<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Dual-Strike XISEM]]></title><description><![CDATA[This substack is the place to learn whats new with Dual-Strike XISEM!]]></description><link>https://press.dual-strike.com</link><image><url>https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png</url><title>Dual-Strike XISEM</title><link>https://press.dual-strike.com</link></image><generator>Substack</generator><lastBuildDate>Fri, 28 Aug 2026 23:43:15 GMT</lastBuildDate><atom:link href="https://press.dual-strike.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Vysion Technology Solutions LLC]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[dualstrikexisem@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[dualstrikexisem@substack.com]]></itunes:email><itunes:name><![CDATA[Andrew Streetman]]></itunes:name></itunes:owner><itunes:author><![CDATA[Andrew Streetman]]></itunes:author><googleplay:owner><![CDATA[dualstrikexisem@substack.com]]></googleplay:owner><googleplay:email><![CDATA[dualstrikexisem@substack.com]]></googleplay:email><googleplay:author><![CDATA[Andrew Streetman]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[MSP first 7 days: Dual-Strike XISEM quickstart]]></title><description><![CDATA[From tenant creation to first meaningful detection &#8212; a public field checklist.]]></description><link>https://press.dual-strike.com/p/msp-first-7-days-dual-strike-xisem-quickstart</link><guid isPermaLink="false">https://press.dual-strike.com/p/msp-first-7-days-dual-strike-xisem-quickstart</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Mon, 27 Jul 2026 14:57:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Onboarding a new MSP practice or client org on Dual-Strike XISEM follows a predictable arc. This <strong>7-day quickstart</strong> is the public version of what successful partners run internally &#8212; no internal codenames, no infra details.</p><h2>Day 1 &#8212; Foundation</h2><ul><li><p>Create <strong>MSP org</strong> and first <strong>client org</strong></p></li><li><p>Invite analyst seats (role-based access)</p></li><li><p>Download <strong>XISEM Agent MSI</strong> and <strong>Anti-Venom</strong> from <a href="https://dual-strike.com/downloads">dual-strike.com/downloads</a></p></li><li><p>Deploy agent to <strong>3&#8211;5 pilot endpoints</strong> (mix of desktop + laptop)</p></li></ul><h2>Day 2 &#8212; Browser coverage</h2><ul><li><p>Confirm <strong>Anti-Venom</strong> from Chrome Web Store / Edge Add-ons / Firefox AMO (8.7.x GA line)</p></li><li><p>Publish <strong>browser policy</strong> in Settings &#8594; Browser Extension</p></li><li><p>Open <strong>Browsing Insights</strong> &#8212; verify sessions within 24h</p></li><li><p>Check <strong>Extension Health</strong> &#8212; aim for Healthy, not Not Detected on active machines</p></li></ul><h2>Day 3 &#8212; Identity</h2><ul><li><p>Establish <strong>Microsoft GDAP</strong> (or client-specific identity infeed)</p></li><li><p>Validate <strong>Entra sign-ins</strong> on Asset timelines</p></li><li><p>Skim <strong>Conditional Access intelligence</strong> panel &#8212; no enforcement, just context</p></li></ul><h2>Day 4 &#8212; EDR and PSA</h2><ul><li><p>Connect <strong>primary EDR</strong> (SentinelOne, CrowdStrike, Huntress, etc.)</p></li><li><p>Connect <strong>PSA</strong> (ConnectWise, Autotask, Halo, SuperOps, &#8230;)</p></li><li><p>Fire test detection &#8594; confirm <strong>ticket creates</strong> with evidence body</p></li></ul><h2>Day 5 &#8212; Detection tuning</h2><ul><li><p>Enable <strong>COBRA&#178;</strong> rules in learning mode: shadow AI, posture regression, identity drift</p></li><li><p>Review <strong>Threat Center</strong> volume &#8212; disable noisy rules</p></li><li><p>Map severities to PSA boards</p></li></ul><h2>Day 6 &#8212; Compliance and reporting</h2><ul><li><p>Select <strong>target framework</strong> (SOC 2, NIST, CMMC, &#8230;)</p></li><li><p>Review initial <strong>control gaps</strong></p></li><li><p>Schedule first <strong>monthly executive report</strong></p></li></ul><h2>Day 7 &#8212; Client readout</h2><ul><li><p>Walk client through <strong>Asset modal</strong> on one device (live demo)</p></li><li><p>Show <strong>Browsing Insights</strong> top domains + AI usage</p></li><li><p>Agree remediation priorities from <strong>POA&amp;M</strong> top items</p></li></ul><h2>Success metrics at day 7</h2><p>MetricGood sign Agent coverage&gt;80% of managed endpoints in pilot Extension healthActive users reporting Healthy/Idle Identity eventsSign-ins visible for M365 clients PSA loopAt least one ticket round-trip Detections&lt;5 false-positive Criticals after tuning</p><p><strong>Deep dives:</strong> Evidence doctrine &#183; COBRA&#178; guide &#183; GDAP onboarding</p><div><hr></div><p><em>Adjust pacing for client size &#8212; enterprise may need 14 days for change windows.</em></p>]]></content:encoded></item><item><title><![CDATA[EDR infeeds: SentinelOne, CrowdStrike, Huntress, and more]]></title><description><![CDATA[Keep your EDR &#8212; add correlation, compliance, and PSA context in Dual-Strike XISEM.]]></description><link>https://press.dual-strike.com/p/edr-infeeds-sentinelone-crowdstrike-huntress-and-more</link><guid isPermaLink="false">https://press.dual-strike.com/p/edr-infeeds-sentinelone-crowdstrike-huntress-and-more</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Mon, 27 Jul 2026 14:36:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> Keep your EDR &#8212; add correlation, compliance, and PSA context in Dual-Strike XISEM.</p><p>&gt; <strong>STAP note:</strong> EDR gateways are <strong>Strategic Technology Alliances</strong> under the <a href="38-stap-strategic-technology-alliance-program.md">Strategic Technology Alliance Program (STAP)</a>. XISEM extends and operationalizes EDR telemetry &#8212; it is not an EDR replacement.</p><div><hr></div><p>Dual-Strike XISEM is not an EDR replacement. It is the <strong>correlation and governance layer</strong> that extends and operationalizes the EDR you already sell. <strong>EDR alliance gateways</strong> import detections, agent health, and asset mappings so COBRA&#178;, ASPIRE, and Threat Center see the same device the SOC already manages.</p><p><strong>Route:</strong> Settings &#8594; Technology Alliances &#8594; EDR</p><h2>Supported EDR families (public index)</h2><p>VendorTypical MSP use <strong>SentinelOne</strong>MSP multi-tenant, Singularity API <strong>CrowdStrike Falcon</strong>Enterprise and mid-market <strong>Huntress</strong>SMB-focused managed EDR <strong>Microsoft Defender for Endpoint</strong>M365-heavy clients <strong>Trend Micro, Sophos, others</strong>See Technology Alliances wiki slug index</p><p>Exact setup steps live in <strong>Support wiki &#8594; Technology Alliances</strong> per vendor (API keys, OAuth, site IDs).</p><h2>What XISEM adds on top of EDR</h2><ol><li><p><strong>Asset reconciliation</strong> &#8212; EDR agent ID &#8596; XISEM agent &#8596; Entra user</p></li><li><p><strong>Unified Threat Center</strong> &#8212; EDR + COBRA + FIM + browsing in one queue</p></li><li><p><strong>Compliance mapping</strong> &#8212; EDR evidence satisfies endpoint protection controls</p></li><li><p><strong>PSA tickets</strong> &#8212; detection &#8594; ticket with cross-source context</p></li><li><p><strong>ASPIRE Security pillar</strong> &#8212; gap when EDR missing on managed asset</p></li></ol><h2>Deployment order</h2><ol><li><p>XISEM <strong>agent</strong> on endpoints (posture + browsing + FIM path)</p></li><li><p><strong>EDR</strong> as today (keep vendor console for containment)</p></li><li><p>Enable <strong>EDR infeed</strong> per client</p></li><li><p>Tune <strong>duplicate suppression</strong> &#8212; same malware signal from EDR and COBRA may merge</p></li></ol><h2>Field note: coverage truth</h2><p>Extension Health and EDR health together answer: <strong>&#8220;Is this laptop actually protected?&#8221;</strong> An EDR agent without XISEM agent misses browsing and posture correlation. XISEM agent without EDR may still score ASPIRE but Security pillar reflects the gap honestly.</p><p><strong>Docs:</strong> Technology Alliances &#8594; SentinelOne MSP &#183; CrowdStrike Falcon &#183; Huntress</p><p><strong>Download agents:</strong> <a href="https://dual-strike.com/downloads">dual-strike.com/downloads</a></p><div><hr></div><p><em>Vendor trademarks belong to their owners &#8212; integration availability subject to API terms.</em></p>]]></content:encoded></item><item><title><![CDATA[Client portal: let customers see posture without your console]]></title><description><![CDATA[Branded read-only views &#8212; executive summary, reports, and open POA&M items.]]></description><link>https://press.dual-strike.com/p/client-portal-let-customers-see-posture-without-your-console</link><guid isPermaLink="false">https://press.dual-strike.com/p/client-portal-let-customers-see-posture-without-your-console</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Mon, 27 Jul 2026 14:33:07 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> Branded read-only views &#8212; executive summary, reports, and open POA&amp;M items.</p><div><hr></div><p>Not every client stakeholder needs an analyst seat. The <strong>Client Portal</strong> exposes <strong>curated, read-only</strong> posture views: scheduled reports, compliance summary tiles, open remediation items, and optional browsing summaries &#8212; under <strong>MSP white-label</strong> branding.</p><p><strong>Route:</strong> Settings &#8594; Client Portal &#183; Support wiki &#8594; Client portal</p><h2>What clients typically see</h2><p>SurfaceStakeholder <strong>Executive dashboard</strong>Owner, CFO <strong>Published reports</strong>IT manager <strong>Open POA&amp;M</strong>Remediation owner <strong>Compliance %</strong>Auditor (read-only link)</p><h2>What stays MSP-internal</h2><ul><li><p>Threat Center full queue</p></li><li><p>Raw browsing session detail (configurable)</p></li><li><p>Cross-client MSP rollups</p></li><li><p>Integration credentials</p></li></ul><p>Portal scope is <strong>per client org</strong> &#8212; no neighbor tenant leakage.</p><h2>Enablement checklist</h2><ol><li><p>Configure <strong>white-label</strong> logo and colors</p></li><li><p>Select <strong>portal modules</strong> to expose</p></li><li><p>Invite client users with <strong>portal role</strong> (email invite)</p></li><li><p>Publish first <strong>scheduled report</strong> to portal archive</p></li><li><p>QBR walkthrough live on portal URL</p></li></ol><h2>Sales angle</h2><p>&gt; &#8220;You get 24/7 visibility into posture and compliance progress &#8212; we retain operational control and PSA workflow.&#8221;</p><p>Differentiates from EDR vendor portals that show only their product silo.</p><h2>Security posture</h2><ul><li><p>Separate auth from MSP analyst accounts</p></li><li><p>MFA recommended (Entra SSO when configured)</p></li><li><p>Session timeout per platform defaults</p></li></ul><p><strong>Related:</strong> Reports and executive binders &#183; Custom dashboards &#183; White-label MSP branding wiki</p><p><strong>Demo:</strong> <a href="https://dual-strike.com">dual-strike.com</a></p><div><hr></div><p><em>Portal module list is configurable &#8212; ship only what the contract includes.