Skip to main content

Cyentrix Audit Library

Reusable control reviews you can run today.

Browse curated cybersecurity control reviews — Active Directory reviews, vendor risk, cloud configuration audits, ransomware readiness and more. Each program is runnable end-to-end, scored, and mapped to common frameworks.

  • 69 programs curated + growing
  • Run end-to-end scored reports
  • Framework-mapped NIST · ISO · CIS · NIS2
  • All open reuse + adapt

AI Security

6 programs

Identity & Access

8 programs

Cloud

6 programs

AppSec & DevSecOps

3 programs

Network

7 programs

Endpoint

7 programs

Data

3 programs

Incident Response

6 programs

3rd Party Risk

3 programs

OT / ICS

3 programs

Social Media & Brand

3 programs

Compliance & Governance

9 programs

Other programs

5 programs

Website Defacement Campaign — Control Review

Free

Ongoing pattern of website defacements where attackers replace site content to push a political or trophy message. Implies the targeted CMS / web tier has unpatched vulnerabilities, weak admin credentials, or missing WAF.

6 controls · v0.1.0

Database Leak / Unauthorised Data Exposure — Control Review

Free

Attacker dumps or sells a customer database. Implies the data store was accessible from the internet, lacked encryption at rest, or had weak access controls. DLP, classification, encryption and database access auditing close the gap.

6 controls · v0.1.0

Remote Access and Credential Exposure Audit

Free

Threat actors exploit weak VPN configurations and stolen or weakly protected credentials to gain initial access, then deploy ransomware after escalating privileges and moving laterally.

7 controls · v0.1.0

ICS / OT Device Vulnerability — Control Review

Free

Vulnerability disclosed in an industrial / building-control device. Implies the device may be reachable from the corporate network or directly from the internet. Calls for network segmentation, asset inventory and vendor patch tracking.

5 controls · v0.1.0

Initial Access Broker Sale — Control Review

Free

Initial-access brokers selling administrative or remote access to a victim organisation (VPN, RDP, Exchange OWA, AWS console, AD domain admin). The buyer is typically a ransomware affiliate. Demands MFA on every remote pathway, PAM for admin tiers, dark-web monitoring of company brand + employee emails.