Security & trust

Security posture and vulnerability visibility beside server monitoring

Salix Monitor 360 combines availability monitoring with practical security posture checks and authorised vulnerability evidence. It does not replace a full security programme, but it helps teams spot issues such as expiring certificates, weak web security settings and scan findings while the operational context is still close at hand.

Posture and vulnerability visibility

Posture & hygiene checks

Group domains and apps into profiles then run regular checks that give you a simple score and a list of practical fixes. It is designed to cover the basics that often get forgotten when projects move on.

Certificates & HTTPS

Avoid “the site is fine but the certificate expired last night” moments.

  • Expiry warnings with sensible notice periods
  • Checks for chain and protocol health
  • Guidance on how to renew and harden

Headers, cookies & CORS

See if your apps are sending the right safety related headers and cookies.

  • Flags missing or risky headers
  • Highlights cookies without Secure or HttpOnly flags
  • Shows where CORS rules are too broad

DNS & email hygiene

Catch issues with SPF, DMARC and other DNS related settings before they cause delivery or trust problems. Salix can also summarise domain expiry and DNS drift so unexpected changes do not hide in the corner.

  • Mail related DNS entries at a glance
  • Signals for missing, conflicting or weakened records
  • Domain expiry and DNS drift evidence for operational reviews
  • Simple language explaining what to adjust

What the posture checks actually look at

Salix runs focused checks and groups the evidence into a score, clear findings and practical next actions.

Reputation, expiry and dependency signals

Extra posture summaries help show whether domains, time checks and third-party dependencies are still in a sensible state.

  • Malware and reputation checks for domains and public services
  • Domain expiry summaries alongside DNS and certificate hygiene
  • NTP/time health and third-party dependency summaries for operational reviews

Certificate inventory & expiry

Keeps track of the certificates your public sites present and how long they have left.

  • Shows which certificates are in use on which hosts
  • Highlights anything heading towards expiry in good time
  • Flags weak chains or obviously out of date setups

HTTPS enforcement & HSTS

Checks that visitors are nudged onto the secure version of your sites and kept there.

  • Looks for clean HTTP → HTTPS redirects
  • Flags missing or very short HSTS settings
  • Helps you move towards always on HTTPS safely

CORS & preflight audit

Reviews which web origins are allowed to talk to your APIs and pages.

  • Spots allow everything patterns that are too generous
  • Highlights places where credentials and wildcards are mixed
  • Makes it easier to tighten rules without breaking real users

Cookie & session flags

Looks at how important cookies are marked so browsers can protect them properly.

  • Checks for Secure and HttpOnly flags on session cookies
  • Highlights where SameSite is missing or too relaxed
  • Gives you concrete wording to use in your settings

HTTP method hygiene

Confirms that your sites and APIs only expose the methods they actually need.

  • Flags rarely used methods that are still switched on
  • Calls out TRACE and similar methods where they are not expected
  • Encourages a just enough approach to what is allowed

Email transport hardening

Looks at DNS records that control how your mail is sent and received.

  • Checks SPF, DKIM and DMARC for sensible modern settings
  • Points out missing or conflicting records in clear terms
  • Helps you move towards fewer spoofing and delivery issues

Public storage exposure

Keeps an eye out for public storage buckets and file shares that are too open.

  • Highlights places that look like anyone on the internet can read this
  • Encourages locked down defaults and short lived links
  • Makes it easier to review where files actually live

Third party script inventory

Lists the external scripts loaded into your pages so you know who has a foothold.

  • Shows which analytics, chat and widget providers you rely on
  • Makes it obvious when an old or unused service is still present
  • Supports better decisions about what to keep, tidy or remove

API surface quick check

Takes a high level look at how your APIs identify themselves and what they reveal.

  • Spots very chatty version banners and debug style headers
  • Encourages cleaner more deliberate API responses
  • Gives you a simple sketch of where your API surface is growing

Lightweight vulnerability checks

Run quick vulnerability sweeps around key endpoints and certificates then track progress over time alongside your uptime and posture data.

Findings you can act on

Results are grouped by severity with clear terms descriptions and suggested fixes so they can be handed to the right teams without translation.

  • Critical, High, Medium, Low and Info levels
  • Descriptions that explain why this matters
  • Next steps you can assign to the right team

Safer view of internal systems

Agents send compact snapshots over HTTPS without exposing internal networks directly to the internet.

