routing decides where it goes, and every suppression is a recorded exception. Offline CVE and MITRE ATT&CK run on the box, so a severed WAN changes nothing about what you can see.

Skans console · Operations
A Skans NOC wall dashboard — metric tiles for fleet health, open incidents, compliance percentage, certificates, devices by tier, vulnerabilities, approvals and maintenance windows, events in the last 24 hours, ATT&CK detections, auto-handled findings, RADIUS/NPS status, and search-engine health.

Signal over noise

Correlation, not raw volume.

Traditional monitoring polls on a timer and floods you with one alert per host. Skans inverts it: anything that can push — a Windows event, a syslog message, an SNMP trap — does so on occurrence, and an always-on alert engine turns those occurrences into findings that are correlated and bounded by device count. A site of 200 devices produces alerts on the order of devices affected, not thousands of raw events. A site-wide outage collapses into a handful of correlated findings instead of one per host.

  • Bounded by device count — a 1,471-event storm resolves to the two findings that actually need you, not a scrollback you'll never read.
  • Storm de-duplication — a site outage coalesces into a single storm count; portable machines get a 24-hour offline grace and are excluded, so a van full of sleeping laptops never reads as an incident.
  • One upstream cause, one finding — root-cause walks the uplink chain, so a known-unreachable switch subsumes everything behind it instead of paging you per device.
  • Fail-open by design — the offline rule watches only registered hosts, but if that allowlist goes missing or stale it watches everything rather than going silent.
Skans console · Home
The Skans console home — an ask-the-appliance command bar over a correlated worklist of what needs attention, where compliance stands, and whether backup ran.

You decide where it lands

Rules decide what fires. Routing decides where it goes.

Detection is the product's judgment; where an alert lands is yours. The Alerting console lets an operator tune the packaged rules, route by severity, and record every exception — a save goes live on the engine's next evaluation cycle, with no service restart. Suppressions are exceptions on the record, never silent muting.

  • Rules & routing — enable, disable and tune rules from the console; route by severity with quiet-hours, and re-notify an unacknowledged alert on an interval instead of firing once and forgetting.
  • Suppressions on the record — silence a rule for a host pattern for a bounded window; if the rule evidences a control like NIST AU-6, the console requires a written justification and logs it as an explicit risk acceptance, so a silenced control is never an invisible gap.
  • Snooze always expires — nothing gets silenced indefinitely by accident.
  • Delivery health — see whether the SMTP relay or webhook actually accepted the last dispatch, so you learn about a broken channel from the console, not from a missed incident.
Skans console · Alerting
The Skans alerting view — a table of alert rules by name, type, severity, cooldown, and routing.

Threat intel, offline

Offline CVE and MITRE ATT&CK, matched on the box.

Skans syncs the public CVE List and MITRE ATT&CK into an on-box store and matches them against live per-host inventory — no cloud scanner in the loop. The match uses a strict version-range gate, not a name lookup, so a host that is actually patched shows zero findings. Green means green, not unscanned.

  • ~342k CVEs, 697 ATT&CK techniques — held on the appliance and matched locally; a severed WAN changes nothing about the scan.
  • Ranked by real-world risk — findings carry a CVSS score, are stamped when they appear in CISA's Known Exploited catalog, and carry a FIRST.org EPSS exploit-probability score, so what's actually being exploited sorts to the top.
  • ATT&CK on every finding — a CVE → CWE → ATT&CK join tags each hit with the techniques that exploit it, so a finding reads as adversary behavior, not just a number.
  • Air-gap integrity — the offline feed arrives as a signed bundle that is cryptographically verified against a held anchor before a single record is indexed; a tampered or unsigned bundle is refused.
  • An honest hand-off — Skans tells you what's vulnerable and which version fixes it, then routes remediation into approved patch rings where a human approves the change. It never picks or applies a fix for you.
Skans console · Updates & patch rings
The Skans updates view — signature-gated updates with per-ring approval and a fleet patch-compliance bar chart, where a CVE finding's remediation lands.

How the signal gets in

Every lane feeds one picture.

Agent lane for Windows

The Authenticode-signed agent runs on each Windows server and workstation, pushing inventory, metrics, Defender health, patch state, and a full event-log mirror over mutual TLS. A failed logon reaches the console in seconds — no forwarding tier to stand up or maintain.

Agentless lane for everything else

A low-privilege collector listens for syslog and SNMP traps and polls SNMP-capable gear on a fast reconcile. For PLCs it does read-only ICS identification — EtherNet/IP and Modbus/TCP — reading run and fault state without ever writing to the device.

The appliance watches itself

A self-health service samples disk, RAM, CPU, database size, and core-service liveness, and raises immediate Critical alerts on the crown jewels — domain-controller drift, DR and backup failure, PKI expiry, and Critical CVE matches.

Events live on the box

Logs, events and metrics land in an on-box store — the appliance's own system of record — with a default one-year retention on event data. With no outbound channel, delivery degrades gracefully to console-only; nothing is silently dropped.

Watched, and audit-ready

The Detect evidence an assessor asks for.

Correlated, reviewable integrity signal is exactly what a continuous-monitoring control wants to see. Skans maps its monitoring to the NIST Detect function — and because suppressing a compliance-tagged rule is recorded as a risk acceptance, a silenced control stays visible to the compliance view. Skans supplies the technical evidence; it never certifies you.

  • Continuous-monitoring evidence — correlated, deduplicated findings give the bounded, reviewable integrity signal NIST 800-171's System & Information Integrity family expects.
  • Offline risk assessment — on-box CVE matching evidences continuous vulnerability monitoring (RA-5) for an enclave with no internet.
  • An honest boundary — this is push-first collection plus correlation, not a full IDS/EDR. Pair Skans with a dedicated IDS/EDR for complete Detect coverage; it's an enabler, never a certification.
Skans console · Compliance
The Skans compliance view — a NIST 800-171 posture ring and per-control-family status cards for AC, AU, CM, IA, RA, and SC.

Talk to us

See Skans on your network.

Built for the teams running networks the cloud can't reach. Email us for a technical walkthrough — architecture, controls, and exactly how it stays offline.