</em></p>]]></content:encoded></item><item><title><![CDATA[Threat Center: triage detections and FIM in one queue]]></title><description><![CDATA[From COBRA&#178; alert to closed PSA ticket &#8212; with audit trail intact.]]></description><link>https://press.dual-strike.com/p/threat-center-triage-detections-and-fim-in-one-queue</link><guid isPermaLink="false">https://press.dual-strike.com/p/threat-center-triage-detections-and-fim-in-one-queue</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Mon, 27 Jul 2026 14:32:34 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/b1706dc1-3007-461a-be1c-fcd1a696504a_960x480.svg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> From COBRA&#178; alert to closed PSA ticket &#8212; with audit trail intact.</p><div><hr></div><p><strong>Threat Center</strong> is the operational heart of Dual-Strike XISEM for MSPs running multi-client fleets. It unifies <strong>COBRA&#178; detections</strong>, <strong>file integrity (FIM) alerts</strong>, CVE correlation items, and integration health findings into a severity-sorted queue you can assign, investigate, and close.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BpCS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c8453d8-51cb-420b-98f2-93377002f5df_960x480.svg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BpCS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c8453d8-51cb-420b-98f2-93377002f5df_960x480.svg 424w, https://substackcdn.com/image/fetch/$s_!BpCS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c8453d8-51cb-420b-98f2-93377002f5df_960x480.svg 848w, https://substackcdn.com/image/fetch/$s_!BpCS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c8453d8-51cb-420b-98f2-93377002f5df_960x480.svg 1272w, https://substackcdn.com/image/fetch/$s_!BpCS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c8453d8-51cb-420b-98f2-93377002f5df_960x480.svg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BpCS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c8453d8-51cb-420b-98f2-93377002f5df_960x480.svg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0c8453d8-51cb-420b-98f2-93377002f5df_960x480.svg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Anonymized Threat Center console mockup&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Anonymized Threat Center console mockup" title="Anonymized Threat Center console mockup" srcset="https://substackcdn.com/image/fetch/$s_!BpCS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c8453d8-51cb-420b-98f2-93377002f5df_960x480.svg 424w, https://substackcdn.com/image/fetch/$s_!BpCS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c8453d8-51cb-420b-98f2-93377002f5df_960x480.svg 848w, https://substackcdn.com/image/fetch/$s_!BpCS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c8453d8-51cb-420b-98f2-93377002f5df_960x480.svg 1272w, https://substackcdn.com/image/fetch/$s_!BpCS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c8453d8-51cb-420b-98f2-93377002f5df_960x480.svg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><figcaption class="image-caption">Anonymized Threat Center console mockup</figcaption></figure></div><h2>Queue anatomy</h2><p>Column / filterOperator use <strong>Severity</strong>Critical &#8594; informational triage order <strong>Detection type</strong>COBRA, FIM, CVE, integration <strong>Client org</strong>MSP multi-tenant scope <strong>Asset / identity</strong>Pivot to Asset modal <strong>Status</strong>Open, investigating, remediated, closed <strong>PSA link</strong>Ticket ID when outfeed enabled</p><h2>FIM in Threat Center</h2><p>File integrity monitoring arrives with <strong>agent 8.8.x</strong> platform support (preview noted separately). FIM alerts surface alongside traditional detections so technicians do not maintain a second queue.</p><p>Typical FIM scenarios:</p><ul><li><p>Unauthorized change to <code>hosts</code> or critical system files</p></li><li><p>New scheduled task or service binary</p></li><li><p>Policy-defined paths on servers and privileged workstations</p></li></ul><p>Each FIM item carries <strong>before/after hash context</strong> and asset linkage &#8212; not a raw syslog line.</p><h2>PSA integration loop</h2><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_5k4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6564d55e-7bfd-462d-aa6d-18a5eab0188f_960x320.svg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_5k4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6564d55e-7bfd-462d-aa6d-18a5eab0188f_960x320.svg 424w, https://substackcdn.com/image/fetch/$s_!_5k4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6564d55e-7bfd-462d-aa6d-18a5eab0188f_960x320.svg 848w, https://substackcdn.com/image/fetch/$s_!_5k4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6564d55e-7bfd-462d-aa6d-18a5eab0188f_960x320.svg 1272w, https://substackcdn.com/image/fetch/$s_!_5k4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6564d55e-7bfd-462d-aa6d-18a5eab0188f_960x320.svg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_5k4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6564d55e-7bfd-462d-aa6d-18a5eab0188f_960x320.svg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6564d55e-7bfd-462d-aa6d-18a5eab0188f_960x320.svg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Detection to PSA ticket close sync&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Detection to PSA ticket close sync" title="Detection to PSA ticket close sync" srcset="https://substackcdn.com/image/fetch/$s_!_5k4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6564d55e-7bfd-462d-aa6d-18a5eab0188f_960x320.svg 424w, https://substackcdn.com/image/fetch/$s_!_5k4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6564d55e-7bfd-462d-aa6d-18a5eab0188f_960x320.svg 848w, https://substackcdn.com/image/fetch/$s_!_5k4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6564d55e-7bfd-462d-aa6d-18a5eab0188f_960x320.svg 1272w, https://substackcdn.com/image/fetch/$s_!_5k4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6564d55e-7bfd-462d-aa6d-18a5eab0188f_960x320.svg 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Detection to PSA ticket close sync</figcaption></figure></div><p>Supported PSA/RMM outfeeds include ConnectWise, Autotask, Halo, SuperOps, Ninja, Syncro, and others (see Integrations wiki). Workflow:</p><ol><li><p>Detection fires in Threat Center</p></li><li><p>Auto or manual ticket creation with evidence snippet</p></li><li><p>Technician remediates in client environment</p></li><li><p>Ticket closed in PSA &#8594; XISEM status sync</p></li></ol><h2>Daily standup ritual (5 minutes)</h2><ol><li><p>Sort <strong>Critical + High</strong> open items across all clients</p></li><li><p>Assign owner per ticket</p></li><li><p>Pivot any &#8220;unknown asset&#8221; rows to Inventory</p></li><li><p>Note recurring rule names for COBRA tuning this week</p></li></ol><p><strong>Route:</strong> <code>/threat-center</code></p><p><strong>Upgrade path:</strong> Agent <strong>8.7.0.17 GA</strong> today &#183; FIM capabilities in <strong>8.8</strong> release notes when promoted</p><div><hr></div><p><em>Mock data only &#8212; Northwind Traders demo tenant.</em></p>]]></content:encoded></item><item><title><![CDATA[How Dual-Strike XISEM thinks about evidence (infographic)]]></title><description><![CDATA[Collectors prove facts. The platform interprets. Humans decide.]]></description><link>https://press.dual-strike.com/p/how-dual-strike-xisem-thinks-about-evidence-infographic</link><guid isPermaLink="false">https://press.dual-strike.com/p/how-dual-strike-xisem-thinks-about-evidence-infographic</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Mon, 27 Jul 2026 14:32:11 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/d3c146e2-8608-4054-8947-17e2c8ab99e1_960x420.svg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> Collectors prove facts. The platform interprets. Humans decide.</p><div><hr></div><p>Most security stacks blur three jobs into one noisy alert stream. Dual-Strike XISEM separates them on purpose &#8212; so your analysts investigate with context, not panic.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8ewY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F952635a4-e626-4aab-9eee-bed5d33e14bf_960x420.svg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8ewY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F952635a4-e626-4aab-9eee-bed5d33e14bf_960x420.svg 424w, https://substackcdn.com/image/fetch/$s_!8ewY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F952635a4-e626-4aab-9eee-bed5d33e14bf_960x420.svg 848w, https://substackcdn.com/image/fetch/$s_!8ewY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F952635a4-e626-4aab-9eee-bed5d33e14bf_960x420.svg 1272w, https://substackcdn.com/image/fetch/$s_!8ewY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F952635a4-e626-4aab-9eee-bed5d33e14bf_960x420.svg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8ewY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F952635a4-e626-4aab-9eee-bed5d33e14bf_960x420.svg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/952635a4-e626-4aab-9eee-bed5d33e14bf_960x420.svg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Dual-Strike XISEM evidence flow: Collect, Interpret, Decide&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Dual-Strike XISEM evidence flow: Collect, Interpret, Decide" title="Dual-Strike XISEM evidence flow: Collect, Interpret, Decide" srcset="https://substackcdn.com/image/fetch/$s_!8ewY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F952635a4-e626-4aab-9eee-bed5d33e14bf_960x420.svg 424w, https://substackcdn.com/image/fetch/$s_!8ewY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F952635a4-e626-4aab-9eee-bed5d33e14bf_960x420.svg 848w, https://substackcdn.com/image/fetch/$s_!8ewY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F952635a4-e626-4aab-9eee-bed5d33e14bf_960x420.svg 1272w, https://substackcdn.com/image/fetch/$s_!8ewY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F952635a4-e626-4aab-9eee-bed5d33e14bf_960x420.svg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><figcaption class="image-caption">Dual-Strike XISEM evidence flow: Collect, Interpret, Decide</figcaption></figure></div><h2>Collect &#8212; neutral facts only</h2><p><strong>XISEM Agents</strong>, <strong>Anti-Venom Secure Access</strong>, and <strong>infeeds</strong> (Microsoft 365, EDR, PSA, identity, network) deliver timestamped evidence. They do not render verdicts. They do not enforce access. They prove what happened on a device, in a browser, or in a cloud tenant.