Bastion

An operating system for exposure management.


Overview

Bastion architecture
Bastion

Bastion enumerates and assesses complex environments across cloud, on premises, and internet facing assets to identify potential attack paths. Its findings can be used directly or passed to Reaper to validate risks through simulated offensive actions.

It builds a dynamic understanding of assets and risk by structuring environmental data into an ontology linking hosts, applications, and vulnerabilities. At its core, it uses Method’s data knowledge graph of interconnected objects and links, enabling contextual risk assessment and attack path discovery.

The Bastion Dashboard

The Bastion dashboard provides an overview of your organization’s overall security posture categorized by Scorecards. These Scorecards rank environments by their overall riskiness, health, number of most issues, closed issues, and other important metrics. The Risk types tab gives you visibility into Issues across different risk categories and trends overtime. You can also view All environments to see and filter all of your environments.

Explore Environments by Risk Types
Sort your Environments

Explorer

Explorer enables flexible search and filtering across environments and object types, to make it easy for you to identify and investigate specific assets in your environment. Learn more about Explorer.

Discover assets and issues in Explorer

Automator

The Automator app lets you create, monitor, and run scheduled tasks and tests in an environment. You can view your surfaced Issues by severity, family, type, status, or environment. Learn more about Automator.

Use Method's Golden Tasks to schedule task runs

Issues

Select an Issue to further investigate, explored linked Objects, view Issue history, change status, generate a report for external stakeholders, or perform active validation of the Issue in Operator.

Investigate and triage Issues