DOCUMENTATION

Start with the evidence.

A practical introduction to ARIEMA’s connected security model, the information it brings together and how to review it.

Start with a domain and its scope

Establish the domain or asset you are reviewing, who is responsible for it and the boundaries of your authorization. Then use the connected pillars to inspect its public footprint.

The homepage demonstrates this workflow with illustrative domains and animated findings. Its animation timing is separate from monitoring or assessment cadence.

Seven connected pillars

  • DNSRecords, configuration and domain dependencies. Read the guide
  • InfrastructureInternet-facing hosts, networks and hosting signals. Read the guide
  • Web & HTTPWebsite behaviour, security headers and configuration. Read the guide
  • TLS & CertificatesEncryption, certificate validity and transparency records. Read the guide
  • Email SecuritySPF, DKIM and DMARC configuration. Read the guide
  • Domain RegistrationRegistration details, expiry and lifecycle signals. Read the guide
  • Exposed ServicesReachable ports, detected services and exposure findings. Read the guide

Observe. Compare. Explain. Review.

  1. Observe: retain the asset, collection time, method and resulting evidence.
  2. Compare: examine the current observation alongside earlier evidence.
  3. Explain: connect the finding to its context, affected service and remaining uncertainty.
  4. Review: assign follow-up, plan remediation and compare a retest with the intended result.

Explore evidence quality and collection

Monitoring and change

A change is a reason to review the evidence. Check timestamps and distinguish a successful observation from a collection failure. An unavailable response does not, on its own, prove that a service has been removed.

Read the monitoring guide

ARIEMA Veritas

Use CVE intelligence to inform investigation and authorized validation planning. Confirm the asset, permission, scope and conditions before active validation. The website’s Veritas scene is an explainer and does not run a test.

Understand the validation workflow

Connected destinations

Native destination support covers Slack, Microsoft Teams, Jira, Linear, ServiceNow, Splunk, Microsoft Sentinel, Datadog, Webhook and Email.

Plan which finding, asset, evidence and workflow update each destination should receive. Before relying on a delivery path, confirm the receiver accepted the expected information.

Explore the destinations