</p><p>Examples of collection (not interpretation):</p><ul><li><p>Agent posture harvest at check-in</p></li><li><p>Browser session domain + duration from Anti-Venom</p></li><li><p>Entra sign-in success/failure</p></li><li><p>SentinelOne or CrowdStrike detection export</p></li><li><p>ConnectWise ticket status change</p></li></ul><h2>Interpret &#8212; correlation and policy</h2><p>The <strong>Dual-Strike XISEM platform</strong> correlates evidence across sources:</p><ul><li><p><strong>COBRA&#178;</strong> detection logic (rules, baselines, drift)</p></li><li><p><strong>ASPIRE</strong> posture scoring across six pillars</p></li><li><p><strong>Conditional Access intelligence</strong> at the client org level</p></li><li><p><strong>Compliance mapping</strong> to 100+ frameworks with control linkage</p></li><li><p><strong>MIP</strong> identity lifecycle and NHI governance signals</p></li></ul><p>Evidence alone is never a verdict. Interpretation produces <strong>posture</strong>, <strong>detections</strong>, and <strong>compliance gaps</strong> &#8212; still advisory until a human or approved workflow acts.</p><h2>Decide &#8212; analyst and operator actions</h2><p>The console is an <strong>investigative surface</strong>, not an autonomous enforcer:</p><ul><li><p><strong>Asset modal</strong> &#8212; timeline, matrices, extension health, pivots</p></li><li><p><strong>Threat Center</strong> &#8212; triage, assign, PSA ticket, remediate</p></li><li><p><strong>Investigations</strong> &#8212; case narrative with evidence chain</p></li><li><p><strong>Reports</strong> &#8212; executive binders and audit exports</p></li></ul><p>PSA outfeeds close the loop: detection &#8594; ticket &#8594; technician work &#8594; status sync back into XISEM.</p><h2>Why this matters for MSPs</h2><p>When you onboard a client, you are not buying another alert generator. You are buying <strong>one correlated story</strong> across agent, browser, identity, and EDR &#8212; with compliance and CA context baked in.</p><p><strong>Start here:</strong> <a href="https://dual-strike.com">dual-strike.com</a> &#183; Support wiki &#8594; Platform overview</p><div><hr></div><p><em>Illustration uses anonymized demo tenant names only.</em></p>]]></content:encoded></item><item><title><![CDATA[Extension Health: the field guide (with screenshots)]]></title><description><![CDATA[Healthy, idle, stale, not detected &#8212; what each tier means for MSPs.]]></description><link>https://press.dual-strike.com/p/extension-health-the-field-guide-with-screenshots</link><guid isPermaLink="false">https://press.dual-strike.com/p/extension-health-the-field-guide-with-screenshots</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Mon, 27 Jul 2026 14:31:47 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/1a004bcd-8fcc-4a08-b842-cff650c03f35_960x420.svg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> Healthy, idle, stale, not detected &#8212; what each tier means for MSPs.</p><div><hr></div><p><strong>Extension Health</strong> answers the question every vCISO asks after deploying Anti-Venom: <strong>&#8220;Is it actually running on the browsers we care about?&#8221;</strong> It lives in <strong>Browsing Insights</strong> and the <strong>Asset modal</strong>, with tier logic designed to reduce <strong>weekend false alarms</strong> on spare laptops.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xwfv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcc5ff8-8a99-4192-a160-942231097129_960x420.svg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xwfv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcc5ff8-8a99-4192-a160-942231097129_960x420.svg 424w, https://substackcdn.com/image/fetch/$s_!xwfv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcc5ff8-8a99-4192-a160-942231097129_960x420.svg 848w, https://substackcdn.com/image/fetch/$s_!xwfv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcc5ff8-8a99-4192-a160-942231097129_960x420.svg 1272w, https://substackcdn.com/image/fetch/$s_!xwfv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcc5ff8-8a99-4192-a160-942231097129_960x420.svg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xwfv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcc5ff8-8a99-4192-a160-942231097129_960x420.svg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2fcc5ff8-8a99-4192-a160-942231097129_960x420.svg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Anonymized Extension Health panel with tier counts&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Anonymized Extension Health panel with tier counts" title="Anonymized Extension Health panel with tier counts" srcset="https://substackcdn.com/image/fetch/$s_!xwfv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcc5ff8-8a99-4192-a160-942231097129_960x420.svg 424w, https://substackcdn.com/image/fetch/$s_!xwfv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcc5ff8-8a99-4192-a160-942231097129_960x420.svg 848w, https://substackcdn.com/image/fetch/$s_!xwfv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcc5ff8-8a99-4192-a160-942231097129_960x420.svg 1272w, https://substackcdn.com/image/fetch/$s_!xwfv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcc5ff8-8a99-4192-a160-942231097129_960x420.svg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><figcaption class="image-caption">Anonymized Extension Health panel with tier counts</figcaption></figure></div><h2>Tier definitions (operator-facing)</h2><p>TierMeaningTypical action <strong>Healthy</strong>Extension reported within normal windowNone <strong>Idle</strong>No extension ping 24&#8211;72h; agent may still check inVerify user on PTO / spare device <strong>Stale</strong>No extension &gt;72h; agent still presentSchedule revisit or decommission asset <strong>Not detected</strong>Agent active &lt;24h but no extensionDeploy/repair extension urgently</p><p><strong>Key nuance:</strong> A laptop unused since Thursday should land <strong>Idle</strong>, not <strong>Not detected</strong>, when agent check-in is older than 24h but younger than 72h.</p><h2>Orange banner semantics</h2><p>The warning banner counts endpoints where:</p><ul><li><p>Agent is <strong>recently active</strong> (&lt;24h), AND</p></li><li><p><strong>No extension</strong> has reported</p></li></ul><p>It excludes long-idle spare machines from the urgent count &#8212; truthful coverage without noise.</p><h2>By-browser columns</h2><p>Users often run <strong>Edge + Chrome</strong>. Health is <strong>per browser</strong>, not per device:</p><ul><li><p>Edge Healthy + Chrome Not detected &#8594; reinstall Chrome extension only</p></li><li><p>Both Not detected with active agent &#8594; GPO/store deployment issue</p></li></ul><h2>Rollout verification checklist</h2><ol><li><p>Deploy agent &#8594; wait for check-in</p></li><li><p>Install extension from <strong>official store</strong> listings (8.7.x line)</p></li><li><p>Browse one site &#8594; session in Browsing Insights within 15 min</p></li><li><p>Extension Health &#8594; <strong>Healthy</strong></p></li><li><p>Repeat for second browser if dual-browser standard</p></li></ol><h2>Pair with COBRA&#178;</h2><p>Rule: <strong>&#8220;Extension gap on active user workstation&#8221;</strong> should fire only on <strong>Not detected + recent agent</strong>, not Idle spare pool.</p><p><strong>Route:</strong> <code>/browsing-insights</code> &#8594; Extension Health tab</p><p><strong>Related:</strong> Browsing Insights field guide &#183; Anti-Venom Edge GA post</p><div><hr></div><p><em>Illustrative demo data &#8212; tiers reflect 8.7.0.17 platform behavior.</em></p>]]></content:encoded></item><item><title><![CDATA[MIP and the JML lifecycle: identity that keeps pace]]></title><description><![CDATA[Subtitle: Join, Move, Leave &#8212; plus non-human identity governance in one Managed Identity Provider view.]]></description><link>https://press.dual-strike.com/p/mip-and-the-jml-lifecycle-identity-that-keeps-pace</link><guid isPermaLink="false">https://press.dual-strike.com/p/mip-and-the-jml-lifecycle-identity-that-keeps-pace</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Mon, 27 Jul 2026 14:30:20 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/328a9958-68fe-4a64-a4a8-e92021cb6b31_960x400.svg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> Join, Move, Leave &#8212; plus non-human identity governance in one Managed Identity Provider view.</p><div><hr></div><p><strong>Managed Identity Provider (MIP)</strong> is Dual-Strike XISEM&#8217;s identity governance surface. It correlates <strong>Entra ID</strong>, <strong>M365</strong>, <strong>PSA/HR signals</strong>, and <strong>platform detections</strong> so human and <strong>non-human identities (NHI)</strong> do not drift unnoticed.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7E4I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18f9f2d0-2c5f-487b-9343-f757d6a555c8_960x400.svg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7E4I!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18f9f2d0-2c5f-487b-9343-f757d6a555c8_960x400.svg 424w, https://substackcdn.com/image/fetch/$s_!7E4I!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18f9f2d0-2c5f-487b-9343-f757d6a555c8_960x400.svg 848w, https://substackcdn.com/image/fetch/$s_!7E4I!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18f9f2d0-2c5f-487b-9343-f757d6a555c8_960x400.svg 1272w, https://substackcdn.com/image/fetch/$s_!7E4I!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18f9f2d0-2c5f-487b-9343-f757d6a555c8_960x400.svg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7E4I!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18f9f2d0-2c5f-487b-9343-f757d6a555c8_960x400.svg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/18f9f2d0-2c5f-487b-9343-f757d6a555c8_960x400.svg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;MIP JML lifecycle infographic&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="MIP JML lifecycle infographic" title="MIP JML lifecycle infographic" srcset="https://substackcdn.com/image/fetch/$s_!7E4I!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18f9f2d0-2c5f-487b-9343-f757d6a555c8_960x400.svg 424w, https://substackcdn.com/image/fetch/$s_!7E4I!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18f9f2d0-2c5f-487b-9343-f757d6a555c8_960x400.svg 848w, https://substackcdn.com/image/fetch/$s_!7E4I!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18f9f2d0-2c5f-487b-9343-f757d6a555c8_960x400.svg 1272w, https://substackcdn.com/image/fetch/$s_!7E4I!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18f9f2d0-2c5f-487b-9343-f757d6a555c8_960x400.svg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><figcaption class="image-caption">MIP JML lifecycle infographic</figcaption></figure></div><h2>Join &#8212; provision with evidence</h2><ul><li><p>New hire appears in PSA or HR infeed (when integrated)</p></li><li><p>Entra account created &#8594; first sign-in on Asset timeline</p></li><li><p>MIP shows <strong>provisioned</strong> state with expected group memberships</p></li><li><p>COBRA&#178; can alert on <strong>over-privileged new accounts</strong></p></li></ul><h2>Move &#8212; role change is the risky beat</h2><p>Most incidents are not joiners &#8212; they are <strong>movers</strong>:</p><ul><li><p>Department change without group cleanup</p></li><li><p>Old admin roles retained &#8220;temporarily&#8221;</p></li><li><p>License downgrade but retained SharePoint access</p></li></ul><p>MIP highlights <strong>delta</strong> between expected and actual entitlements after move events.