Four surfaces, 1,692 checks, one scan
External scanning is where most tools stop. SBCMSP keeps going — inside the network, into the cloud, and across identity.
External attack surface
674 checksTLS, DNS, email auth, exposed services, subdomains, and KEV-listed CVEs — everything an attacker can see, no agent required.
Internal agent
574 checksLightweight agents for Windows, Linux and macOS: BitLocker, patching, local admin, AD attack paths, Defender posture, and more.
Cloud posture (AWS, Azure & Google)
318 checksCSPM across AWS, Azure and Google Cloud — IAM, storage, network, logging and Defender — plus Google Workspace identity, with public exposure and misconfigurations flagged continuously.
Microsoft 365 / Entra
126 checksMFA coverage, conditional access, legacy auth, risky sign-ins, sharing and tenant hardening read straight from the tenant.