Lawliet LAWLIET
Book a demo
LAWLIET
Hardened by design

Prove your estate is compliant. Fix what is not. On servers you own.

Scroll
The console

One console. Every control, every host, every piece of evidence.

Compliance, network, firewall, data, forensics and response in one place, on your own server. Below is one example estate; every number here carries through the rest of this page.

Hardening

Fix it. Prove it. Undo it if you have to.

A failing control is fixed through a workflow: a change is proposed, a second person approves, it is applied, then re-scanned. A control is compliant only after validation.

Example
control 5.2.8 - /etc/ssh/sshd_config - web-01
#Loglevel INFO
PermitRootLogin no
PubkeyAuthentication yes
FailedPassedre-scan after apply
  1. Fix proposed

    Set PermitRootLogin to no on web-01.

  2. Second person approves

    Critical changes wait for a second signature.

    Approved - second signature - rso
  3. Applied and re-scanned

    Status flips from Failed to Passed after validation.

  4. Rollback available

    Nothing is one-way. The change can be reverted from the same record.

evidence EB-0142 sha256
How evidence bundles work
Modules

The rest of the estate, in the same console.

01

Network discovery

Twelve techniques build an inventory and a topology map, including the devices no one is managing.

Example
212 devices - 4 segments - 9 unknown
203.0.113.24unknown, unmanaged - segment 4
02

Firewall review

Cisco ASA, FortiGate and iptables rule sets, checked for any-any, shadowed and duplicate rules, with a cleanup plan.

Example - ASA
1permit tcp 192.0.2.0/24 any eq 443
2permit tcp host 192.0.2.10 any eq 443 shadowed by 1
3permit ip any any any-any
4deny ip 198.51.100.0/24 any shadowed by 3

Cleanup plan: drop rules 2 and 4, scope rule 3 to the ports you actually serve.

03

File integrity monitoring

A baseline of what should be there, and an event the moment it changes.

Example
/etc/sudoersbaselinea19f...4c2
/etc/sudoerschanged 03:147b02...9e1

Changed on db-primary by user deploy. Raised to the review queue.

04

Data loss prevention

Endpoint incidents with honest enforcement status: it says whether it only detected, or actually blocked.

Example
Card numbers copied to USBwks-14Detected, not blocked
Source code to personal cloudwks-09Blocked

Enforcement is never overstated. Detected is not the same as blocked.

05

Forensics

YARA scanning and artifact analysis, in cases with a timeline and a chain of custody.

Example - CASE-0031
YARA match: C2_Dropper_Generic
path /tmp/.x on app-03
IOC 203.0.113.45
IOC sha256 3af1...be9
  1. 03:02 dropper written to /tmp/.x
  2. 03:03 outbound to 203.0.113.45
  3. 03:14 flagged, host isolated
06

Log collection and SIEM

Syslog in on port 5514, search and detections, and forwarding out as CEF or LEEF over TLS or HTTPS to Splunk, Sentinel and more.

Example

Forwarded as CEF One detection raised: brute-force sudo on db-primary.

07

Honeypots

Decoys planted across the hosts you already manage - fake credentials, services, canary tokens and accounts. A decoy has no legitimate use, so any touch is a high-severity alert with one-click containment.

New in 1.5.4Example - web-01
/root/.aws/credentialsdecoy fileQuiet
:22 sshd (fake)decoy serviceQuiet
/srv/app/prod.envdecoy fileTouched 03:14

High Read by curl as user www-data on web-01. Contain

Review queue

Everything that needs a person, in one queue.

Findings from every module land in one work list, sorted by severity, next to the notifications each person chose to see.

Review queueExample - 5 open
YARA match on app-03 /tmp/.xforensics - C2 dropper signatureCritical
SSH root login enabledcompliance - web-01High
Card numbers copied to USBdlp - wks-14 - detected, not blockedHigh
/etc/sudoers changedfim - db-primaryMedium
Drift: 3 controls regressedcompliance - app-02Medium
Notifications3
  • 2 agents offline - mail-relay, win-07
  • 1 critical review item - app-03
  • 1 setup step outstanding

Each person chooses their categories and a minimum severity. History is kept.

Security

Secure by design, not by configuration.

The trust model is fixed in the product, not left to whoever installs it.

Agents pull their work

No inbound port on your hosts. Agents reach out; nothing reaches in.

Every command is signed

HMAC-signed, and refused if it is more than 10 minutes old.

Critical actions need two people

Dual control holds destructive actions until a second authorised person approves.

Accounts are locked down

Two-factor for every account, 7 roles, recovery codes, and a two-year audit trail.

Upgrades are signed offline

Agent upgrades are Ed25519-signed with a key kept offline.

The licence is yours

Bound to the installation fingerprint, RSA-4096 signed, verified offline. No phone-home.

Lawliet
Delivered signed and compiled

You receive a signed, compiled bundle. Install, activate, enrol.

Deployment

Runs on your servers. Works without the internet.

A signed bundle, an install, a fingerprint, a licence matched to it, then agents enrol across Linux, macOS and Windows.

Example
  1. 1
    A signed bundle arrives

    lawliet-2.4.0.bundle.sig - verified

  2. 2
    Install

    $ ./lawliet install

  3. 3
    The installation fingerprint prints

    fp 8b21-44df-90ac-7e15

  4. 4
    A licence locks to that fingerprint

    licence bound, RSA-4096

  5. 5
    Agents enrol

    48 agents - 30 Linux, 12 Windows, 6 macOS - 46 online.

Deployment requirements
ServerAny current 64-bit Linux, Intel/AMD or ARM
RuntimeDocker with Compose, or standalone
Small estate4 CPU, 8 GB RAM, 40 GB disk
Network443 for the console and agents, 5514 for syslog. No inbound port on monitored hosts.
InternetNot required. Install, activation and updates work offline.
AgentsLinux, macOS, Windows
Questions

What buyers ask first.

Does any of our data leave our network?

No. The console, its database and every result stay on your server. The licence is verified offline, so nothing needs to reach us.

Can it run fully offline?

Yes. Install, activation and updates all work from a bundle you carry in. Activation matches a fingerprint the installer prints.

Which systems can it monitor?

Linux, macOS and Windows through the agent. Network devices through discovery and syslog, and firewalls through rule-set import. The standards checks run on Linux hosts.

Which frameworks does it check?

CIS benchmarks, NIST, PCI DSS, ISO 27001, and more. It ships checks and framework mappings out of the box; on a demo we will tell you exactly which of your frameworks are covered today.

How do you keep changes safe?

Critical changes need a second approver. Every change is validated by re-scanning and can be rolled back. A control is compliant only after validation.

Can we keep our own SIEM?

Yes. Lawliet forwards events as CEF or LEEF over syslog or HTTPS, so it feeds the SIEM you already run, such as Splunk or Microsoft Sentinel.

How is it priced?

Three suites - Comply, Operate and Complete - each sized for up to 30, 100, 500, 1,000 or 3,000 agents, or every host with a site licence. Each suite is sized on its own and quoted for your estate. There are no public prices.

How is it delivered?

As a signed, compiled bundle. You install it, activate by fingerprint and enrol agents. One-time engagements ship with a scoped engagement licence.

Book a demo

See it on an estate like yours.

  1. 1A walkthrough against a scenario close to your environment.
  2. 2A pilot on your own hardware, offline if that is how you run.
  3. 3A straight answer on which of your frameworks are covered today.
  4. 4Run by the engineers who build Lawliet, its lead architect included, not a sales team.

Prefer email? [email protected]

We reply within one working day.