</p><h2>Leave &#8212; deprovision completely</h2><ul><li><p>PSA offboarding ticket closed &#8800; Entra disabled (verify both)</p></li><li><p>MIP tracks <strong>disabled accounts</strong>, <strong>mailbox forwarding</strong>, <strong>active sessions</strong></p></li><li><p>Pair with <strong>Browsing Insights</strong> for OAuth grants that survive disable</p></li></ul><h2>NHI &#8212; service accounts and app registrations</h2><p>Non-human identities include:</p><ul><li><p>Azure app registrations with secrets</p></li><li><p>Service principals with Graph permissions</p></li><li><p>Legacy service accounts with password never expires</p></li></ul><p>MIP NHI panel (public marketing: <a href="https://dual-strike.com/mip">dual-strike.com/mip</a>) surfaces <strong>stale secrets</strong>, <strong>excessive API scopes</strong>, and <strong>ownerless apps</strong>.</p><h2>vCISO monthly review (30 min)</h2><ol><li><p><strong>Leavers</strong> last 30 days &#8212; all disabled in Entra?</p></li><li><p><strong>Movers</strong> &#8212; any admin role accumulation?</p></li><li><p><strong>NHI</strong> top 10 by privilege &#8212; owners assigned?</p></li><li><p>Export gaps to <strong>POA&amp;M</strong> and PSA remediation project</p></li></ol><p><strong>Related:</strong> GDAP onboarding &#183; Conditional Access intelligence &#183; MIP NHI deep dive (post #4)</p><div><hr></div><p><em>Identity evidence from infeeds &#8212; XISEM does not provision Entra directly.</em></p>]]></content:encoded></item><item><title><![CDATA[Compliance that works every day for Government Entities]]></title><description><![CDATA[Dual-Strike XISEM for Government &#8212; continuous evidence for NIST, CMMC, FedRAMP-family programs, and export-control&#8211;sensitive missions.]]></description><link>https://press.dual-strike.com/p/compliance-that-works-every-day</link><guid isPermaLink="false">https://press.dual-strike.com/p/compliance-that-works-every-day</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Mon, 27 Jul 2026 14:29:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> Dual-Strike XISEM for Government &#8212; continuous evidence for NIST, CMMC, FedRAMP-family programs, and export-control&#8211;sensitive missions.</p><div><hr></div><p>Government and defense-industrial cybersecurity has a calendar problem.</p><p>Most programs can assemble a binder for an assessment window. Fewer can answer &#8212; <strong>today</strong> &#8212; whether they are audit-ready against the frameworks they contracted, which controls fail with proof, and which remediations will move posture this sprint.</p><p>Authorizing officials want trajectory. Assessors want evidence. Operators want actions. Spreadsheet POA&amp;Ms and annual screenshot archaeology satisfy none of them for long.</p><p>Dual-Strike <strong>XISEM for Government (XISEM GOV)</strong> is the cyber operations platform for that reality: discover, secure, measure, and <strong>continuously prove</strong> compliance posture across mission systems, identities, endpoints, and enclaved workloads.</p><p>&gt; One platform to discover, secure, measure, and continuously prove compliance posture across every mission system, identity, endpoint, and enclaved workload.</p><p><strong>Explore:</strong> <a href="https://dual-strike.com/solutions/government">dual-strike.com/solutions/government</a></p><div><hr></div><h2>The government problem in plain language</h2><p>Agencies, state programs, and Defense Industrial Base contractors drown in point tools. Each tool owns a slice of truth. None owns the program narrative.</p><p>The failure mode is predictable:</p><ul><li><p>NIST and CMMC readiness lives in a GRC spreadsheet that lags live systems by months.</p></li><li><p>FedRAMP-family and StateRAMP programs scramble between 3PAO milestones instead of operating posture every day.</p></li><li><p>Privileged access is still standing admin because &#8220;the maintenance window required it.&#8221;</p></li><li><p>Browsing and SaaS risk &#8212; including Shadow AI and exfiltration-oriented behavior &#8212; sits outside the compliance story for Controlled Unclassified Information and export-sensitive work.</p></li><li><p>When an assessor asks for proof, the answer is a folder of screenshots with no provenance chain.</p></li></ul><p>XISEM GOV is not another SIEM that only stores logs, and it is not a GRC tool that only tracks policies. It turns <strong>live telemetry into defensible control evidence</strong>, plans of action and milestones (POA&amp;M), and assessor-ready binders &#8212; every day.</p><p>GRC tracks intent. XISEM feeds <strong>evidence</strong>. They complement.</p><div><hr></div><h2>Built for framework-first missions</h2><p>Government buyers are measured against frameworks &#8212; not feature lists. XISEM GOV maps evidence already in the platform to the programs those missions live under:</p><p>Program pressureMeetExceed <strong>NIST CSF / SP 800-53 / SP 800-171</strong>Live control mapping and daily evidence against the frameworks your program contractsASPIRE&#8482; / MAVICE&#8480; trajectory an authorizing official or CISO can defend &#8212; not annual screenshot archaeology <strong>CMMC Levels 1&#8211;3</strong>Level-scoped packs, POA&amp;M, and readable evidence chains for CUI environmentsRanked remediation that moves assessor outcomes this sprint &#8212; not spreadsheet theater <strong>FedRAMP / GovRAMP / StateRAMP / TX-RAMP</strong>Framework operations, binders, and accreditation-status tracking between 3PAO milestonesContinuous posture <strong>without</strong> claiming an authorization Dual-Strike has not officially attained</p><p><strong>Framework center of gravity:</strong> NIST CSF 2.0 &#183; NIST 800-171 &#183; NIST 800-53 &#183; CMMC L1&#8211;L3 &#183; FedRAMP &#183; GovRAMP &#183; StateRAMP &#183; TX-RAMP &#183; ITAR-supporting program controls &#183; DFARS cyber expectations</p><p><strong>Meet the frameworks. Exceed the binder scramble.</strong></p><div><hr></div><h2>What an authorizing official actually needs</h2><h3>Framework-first compliance</h3><p>Select the contracted set &#8212; NIST CSF, 800-171, 800-53, CMMC, FedRAMP-family packs &#8212; and operate against <strong>that</strong> set with evidence refreshed daily. Framework mapping only hurts when it is a January spreadsheet. Tie controls to live telemetry and compliance becomes a running program, not a fire drill.</p><h3>POA&amp;M and binders with provenance</h3><p>Remediation needs owners, due dates, and proof. XISEM GOV generates POA&amp;M from live control failures and packages assessor-ready binders with mappings, evidence, and provenance &#8212; so the package is a product of operations, not a weekend of archaeology.</p><h3>Secure Elevate &#8212; least privilege you can defend</h3><p>Standing administrator rights are a recurring finding and a recurring incident path. <strong>Secure Elevate</strong> eliminates standing admin and replaces it with just-in-time elevation <strong>with evidence</strong> for privileged workflows &#8212; the kind of access story an assessor and a program security officer can both accept.</p><h3>Secure Resolve and Secure Access &#8212; endpoint and browsing risk in the compliance story</h3><p><strong>Secure Resolve</strong> blocks phishing, malware, and malicious domains at the endpoint. <strong>Secure Access</strong> (Anti-Venom Secure Access) surfaces browser extensions, Shadow AI, risky SaaS, and exfiltration-oriented browsing &#8212; including signals that matter for CUI and export-sensitive environments.</p><p>Endpoint and browser risk are not &#8220;IT hygiene side quests.&#8221; They are control evidence.</p><h3>ASPIRE&#8482; and MAVICE&#8480; &#8212; executive truth with drill-down</h3><p><strong>ASPIRE&#8482;</strong> answers technical posture. <strong>MAVICE&#8480;</strong> answers maturity. Together they support the questions authorizing officials, CISOs, and boards actually ask:</p><ul><li><p>Are we audit-ready against our contracted frameworks <em>today</em>?</p></li><li><p>Which controls fail, and what evidence proves it?</p></li><li><p>What are the top remediations that move CMMC / NIST posture this sprint?</p></li><li><p>Can we show continuous improvement to an AO, 3PAO, prime, or board?</p></li></ul><p>Vendor scores without evidence are theater. Scores with drill-down to readable proof are a management system.</p><h3>Readable evidence doctrine</h3><p>Assessors and analysts should not be asked to decode raw JSON as the primary story. XISEM presents <strong>human-readable, complete evidence</strong> &#8212; labeled fields, structured detail, full pertinent facts. Raw JSON remains available as an audit appendix, not the default narrative.</p><p>That doctrine matters when a C3PAO or agency reviewer opens the console. They get evidence chains and binders &#8212; not an opaque vendor dashboard as the only artifact.</p><h3>Siloed mission tenancy</h3><p>Client and agency data stays siloed. Attribution is enforced at write time. Managed service provider rollups must not bleed one mission&#8217;s identities, events, or assets into another. Isolation is not a UI filter; it is a platform rule.</p><h3>FedRAMP journey surfaces &#8212; honest by design</h3><p>XISEM GOV includes accreditation-status tracking and compliance POA&amp;M surfaces for executive reporting <strong>between</strong> 3PAO milestones. That is operational support for a FedRAMP-oriented journey.</p><p>It is <strong>not</strong> a claim that Dual-Strike is FedRAMP authorized unless that status is separately attained and published. We support FedRAMP-oriented <strong>operations and evidence</strong>. Authorization status is separate &#8212; and we will not pretend otherwise.</p><h3>ITAR-supporting controls &#8212; not a legal determination engine</h3><p>For export-controlled programs, XISEM GOV supports the <strong>program security</strong> story: identity hygiene, least privilege, endpoint controls, and browsing / exfiltration-oriented signals with defensible audit evidence.</p><p>Legal ITAR determinations stay with counsel and the Empowered Official. The platform supports the controls; it does not replace the legal determination.</p><div><hr></div><h2>Designed for operators, not alert theater</h2><p>A Cyber Operations Platform does three jobs well:</p><ol><li><p><strong>Discover</strong> the mission footprint &#8212; assets, identities, SaaS, endpoints</p></li><li><p><strong>Secure</strong> with Elevate / Resolve / Access &#8212; least privilege and endpoint / browsing risk</p></li><li><p><strong>Prove</strong> with daily evidence, POA&amp;M, binders, and ASPIRE / MAVICE trajectory</p></li></ol><p>Logs are inputs. Evidence is the product. Action is the outcome.</p><p>That is why XISEM GOV fits agencies, DIB primes and subcontractors, state and local programs under GovRAMP / StateRAMP / TX-RAMP pressure, and government-focused MSPs who cannot afford another console that only pages people.</p><div><hr></div><h2>What we do not claim</h2><p>Public-sector buyers deserve precision:</p><ul><li><p>We do <strong>not</strong> claim FedRAMP authorization Dual-Strike has not officially attained.