#04Perimeter control / AppSec

Claw Shield

A continuous external-perimeter control platform: service inventory, vulnerability tracking and reports for the security team.

  • Go
  • Python
  • Burp Suite
  • PostgreSQL
  • Docker
  • Grafana
Source code is covered by an NDA Discuss a similar project

Results in numbers

  • 12k

    assets under watch

  • ×6

    faster than manual inventory

  • −60%

    time to remediate

  • 24/7

    change monitoring

01

Challenge

The client security team lacked an accurate picture of its own external perimeter: forgotten staging hosts surfaced only after incidents.

02

Solution

A Go orchestrator inventories the client's own services on a schedule in isolated containers, while Python modules merge findings and open remediation tickets.

03

Result

The security team sees an up-to-date perimeter map and gets remediation tasks within hours instead of after an incident.

Key features

  • 01 Inventory of domains, services and software versions
  • 02 Isolated check execution in Docker
  • 03 CVSS-prioritized remediation tickets
  • 04 Trend dashboards in Grafana

Architecture

  1. Assets client asset registry
  2. Orchestrator Go, scheduler
  3. Workers isolated containers
  4. Analyzer Python, prioritization
  5. Grafana reports & trends

Tech stack

  • Go
  • Python
  • Burp Suite
  • PostgreSQL
  • Docker
  • Grafana

Timeline

  1. 2 weeks

    Asset registry & methodology

  2. 4 weeks

    Orchestrator & workers

  3. 3 weeks

    Integrations & reports

  4. 1 week

    Pilot & handover

Need something similar?

Describe your task in a messenger — we will come back with questions, an architecture and an estimate.