  • Tokens can be created and revoked easily
  • No user content or files sent, just metrics
  • Access scoped by organisation and role

Vulnerability sweeps with Nmap, Nuclei and OWASP ZAP

Salix Monitor 360 coordinates Nmap, Nuclei and OWASP ZAP, then normalises their findings into consistent severity, evidence and remediation details.

Nmap - what is exposed on the network

Nmap checks which ports and services are visible from the network so you can see what is really exposed to the outside world or to other parts of your infrastructure.

  • Quick sweeps of key hosts and ranges you choose
  • Helps you spot unexpected open ports or old services
  • Summarises exposed services and changes inside Salix

Used sensibly Nmap helps you keep a handle on where services appear over time instead of relying on memory and old handover notes.

Nuclei - template-based vulnerability checks

Nuclei runs fast, template-driven checks against known technologies and common weaknesses so likely issues can be spotted without turning every review into a heavy penetration test.

  • Uses curated templates for common CVEs, exposures and misconfigurations
  • Helps spot known weak points across websites, APIs and services
  • Fits neatly into repeatable scans so fixes can be checked again later

Nuclei is useful for quick, repeatable checks where you want practical findings and trend history rather than a one-off pile of raw scan output.

OWASP ZAP - web application checks

OWASP ZAP crawls and exercises your web applications looking for common weaknesses in how pages and APIs are built. It focuses on the pieces people actually touch.

  • Helps uncover issues in forms, sessions and user flows
  • Suited to important sites and applications rather than every host
  • Results land back in Salix so you can track and rescan easily

ZAP gives you a realistic view of how a web application behaves when pushed and Salix keeps the findings tidy so follow up work is easier to plan.

You choose which targets are in scope for Nmap, Nuclei and ZAP. Salix handles scheduling and keeps the history so you can see whether things are getting better, drifting or staying flat between reviews.

Seeing vulnerability scans in context

Results from Nmap, Nuclei and OWASP ZAP land back in Salix as tidy summaries ready to share with technical teams and non technical stakeholders. Important posture and vulnerability signals can also feed the administration dashboard, including TV mode, so shared screens show operational health and exposure context together.

Instead of dropping you into raw scanner output, Salix groups findings by host, severity and time. That makes it easier to see which systems are improving, which are drifting and where you may need a planned piece of remedial work.

When you do need the fine detail, you can still download the underlying scanner reports for your security team or auditors, while using the cleaner Salix view for everyday conversations with stakeholders.

Vulnerability scans page in Salix Monitor 360
Vulnerability scans Scan queue and history
Salix Monitor 360 Nmap vulnerability scan report with host findings and raw output
Nmap report detail. Click to open the screenshot at its natural size.

How Salix Monitor 360 is locked down

Salix Monitor 360 is built to be safe to run as a serious monitoring app. Beyond the features above, the application is hardened, and key actions are audited so you can answer “who changed what, and when?” without guesswork.

Audited and searchable activity

Important actions are recorded so you have an audit trail that can be searched when you need to understand a change, investigate an incident, or support a review.

  • Clear “who did what” records for key admin actions
  • Searchable history to support support and governance
  • Designed to reduce finger-pointing during incidents

Security headers enabled

Salix Monitor 360 is configured to send modern security headers that help browsers apply safer defaults.

  • HSTS: On - tells browsers to stick to HTTPS for the site, reducing downgrade risk.
  • X-Frame-Options: On - reduces clickjacking by preventing unwanted framing.
  • Referrer-Policy: On - limits what referrer information is sent to other sites.
  • X-Content-Type-Options: On - prevents certain “content sniffing” behaviours in browsers.
  • Permissions-Policy: Present - restricts access to browser features that are not needed.

Runtime hardening signals

Session handling is configured with safety-first settings so cookies behave as they should.

  • session.cookie_secure: On - session cookies are only sent over HTTPS.
  • session.cookie_httponly: On - helps prevent JavaScript from reading session cookies.
  • session.use_only_cookies: On - avoids leaking session identifiers via URLs.

The application uses PDO for database access, with parameterised queries. This helps protect against SQL injection by ensuring values are handled as data rather than being treated as part of the SQL itself. It also encourages consistent error handling and safer query patterns across the codebase.

No security measure is magic on its own, but together these choices reduce common attack paths and make the app safer to operate day to day.