</p></li><li><p>We do <strong>not</strong> issue ITAR licenses or legal determinations.</p></li><li><p>We do <strong>not</strong> replace agency SOC-as-a-service mandates or official PMO / ATO packages.</p></li><li><p>We do <strong>not</strong> position XISEM as &#8220;instead of&#8221; your EDR, identity provider, or GRC system &#8212; we extend and operationalize evidence those systems produce.</p></li></ul><div><hr></div><h2>Who this is for</h2><ul><li><p>CISOs, ISSOs, and compliance managers who live under NIST / CMMC calendars</p></li><li><p>Authorizing officials, CIOs, and program executives who need trajectory, not theater</p></li><li><p>Defense Industrial Base primes and subcontractors protecting CUI</p></li><li><p>State and local programs under GovRAMP / StateRAMP / TX-RAMP expectations</p></li><li><p>C3PAOs, systems integrators, and government MSPs / MSSPs who need readable evidence packages</p></li></ul><div><hr></div><h2>Next step</h2><p>If your program can pass an assessment week but cannot prove readiness on an ordinary Tuesday, start here:</p><p><strong><a href="https://dual-strike.com/solutions/government">dual-strike.com/solutions/government</a></strong> &#183; Contact government sales &#183; Request a demo</p><p>Audit-ready today. Every day.</p><p>&#8212; The Dual-Strike team</p>]]></content:encoded></item><item><title><![CDATA[USB Prospecting Tool: win the deal before you install an agent]]></title><description><![CDATA[Subtitle: Portable LAN discovery, pipeline reporting, and a 14-day Anti-Venom Monitor trial &#8212; one platform from first meeting to managed client.]]></description><link>https://press.dual-strike.com/p/usb-prospecting-tool-win-the-deal-before-you-install-an-agent</link><guid isPermaLink="false">https://press.dual-strike.com/p/usb-prospecting-tool-win-the-deal-before-you-install-an-agent</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Mon, 27 Jul 2026 14:29:17 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/e4b05396-da12-478a-bdb9-a4a92bdf4931_960x420.svg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> Portable LAN discovery, pipeline reporting, and a 14-day Anti-Venom Monitor trial &#8212; one platform from first meeting to managed client.</p><div><hr></div><p>Most MSPs, MSSPs, and vCISO practices still walk into a first meeting with a slide deck and a promise. The <strong>USB Prospecting Tool</strong> lets you walk in with <strong>evidence</strong>.</p><p>It is a self-contained Windows assessment application &#8212; no .NET install on the prospect PC, no agent deployment, no policy enforcement. Run a LAN discovery scan on site, export a leave-behind summary, upload results into the <strong>Prospecting Center</strong>, and generate a branded HTML report before anyone signs a contract.</p><p><strong>Who it is for:</strong> MSP and MSSP sales teams, field technicians, and vCISOs doing on-site or air-gapped prospect visits. Direct commercial clients with an MSP partner use the same pipeline when their provider runs assessments.</p><p><strong>Get started:</strong> Sign in at <a href="https://dual-strike.com">dual-strike.com</a>, open <strong>Tenants and Prospects &#8594; Prospects</strong>, and download the <strong>Prospect Scanner USB Win64</strong> package from the MSP download card. This tool is partner-only &#8212; it is not on the public agent downloads page.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HHgf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F021e177d-a964-46c3-b603-33fe56cf65c7_960x420.svg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HHgf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F021e177d-a964-46c3-b603-33fe56cf65c7_960x420.svg 424w, https://substackcdn.com/image/fetch/$s_!HHgf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F021e177d-a964-46c3-b603-33fe56cf65c7_960x420.svg 848w, https://substackcdn.com/image/fetch/$s_!HHgf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F021e177d-a964-46c3-b603-33fe56cf65c7_960x420.svg 1272w, https://substackcdn.com/image/fetch/$s_!HHgf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F021e177d-a964-46c3-b603-33fe56cf65c7_960x420.svg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HHgf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F021e177d-a964-46c3-b603-33fe56cf65c7_960x420.svg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/021e177d-a964-46c3-b603-33fe56cf65c7_960x420.svg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Prospect to client evidence flow: LAN scan on USB, interpret in Prospecting Center, decide with reports and trial&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Prospect to client evidence flow: LAN scan on USB, interpret in Prospecting Center, decide with reports and trial" title="Prospect to client evidence flow: LAN scan on USB, interpret in Prospecting Center, decide with reports and trial" srcset="https://substackcdn.com/image/fetch/$s_!HHgf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F021e177d-a964-46c3-b603-33fe56cf65c7_960x420.svg 424w, https://substackcdn.com/image/fetch/$s_!HHgf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F021e177d-a964-46c3-b603-33fe56cf65c7_960x420.svg 848w, https://substackcdn.com/image/fetch/$s_!HHgf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F021e177d-a964-46c3-b603-33fe56cf65c7_960x420.svg 1272w, https://substackcdn.com/image/fetch/$s_!HHgf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F021e177d-a964-46c3-b603-33fe56cf65c7_960x420.svg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><figcaption class="image-caption">Prospect to client evidence flow: LAN scan on USB, interpret in Prospecting Center, decide with reports and trial</figcaption></figure></div><h2>Why this is a game changer for MSPs, MSSPs, and MIPs</h2><p><strong>Assessment before the contract.</strong> You do not need prospect IT to install software, open firewall ports, or provision a tenant before you can show value. One permitted run on a workstation gives you a network map, host inventory from discovery, open ports, and remote-access signals &#8212; enough to anchor a credible first conversation.</p><p><strong>One platform from prospect to client.</strong> USB scans land in the same Dual-Strike XISEM console as production agents. When the deal closes, you are not migrating tools &#8212; you are extending coverage. Full posture sections &#8212; Active Directory, patching, security tools, browser posture &#8212; unlock after <strong>XISEM Agent</strong> enrollment on managed endpoints.</p><p><strong>Pipeline built in, not bolted on.</strong> The Prospecting Center tracks stages from Identification through Result, pipeline value, next actions, and prospect types including One-Off, MSP, MSSP, and Trial. Inbound leads from marketing pages and SuperOps trial imports feed the same funnel.</p><p><strong>Free assessment edition.</strong> Unlike stacks that charge for discovery appliances or per-seat assessment SKUs, the USB Prospecting Tool ships with XISEM partner releases at no separate assessment license. Your cost is technician time &#8212; not another product line item.</p><h2>What the USB Prospecting Tool does</h2><h3>LAN discovery scan</h3><p>The scanner runs native on-network discovery: ICMP reachability, ARP cache, reverse DNS, TCP port checks, and OS hints. Results use the same contract as XISEM Agent NetRecon, so findings correlate cleanly when you enroll agents later.</p><p>Typical first-meeting outputs include:</p><ul><li><p>Remote hosts &#8212; IP, hostname, MAC where available</p></li><li><p>Open ports and inferred services</p></li><li><p>Weak OS fingerprint guesses</p></li><li><p>RMM and remote-access tools inferred from open ports</p></li><li><p>Local JSON and HTML archives beside the executable for leave-behind</p></li></ul><h3>Three ways to link a scan to your pipeline</h3><p>Choose the mode that fits the visit:</p><ol><li><p><strong>New prospect</strong> &#8212; enter company name; the platform creates the prospect record on first upload.</p></li><li><p><strong>Link code</strong> &#8212; enter the eight-digit code from the prospect detail dialog in the console. Codes expire after thirty days.</p></li><li><p><strong>Signed in</strong> &#8212; authenticate with your Dual-Strike credentials and pick from your active prospect list.</p></li></ol><h3>Multi-PC and multi-subnet site visits</h3><p>Large sites rarely fit on one machine. Copy the tool to an encrypted USB drive. The first PC creates or links the prospect. Each additional PC appends scan sections to the same prospect record. Unique scan IDs keep every run traceable.</p><p>Scan offline if needed. Upload when you have connectivity and a configured infeed token.</p><h3>Headless automation</h3><p>For scripted field kits, run <code>XISEM.ProspectingScanner.App.exe --nogui "Company Name"</code> to scan and upload without the graphical interface.</p><p>Override scan targets with the <code>XISEM_SCAN_TARGET</code> environment variable when you need a specific CIDR or IP list.</p><h2>Prospecting Center: reporting and sales workflow</h2><p>After upload, open the prospect in <strong>Tenants and Prospects &#8594; Prospects</strong>.</p><h3>Sales pipeline</h3><p>Track six stages &#8212; Identification, Initial Meeting, Assessment, Quotation, Proposal, and Result &#8212; with status, estimated value, close dates, and upcoming actions. The funnel chart shows where active deals sit at a glance.</p><h3>Scan Data and HTML reports</h3><p>The <strong>Scan Data</strong> tab shows structured sections from every upload. Click <strong>Generate Report</strong> for a downloadable HTML assessment.</p><p>USB-only runs are labeled <strong>LAN Discovery Assessment</strong>. Sections that require agent enrollment &#8212; AD, host inventory, patching, security tools &#8212; are marked <em>Available after enrollment</em>, which sets honest expectations and creates a natural upsell path.</p><p>Reports are print-friendly: clean typography, metric cards, and finding callouts designed for executive readouts and PDF export from the browser.</p><h3>Integrations that close the loop</h3><p>Link prospects to SuperOps accounts, Hudu companies, and trial IDs. Hudu sync modes &#8212; automatic, manual, or conversion-only &#8212; keep documentation aligned with your PSA workflow.</p><p>Import SuperOps trial orgs directly into the pipeline with <strong>Import Trials</strong>.</p><h2>Anti-Venom Monitor: 14-day trial inside Prospecting</h2><p>Starting with Prospecting workflows, partners can offer prospects a <strong>14-day Dual-Strike XISEM platform trial</strong> that includes <strong>Anti-Venom Secure Access in Monitor mode</strong>.</p><p>Monitor mode is observe-only. It runs full indicator lookups and provider feed validation without watermarks or blocking. Your prospect sees real browsing telemetry &#8212; SaaS usage, AI tool sessions, MFA app patterns &#8212; while you build the case for Protect mode after contract signature.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GQ0N!