BLUE16
Security Assessment Suite
Restricted · private preview
ALL SYSTEMS OPERATIONAL
See the unknown · Reduce the risk

Offensive & Defensive
Security Tooling

Discover, analyse and reduce your exposure with Microsoft-native security data and open intelligence. Passive from three portal exports, or active with a scan engine behind it.

2 modesPassive & active
3 sourcesAzure · Defender · Entra
1 backendSightline only · passive needs none
AzureScan egress · westeurope
01 · DISCOVER

What answers from the internet

Azure public IPs, Defender's internet-facing devices and Entra's app and identity data in. Active mode adds a masscan → nmap → nuclei pipeline to find what is really listening.

02 · ANALYZE

Hold it against Defender

Every reachable address is compared with what Defender for Endpoint is actually watching, so coverage becomes a fact rather than an assumption.

03 · PRIORITIZE

Name the pair nobody else names

Addresses with no sensor that something is already answering on come first. Defender's exposure level and open ports decide the order.

04 · MITIGATE

Onboard, close or accept

Each finding ends in one of three actions: onboard the host, close the port, or record the acceptance. Exports go straight into the ticket.

Exposure Security

Visitor Telemetry

live geo-ip lookup
Your connection
IP addressresolving…
Location
ISP / Organisation
Coordinates
Triangulating location…
Connection facts
Country
Region
Timezone
ASN
Source
Your positionlocating