Findings
Generator
Configuration
Lucidum Reverse
Architecture
Statistics
← All Findings
Vendor:
SentinelOne Singularity XDR
FIN-287
Weight:
5
4
3
2
1
Confidence:
High
Medium
Low
Edited:
2026-03-06 09:03
Verified
What It Detects
Asset is unmanaged (shadow IT), has a public IP address, and has no firewall rules configured. This represents the maximum network exposure condition: an asset that is directly reachable from the internet, has no network-level access controls, and is not enrolled in IT management for patching, monitoring, or policy enforcement.
MITRE ATT&CK Techniques
Comma-separated, e.g. T1078, T1190
Checks
read-only
Field
Operator
Value
IT Managed (True/False)
equals
False
Public IP Address
not_empty
Firewall Rules
is_empty
Remediation
×
×
×
×
×
+ Add item
Why It Matters
×
×
×
+ Add item
Save Changes
Export Lucidum