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4592683-b817-42ac-a767-d6b9347eb4c8_1080x1080.svg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GQ0N!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4592683-b817-42ac-a767-d6b9347eb4c8_1080x1080.svg 424w, https://substackcdn.com/image/fetch/$s_!GQ0N!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4592683-b817-42ac-a767-d6b9347eb4c8_1080x1080.svg 848w, https://substackcdn.com/image/fetch/$s_!GQ0N!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4592683-b817-42ac-a767-d6b9347eb4c8_1080x1080.svg 1272w, https://substackcdn.com/image/fetch/$s_!GQ0N!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4592683-b817-42ac-a767-d6b9347eb4c8_1080x1080.svg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GQ0N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4592683-b817-42ac-a767-d6b9347eb4c8_1080x1080.svg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d4592683-b817-42ac-a767-d6b9347eb4c8_1080x1080.svg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Week one Anti-Venom Monitor fleet results: browser sessions captured, SaaS and AI discovery, zero blocking in Monitor mode&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Week one Anti-Venom Monitor fleet results: browser sessions captured, SaaS and AI discovery, zero blocking in Monitor mode" title="Week one Anti-Venom Monitor fleet results: browser sessions captured, SaaS and AI discovery, zero blocking in Monitor mode" srcset="https://substackcdn.com/image/fetch/$s_!GQ0N!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4592683-b817-42ac-a767-d6b9347eb4c8_1080x1080.svg 424w, https://substackcdn.com/image/fetch/$s_!GQ0N!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4592683-b817-42ac-a767-d6b9347eb4c8_1080x1080.svg 848w, https://substackcdn.com/image/fetch/$s_!GQ0N!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4592683-b817-42ac-a767-d6b9347eb4c8_1080x1080.svg 1272w, https://substackcdn.com/image/fetch/$s_!GQ0N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4592683-b817-42ac-a767-d6b9347eb4c8_1080x1080.svg 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Week one Anti-Venom Monitor fleet results: browser sessions captured, SaaS and AI discovery, zero blocking in Monitor mode</figcaption></figure></div><p><strong>Recommended prospect journey:</strong></p><ol><li><p><strong>Day zero</strong> &#8212; USB LAN discovery at the first meeting. Leave behind local HTML summary.</p></li><li><p><strong>Day one</strong> &#8212; Upload to Prospecting Center. Generate branded LAN Discovery report for IT leadership.</p></li><li><p><strong>Days one through fourteen</strong> &#8212; Deploy XISEM Agent to a pilot group. Enable Anti-Venom Monitor on Chrome, Edge, Firefox, or Safari. Review Browsing Insights with the prospect.</p></li><li><p><strong>Day fourteen</strong> &#8212; Walk through ASPIRE posture, Threat Center context, and a scoped proposal. Convert prospect to client.</p></li></ol><p>The platform trial supports up to five client tenants with no credit card required. Pair it with the USB assessment for a complete pre-contract story: <strong>network truth on day zero, browser truth by day seven.</strong></p><h2>What it does not do</h2><p>Be direct with prospects:</p><ul><li><p>The USB tool does <strong>not</strong> replace production XISEM Agent deployment.</p></li><li><p>It does <strong>not</strong> send data without your configured upload and explicit action.</p></li><li><p>It does <strong>not</strong> enforce policies, block users, or install persistent services &#8212; assessment only.</p></li><li><p>Full posture sections require agent enrollment after conversion.</p></li></ul><p>That honesty is a feature. Prospects trust read-only snapshots. Production monitoring uses the same evidence doctrine with continuous correlation in Dual-Strike XISEM.</p><h2>Field workflow checklist</h2><ol><li><p>Download the USB package from Prospecting Center. Extract to an encrypted USB drive.</p></li><li><p>Optionally place <code>prospect_scanner.settings.json</code> beside the executable with your infeed token.</p></li><li><p>Run on a prospect workstation with written permission.</p></li><li><p>Review findings with the IT lead on site.</p></li><li><p>Upload to XISEM. Open Scan Data and generate the HTML report.</p></li><li><p>Start the 14-day trial with Anti-Venom Monitor on pilot endpoints.</p></li><li><p>On signature: convert prospect, deploy fleet agents, and advance Monitor to Protect when ready.</p></li></ol><h2>Talk track</h2><p>&gt; "This is a read-only LAN discovery snapshot &#8212; no agents installed, no blocking, no data leaving your network until you approve upload. If we partner, the same platform carries from this assessment through managed monitoring, browser security, and compliance reporting. We can even run Anti-Venom in Monitor mode for two weeks so you see real browsing telemetry before anything is enforced."</p><p><strong>Related reading:</strong> MSP first 7 days quickstart &#183; ASPIRE scoring &#183; Evidence doctrine infographic</p><p><strong>Next step:</strong> <a href="https://dual-strike.com">dual-strike.com</a> &#183; Partner program at <code>/get-xisem/msp</code> &#183; Request a demo</p><div><hr></div><p><em>Illustrations use anonymized demo data. USB Prospecting Tool version aligns with current XISEM GA releases &#8212; check the Prospecting Center download card for build number and SHA-256.</em></p>]]></content:encoded></item><item><title><![CDATA[Introducing Anti-Venom Secure Resolve]]></title><description><![CDATA[Subtitle: Browser enforcement where users click.]]></description><link>https://press.dual-strike.com/p/introducing-anti-venom-secure-resolve</link><guid isPermaLink="false">https://press.dual-strike.com/p/introducing-anti-venom-secure-resolve</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Mon, 27 Jul 2026 14:28:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> Browser enforcement where users click. Resolver enforcement everywhere else. One policy story, one investigation timeline.</p><div><hr></div><p>Roaming DNS is still the quiet gap in endpoint security.</p><p>Users leave the office. VPN split-tunnel fights the roaming client. Windows 11 enables encrypted DNS in Settings. Browsers send queries around the OS resolver. The SIEM gets a vendor export from last month &#8212; not proof that a block happened on <em>this</em> laptop, for <em>this</em> user, <em>now</em>.</p><p><strong>Anti-Venom Secure Access</strong> already covers the browser: session telemetry, verdict watermarks, AI-tool visibility, and policy in Chrome, Edge, and Firefox &#8212; correlated in <strong>Browsing Insights</strong> and investigations.</p><p>Today we name the network half:</p><h2>Anti-Venom Secure Resolve</h2><p>Dual-Strike XISEM&#8217;s first-party <strong>endpoint DNS protection</strong> &#8212; a lightweight bolt-on that works <strong>with</strong> Secure Access, not instead of it.</p><p>LayerProductWhat it protects <strong>BrowserAnti-Venom Secure Access</strong>Tabs, sessions, phishing paths, SaaS and AI-tool policy <strong>Network / resolverAnti-Venom Secure Resolve</strong>OS and app DNS before traffic leaves the endpoint</p><p>Same Anti-Venom family. Different surface. One correlated picture in the console.</p><h2>Why two products?</h2><p><strong>No single hook sees every query.</strong></p><ul><li><p><strong>Secure Access</strong> &#8212; inside the browser, including DoH bypass paths and session-level policy</p></li><li><p><strong>Secure Resolve</strong> &#8212; at the system resolver: apps, scripts, and background agents that never open a tab</p></li></ul><p>Together they cover home ISP routers, split-tunnel VPN, Win10/Win11 encrypted DNS, and non-browser software that still phones home over DNS. Neither replaces your EDR. Both feed Dual-Strike XISEM&#8217;s evidence doctrine &#8212; neutral facts in, correlated posture and investigations out.</p><h2>What Secure Resolve does</h2><p>Paired with the <strong>Dual-Strike XISEM Agent</strong> on Windows 10 and 11:</p><ul><li><p><strong>Local-first policy</strong> &#8212; lists cached on the endpoint; cloud for sync and evidence</p></li><li><p><strong>VPN- and NRPT-aware</strong> &#8212; internal zones stay on VPN DNS; yields to known relays instead of fighting them</p></li><li><p><strong>Encrypted upstream</strong> &#8212; aligned with modern Windows DoH/DoT</p></li><li><p><strong>Evidence in the same pane</strong> &#8212; batched query and block events for ASPIRE, COBRA&#178;, and investigations</p></li><li><p><strong>MSP policy packs</strong> &#8212; one baseline, per-client exceptions, approve/deny without a second vendor console</p></li><li><p><strong>Learning mode first</strong> &#8212; log would-block before enforce, like Secure Access</p></li></ul><p><strong>Defense in depth:</strong> Resolve blocks C2 and unwanted categories at the resolver. Secure Access enforces browser policy on what users actually visit. When browser DoH bypasses OS DNS, Secure Access still sees it. When malware resolves a domain outside the browser, Secure Resolve still sees it.</p><h2>Your DNS, your choice</h2><p>Already on <strong>DNSFilter</strong> or another DNS infeed? Keep it. Third-party DNS stays in the open integration fabric &#8212; evidence in, correlation out. Secure Resolve is the <strong>first-party bolt-on</strong> for MSPs who want policy and unblock workflow inside Dual-Strike XISEM. Run either, or both while you migrate.</p><h2>Who it is for</h2><p>MSPs standardizing browser and resolver policy on one console. vCISO teams tired of &#8220;DNS active&#8221; posture with no per-endpoint proof. Distributed shops where legacy roaming clients break on VPN and Win11. Existing <strong>Secure Access</strong> customers adding resolver coverage without a second product story.</p><h2>Availability</h2><p><strong>Anti-Venom Secure Resolve</strong> ships on the <strong>Dual-Strike XISEM Agent 8.8+</strong> line as a bolt-on SKU &#8212; same release train as the Windows agent and Edge Scan Sensor.</p><p>PhaseWhat <strong>Now</strong>Product naming and MSP preview enrollment <strong>Next</strong>Windows resolver preview &#8212; audit mode and DNS evidence in investigations <strong>GA</strong>Enforce mode, unified block/unblock with existing DNS infeeds, in-console policy packs</p><p><strong>Early access:</strong> Reply here or reach us via <a href="https://dual-strike.com">dual-strike.com</a> &#8212; share your Secure Access footprint, VPN mix, and any third-party DNS infeed.</p><p><strong>Already on Secure Access?</strong> No browser redeploy required. Resolve adds the resolver layer when you are ready.</p><p><strong>Downloads (agent + extension today):</strong> <a href="https://dual-strike.com/downloads">dual-strike.com/downloads</a></p><p>&gt; <strong>Secure Access protects the browser. Secure Resolve protects the resolver. Dual-Strike XISEM connects both to identity, device, and investigation &#8212; so DNS is evidence, not a checkbox.