Home › Endpoint Security Posture
190+ Checks · 8 Categories · 3 Platforms

Endpoint Security
Posture Assessment

How secure are your endpoints — really? Lorika performs 190+ automated security checks across 8 categories, covering authentication, network, filesystem, kernel hardening, software patches, services, SSH, and audit logging. Know your posture. Prove your compliance.

190+ checks across 8 security categories

Each check contributes to a weighted Security Score. Results are mapped to 8 compliance frameworks automatically.

🔑

Auth & Access

Password policy, SSH hardening, brute-force protection, NOPASSWD sudoers, MFA enforcement, admin group audit.

🌐

Network

Firewall status, risky open ports, 20+ dangerous exposed services, DNS-over-TLS, NTP config, NAT detection.

📁

Filesystem

Full-disk encryption, world-writable files, SUID/SGID binaries, home directory permissions, sensitive file perms.

Kernel

ASLR, NX/DEP, SIP (macOS), Secure Boot, SELinux/AppArmor, core dump disabled, kernel module blacklist.

📦

Software

Pending OS updates, auto-updates config, EOL OS detection, pending kernel reboot, untrusted repos.

🐳

Services & Docker

Screen lock, antivirus/EDR, Docker daemon security, privileged containers, Content Trust, sharing services.

🖥

SSH Hardening

PermitRootLogin, PasswordAuth, MaxAuthTries, AllowTcpForwarding, ClientAliveInterval, key algorithm strength.

📋

Audit & Logging

auditd running, log retention policy, syslog configured, privileged command audit rules, log integrity.

Beyond security checks

Lorika doesn't just run checks — it provides a complete endpoint security intelligence layer.

🐛

CVE Vulnerability Scanning

Every installed package is matched against OSV.dev CVE databases. Severity breakdown (Critical/High/Medium/Low), fix availability tracking, per-device CVE timeline, fleet-wide vulnerability dashboard.

📦

Software Inventory

Complete package list via dpkg, rpm, apk, pacman, brew, and Windows package managers. Searchable. Tracked per scan for change detection across your entire fleet.

📊

Resource Monitoring

CPU, RAM, disk usage per device. Historical tracking and trend analysis. Infrastructure health dashboard monitoring API, database, and Redis status.

🔄

Delta Scans

Agent caches previous results and only sends changed checks. Three-timer architecture (heartbeat 3 min, quick 15 min, full 60 min) reduces bandwidth by ~90%.

🌍

Network Discovery

Open port scanning, exposed service detection (Redis, MongoDB, MySQL, PostgreSQL, SMB, RDP, and 14+ more), NAT detection, and external reachability verification.

🤖

Silent Auto-Update

Agent updates itself on startup and every 6 hours. Binary integrity verified with SHA-256 checksums. Zero downtime, zero user interaction, zero manual maintenance.

Cross-platform endpoint coverage

🍎

macOS

Apple Silicon (M1-M4) and Intel. macOS 12 Monterey or later. FileVault, SIP, Gatekeeper, macOS sharing services, launchd integration. One-line install.

🪟

Windows

x64 architecture. Windows 10 (1903+) or Server 2019+. BitLocker, Windows Firewall, Windows Defender, Windows services monitoring. MSI or PowerShell install.

🐧

Linux

x86_64 and ARM64. Ubuntu 20.04+, Debian 10+, RHEL 8+, Fedora 38+. LUKS, SELinux/AppArmor, systemd, auditd, PAM. Shell one-liner install.

Assess your endpoint security posture now

Free forever for personal use. 190+ checks, 8 categories, real-time Security Score. Install in 3 minutes.

Create free account →