</strong></p><div><hr></div><p><em>Anti-Venom Secure Access and Anti-Venom Secure Resolve are components of Dual-Strike XISEM. Third-party DNS integrations remain optional. Confirm current GA status on dual-strike.com before customer commitments.</em></p>]]></content:encoded></item><item><title><![CDATA[Introducing STAP: Strategic Technology Alliance Program]]></title><description><![CDATA[Subtitle: Dual-Strike XISEM extends your stack &#8212; it doesn't replace it.]]></description><link>https://press.dual-strike.com/p/introducing-stap-strategic-technology-alliance-program</link><guid isPermaLink="false">https://press.dual-strike.com/p/introducing-stap-strategic-technology-alliance-program</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Mon, 27 Jul 2026 14:28:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> Dual-Strike XISEM extends your stack &#8212; it doesn't replace it. Here's how we talk about technology alliances with MSPs and partners.</p><div><hr></div><p>If you run an MSP, you already bought the stack. PSA. RMM. EDR. Identity. DNS. Browser controls. You don't need another vendor telling you to rip and replace.</p><p>You need a <strong>Cyber Operations Platform</strong> that makes what you already run <strong>more valuable</strong> &#8212; correlated, reportable, and actionable for technicians and executives alike.</p><p>That's what the <strong>Strategic Technology Alliance Program (STAP)</strong> is for.</p><p>STAP is <strong>not</strong> an integrations program. It's a <strong>technology alliance framework</strong>: mutual value between Vysion Technology Solutions, alliance partners, MSPs, MSSPs, MIPs, and shared customers.</p><div><hr></div><h2>What STAP means for your operation</h2><p>Dual-Strike XISEM <strong>extends, enriches, operationalizes, and orchestrates</strong> existing technology investments. Every alliance partner should feel that XISEM improves adoption, visibility, executive reporting, operational intelligence, and customer outcomes for their platform.</p><p>Three concepts to remember:</p><ol><li><p><strong>Cyber Operations Platform</strong> &#8212; XISEM is the layer above your tools, not a substitute for them.</p></li><li><p><strong>Shared Security Context</strong> &#8212; telemetry from every alliance enriches every other source continuously.</p></li><li><p><strong>Operational Intelligence</strong> &#8212; correlated events become decisions your team can act on Monday morning.</p></li></ol><div><hr></div><h2>Shared Security Context</h2><p>Products don't operate in silos. Telemetry from Microsoft, EDR, identity, DNS, browsers, Scout, and alliance gateways flows into one shared context &#8212; then becomes Operational Intelligence.</p><p>```mermaid</p><p>flowchart TB</p><p>MS[Microsoft]</p><p>S1[SentinelOne]</p><p>TL[ThreatLocker]</p><p>GZ[Guardz]</p><p>PT[Petra]</p><p>DNS[DNS]</p><p>BR[Browsers]</p><p>ID[Identity]</p><p>SC[Scout]</p><p>SN[Sonar]</p><p>CB[COBRA&#178;]</p><p>SSC[Shared Security Context]</p><p>OI[Operational Intelligence]</p><p>MS --&gt; SSC</p><p>S1 --&gt; SSC</p><p>TL --&gt; SSC</p><p>GZ --&gt; SSC</p><p>PT --&gt; SSC</p><p>DNS --&gt; SSC</p><p>BR --&gt; SSC</p><p>ID --&gt; SSC</p><p>SC --&gt; SSC</p><p>SN --&gt; SSC</p><p>CB --&gt; SSC</p><p>SSC --&gt; OI</p><p>```</p><div><hr></div><h2>Messaging: do this, not that</h2><p>AvoidPrefer XISEM replaces SentinelOneXISEM operationalizes SentinelOne telemetry XISEM replaces ThreatLockerXISEM extends ThreatLocker policy intelligence through Shared Security Context XISEM replaces HuntressXISEM enriches Huntress detections with browser, identity, DNS, compliance, and organizational context XISEM integrates with GuardzXISEM operationalizes Guardz intelligence through graph correlation and executive reporting</p><p><strong>Never state or imply:</strong> replace &#183; compete with &#183; alternative to &#183; instead of</p><p><strong>Preferred language:</strong> extends &#183; enriches &#183; correlates &#183; operationalizes &#183; orchestrates &#183; amplifies &#183; unifies &#183; enhances</p><div><hr></div><h2>Launch Packs (curated onboarding)</h2><p>STAP onboarding is organized into <strong>Launch Packs</strong> &#8212; not one-off vendor checkboxes:</p><p>Launch PackAlliances <strong>MSP Essentials</strong>XISEM, SuperOps, Microsoft 365, Anti-Venom <strong>Identity Protection</strong>XISEM, Petra, Keeper <strong>Business Protection</strong>XISEM, Guardz, Anti-Venom <strong>Endpoint Security</strong>XISEM, SentinelOne, ThreatLocker, Huntress <strong>Compliance</strong>XISEM, Petra, ASPIRE, MAVICE, CAA</p><p>Select a Launch Pack in <strong>Partner Center &#8594; New Prospect</strong> when standing up a new evaluation.</p><div><hr></div><h2>Priority alliances (where we're investing first)</h2><p><strong>Priority 1:</strong> SuperOps &#183; Petra &#183; Guardz</p><p><strong>Priority 2:</strong> SentinelOne &#183; ThreatLocker &#183; Huntress &#183; Keeper &#183; Proofpoint &#183; DNSFilter</p><p>Each alliance in Partner Center shows status, gateway availability, Launch Pack placement, evaluation support, and documentation links.</p><div><hr></div><h2>What you can do today</h2><ul><li><p><strong>Explore alliances:</strong> <a href="https://dual-strike.com/partners">dual-strike.com/partners</a></p></li><li><p><strong>Program overview:</strong> <a href="https://dual-strike.com/support/stap-strategic-technology-alliance-program">dual-strike.com/support/stap-strategic-technology-alliance-program</a></p></li><li><p><strong>MSP partners:</strong> apply through Partner Center for Launch Packs, evaluations, and federation</p></li></ul><p>We won't ask you to abandon the vendors your clients already trust. We will help you <strong>operationalize</strong> them &#8212; together &#8212; through Shared Security Context.</p><p>&#8212; The Dual-Strike team</p>]]></content:encoded></item><item><title><![CDATA[Every campus. One cyber posture. 👍 XISEM for Education.]]></title><description><![CDATA[Subtitle: Dual-Strike XISEM for Education &#8212; how districts with thin IT teams discover, secure, measure, and prove continuous improvement.]]></description><link>https://press.dual-strike.com/p/every-campus-one-cyber-posture</link><guid isPermaLink="false">https://press.dual-strike.com/p/every-campus-one-cyber-posture</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Mon, 27 Jul 2026 14:28:08 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> Dual-Strike XISEM for Education &#8212; how districts with thin IT teams discover, secure, measure, and prove continuous improvement.</p><div><hr></div><p>K-12 cybersecurity has a visibility problem dressed up as a tooling problem.</p><p>Most districts already own an endpoint product, a filter, and a Microsoft 365 or Google Workspace tenancy. What they rarely own is a single, honest answer to the questions a superintendent and a school board actually ask:</p><ol><li><p><strong>Are we more secure than last month?</strong></p></li><li><p><strong>Which schools or campuses are at greatest risk?</strong></p></li><li><p><strong>What are the top five actions that will improve our posture?</strong></p></li><li><p><strong>Can we prove improvement for grants, insurers, and state reporting?</strong></p></li></ol><p>Those are not SIEM questions. They are <strong>operations</strong> questions. Dual-Strike <strong>XISEM for Education (XISEM EDU)</strong> is built for that reality: a cyber operations platform for districts that do not have a twenty-person security operations center &#8212; and should not need one to run a defensible program.</p><p>&gt; One platform to discover, secure, measure, and prove continuous improvement across every student, staff member, classroom, and campus.</p><p><strong>Explore:</strong> <a href="https://dual-strike.com/solutions/education">dual-strike.com/solutions/education</a></p><div><hr></div><h2>The district problem in plain language</h2><p>Schools face ransomware, credential theft, and data exposure with staffing that would be called &#8220;under-resourced&#8221; in any private enterprise. Point tools create alert noise. Boards and grantors ask for <strong>measurable improvement</strong>, not another dashboard login.</p><p>The failure mode is familiar:</p><ul><li><p>Inventory lives in three places and none of them know about the smart board, the lab printer, or the Chromebook that never joined the right OU.</p></li><li><p>Teachers still have standing local admin &#8220;because the projector driver broke last semester.&#8221;</p></li><li><p>Filtering works on campus and softens once students and staff leave the network.</p></li><li><p>Compliance evidence is assembled in January for a binder that is stale by March.</p></li><li><p>When something happens, the story is scattered across logs, tickets, and screenshots &#8212; not a readable timeline a small team can act on.</p></li></ul><p>XISEM EDU does not ask districts to throw away what already works. It <strong>correlates</strong> identity, assets, browsing, endpoint controls, and compliance evidence into one posture story those tools cannot tell alone.</p><div><hr></div><h2>Built for the Enhancing K-12 Cybersecurity Act agenda</h2><p>The bipartisan <a href="https://www.nextgov.com/cybersecurity/2023/04/lawmakers-reintroduce-bill-bolster-cybersecurity-k-12-schools/385366/">Enhancing K-12 Cybersecurity Act</a> (reintroduced 2023) points CISA toward three outcomes for primary and secondary schools:</p><ol><li><p><strong>Information, best practices, and training</strong> through a cybersecurity information exchange</p></li><li><p><strong>Incident visibility</strong> through voluntary K-12 cyber incident tracking</p></li><li><p><strong>Technology improvement</strong> &#8212; helping schools deploy cybersecurity capabilities against real risks to school information systems</p></li></ol><p>XISEM EDU is not a substitute for CISA programs or mandated reporting. It is the <strong>district operating layer</strong> that turns that agenda into daily posture, measurable improvement, and audit-ready proof.</p><p>What the Act pushes towardHow XISEM EDU meets itHow XISEM EDU goes further Information, best practices &amp; trainingCISA-aligned guidance in live compliance dashboards &#8212; not a static PDF toolkitLive top-five actions and campus risk ranking every day Incident tracking &amp; threat landscapeEvidence-driven detections, alerts, and readable investigation timelinesOptional Community Gateway &#8212; anonymized ESC/SEA trends without student PII Deploy cybersecurity capabilitiesScout agents, Secure Elevate / Resolve / Access, Microsoft 365 + Google Workspace + Active Directory identityAutomated grant evidence &#8212; before/after posture and control proof packs</p><p><strong>Meet the Act. Exceed the toolkit.</strong></p><div><hr></div><h2>What a superintendent actually needs</h2><h3>Complete campus discovery</h3><p>Security programs fail when they only know about the Windows laptop that enrolled cleanly. XISEM EDU discovers across the real campus footprint: Windows, macOS, Chromebooks (where supported), Linux, mobile, network gear, printers, IoT, cameras, smart boards, and lab equipment.</p><p>You cannot protect what you cannot see &#8212; and you cannot rank campus risk without a complete inventory.</p><h3>Identity for schools</h3><p>Districts run hybrid identity worlds. XISEM EDU correlates <strong>Microsoft 365</strong>, <strong>Google Workspace</strong>, and <strong>Active Directory / LDAP</strong> so dormant accounts, privilege creep, and impossible travel / geo-velocity show up as identity posture &#8212; with staff versus student context where the environment supports it.</p><p>Identity is not a separate product silo. It is part of the same story as the device and the browsing session.</p><h3>Secure Elevate &#8212; end standing admin for teachers and IT</h3><p>Standing local administrator rights are still one of the most common ways a phishing click becomes a district-wide incident. <strong>Secure Elevate</strong> eliminates permanent teacher and IT admin rights and replaces them with just-in-time elevation <strong>with evidence</strong> &#8212; so helpdesk workflows still work, and auditors can see who elevated, when, and why.</p><h3>Secure Resolve &#8212; protection that travels</h3><p>Students and staff leave campus. Threats do not respect the firewall. <strong>Secure Resolve</strong> blocks phishing, malware, and inappropriate domains at the endpoint &#8212; on campus or at home &#8212; so filtering posture is not a building-hours feature.</p><h3>Secure Access &#8212; Shadow AI, risky SaaS, and browser risk</h3><p>Classroom and staff browsing is where Shadow AI tools, risky SaaS, and exfiltration-oriented behavior show up first. <strong>Secure Access</strong> (Anti-Venom Secure Access) monitors browser extensions, Shadow AI usage, risky SaaS, and data-exfiltration oriented browsing signals &#8212; so IT can teach, policy, and remediate with facts instead of rumor.</p><h3>Compliance without the binder chase</h3><p>Grantors, insurers, and state programs ask for alignment to <strong>CIS Controls</strong>, <strong>NIST Cybersecurity Framework</strong>, and <strong>CISA K-12 guidance</strong>. XISEM EDU maps live evidence into compliance dashboards, daily control refresh, plans of action and milestones (POA&amp;M), and grant-ready packs &#8212; so &#8220;prove improvement&#8221; is not a weekend of screenshots.</p><h3>ASPIRE&#8482; and MAVICE&#8480; &#8212; scores that answer human questions</h3><p><strong>ASPIRE&#8482;</strong> is technical posture truth. <strong>MAVICE&#8480;</strong> is maturity. Together they answer board-level questions without translating ten thousand alerts:</p><ul><li><p>Are we more secure than last month?</p></li><li><p>Which campuses are at risk?</p></li><li><p>What are the top five actions?</p></li></ul><p>Scores without drill-down are vanity. XISEM EDU ties letter grades and trends back to evidence a small team can act on.</p><h3>Community Gateway (optional) &#8212; share trends, not student data</h3><p>Educational Service Centers and State Education Agencies need regional awareness without becoming a privacy liability. The optional <strong>Community Gateway</strong> supports anonymized, aggregated rollups for ransomware, phishing, and vulnerable-technology trends &#8212; without exposing student personally identifiable information in shared telemetry.</p><p>Districts stay siloed. Shared views stay privacy-first and FERPA-aware by design.</p><div><hr></div><h2>Designed for thin IT teams</h2><p>XISEM EDU is intentionally <strong>not</strong> another alert factory.</p><p>A district with two or three technology staff members cannot live inside a log warehouse. They need:</p><ul><li><p><strong>Discovery</strong> that covers classroom reality</p></li><li><p><strong>Controls</strong> that fit helpdesk workflows (Elevate / Resolve / Access)</p></li><li><p><strong>Measurement</strong> a superintendent can understand</p></li><li><p><strong>Evidence</strong> that survives a grant review or insurance questionnaire</p></li></ul><p>That is the difference between a cyber operations platform and a pile of point products that never become a program.</p><div><hr></div><h2>What we do not claim</h2><p>Honesty matters in public sector sales:</p><ul><li><p>XISEM EDU does <strong>not</strong> replace CISA, MS-ISAC, or mandated incident reporting to federal or state agencies.</p></li><li><p>It does <strong>not</strong> claim to be a complete legal FERPA determination engine &#8212; it supports a privacy-aware operating posture (siloed tenants, minimized student data in shared views, anonymized community trends).</p></li><li><p>It does <strong>not</strong> ask you to rip out your EDR or web filter. Keep them. XISEM correlates what they cannot see alone.</p></li></ul><div><hr></div><h2>Who this is for</h2><ul><li><p>District CIOs and Directors of Technology</p></li><li><p>Superintendents and board cyber committees who need measurable improvement</p></li><li><p>Educational Service Centers and State Education Agency cybersecurity coordinators</p></li><li><p>Education-focused MSPs and MSSPs supporting multi-district portfolios</p></li></ul><div><hr></div><h2>Next step</h2><p>If your district is drowning in tools and still cannot answer &#8220;are we better than last month,&#8221; start here:</p><p><strong><a href="https://dual-strike.com/solutions/education">dual-strike.com/solutions/education</a></strong> &#183; Contact education sales &#183; Request a demo</p><p>Secure the classroom. Prove the posture.</p><p>&#8212; The Dual-Strike team</p>]]></content:encoded></item><item><title><![CDATA[Edge Scan Sensor: the lowest-cost way to see a remote LAN]]></title><description><![CDATA[Subtitle: Bring your own Raspberry Pi.]]></description><link>https://press.dual-strike.com/p/edge-scan-sensor-the-lowest-cost-way-to-see-a-remote-lan</link><guid isPermaLink="false">https://press.dual-strike.com/p/edge-scan-sensor-the-lowest-cost-way-to-see-a-remote-lan</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Mon, 27 Jul 2026 14:27:37 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/5c36cf36-2e61-48a3-9538-9287b57ce7f1_1080x520.svg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Subtitle:</strong> Bring your own Raspberry Pi. Get always-on site discovery, overnight visibility, and a first-class XISEM asset &#8212; without leaving a PC running.</p><div><hr></div><p>Remote offices, warehouse VLANs, clinic branches, and ISP-router flat networks share one problem: <strong>no always-on workstation</strong>.</p><p>Traditional RMM discovery assumes a managed PC stays online. Traverse-style site scanners assume you will ship an appliance subscription. Dual-Strike XISEM solves the gap with the <strong>Edge Scan Sensor</strong> &#8212; a headless Linux collector built for Raspberry Pi and other arm64 boxes that lives on the customer LAN and phones home to your console.</p><p><strong>Who it is for:</strong> MSPs and MSSPs shipping plug-and-play sensors to client sites. Direct commercial clients with multi-site footprints. Any practice that needs nominated site scans and network inventory where a full desktop agent is impractical.</p><p><strong>Why partners call it a game changer:</strong> Commodity hardware, a free public installer, per-asset platform pricing, and the same correlation engine as your Windows fleet &#8212; without a second NMS bill or a workstation burning power overnight.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JG6Q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78287fc7-f3f0-434a-8dab-fca9ebcac7c6_1080x520.svg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JG6Q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78287fc7-f3f0-434a-8dab-fca9ebcac7c6_1080x520.svg 424w, https://substackcdn.com/image/fetch/$s_!JG6Q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78287fc7-f3f0-434a-8dab-fca9ebcac7c6_1080x520.svg 848w, https://substackcdn.com/image/fetch/$s_!JG6Q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78287fc7-f3f0-434a-8dab-fca9ebcac7c6_1080x520.svg 1272w, https://substackcdn.com/image/fetch/$s_!JG6Q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78287fc7-f3f0-434a-8dab-fca9ebcac7c6_1080x520.svg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JG6Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78287fc7-f3f0-434a-8dab-fca9ebcac7c6_1080x520.svg" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/78287fc7-f3f0-434a-8dab-fca9ebcac7c6_1080x520.svg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Edge Scan Sensor architecture: Raspberry Pi on customer LAN discovers hosts via ICMP ARP TCP and SNMP, phones home to Dual-Strike XISEM for assets and site scan nominations&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Edge Scan Sensor architecture: Raspberry Pi on customer LAN discovers hosts via ICMP ARP TCP and SNMP, phones home to Dual-Strike XISEM for assets and site scan nominations" title="Edge Scan Sensor architecture: Raspberry Pi on customer LAN discovers hosts via ICMP ARP TCP and SNMP, phones home to Dual-Strike XISEM for assets and site scan nominations" srcset="https://substackcdn.com/image/fetch/$s_!JG6Q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78287fc7-f3f0-434a-8dab-fca9ebcac7c6_1080x520.svg 424w, https://substackcdn.com/image/fetch/$s_!JG6Q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78287fc7-f3f0-434a-8dab-fca9ebcac7c6_1080x520.svg 848w, https://substackcdn.com/image/fetch/$s_!JG6Q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78287fc7-f3f0-434a-8dab-fca9ebcac7c6_1080x520.svg 1272w, https://substackcdn.com/image/fetch/$s_!JG6Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78287fc7-f3f0-434a-8dab-fca9ebcac7c6_1080x520.svg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><figcaption class="image-caption">Edge Scan Sensor architecture: Raspberry Pi on customer LAN discovers hosts via ICMP ARP TCP and SNMP, phones home to Dual-Strike XISEM for assets and site scan nominations</figcaption></figure></div><h2>Lowest total cost of ownership in the edge sensor category</h2><p>We are comfortable saying this plainly: <strong>the Edge Scan Sensor is among the lowest-cost edge discovery options you can deploy today.</strong></p><p>Here is the math most MSPs run:</p><p>Cost lineEdge Scan SensorTypical alternatives Hardware<strong>Bring your own</strong> Raspberry Pi Zero 2 W, Pi 3, Pi 4, or Pi 5 &#8212; often thirty-five to seventy-five dollarsProprietary appliance &#8212; hundreds to thousands Software install<strong>Free</strong> public arm64 installer from dual-strike.comAppliance license or per-site scanner SKU Power drawRoughly three to five watts &#8212; pennies per monthFull desktop or NMS appliance &#8212; tens of watts Platform billing<strong>Per managed asset</strong> on Dual-Strike XISEM &#8212; servers, IoT, and infrastructure count transparentlyPer-user RMM pricing hides infrastructure</p><p>You are not buying a locked appliance. You are enrolling a <strong>first-class infrastructure asset</strong> on the same platform that runs your agents, browser security, and compliance mapping.</p><p><strong>Public installer one-liner:</strong> run the latest arm64 installer from <a href="https://dual-strike.com/downloads">dual-strike.com/downloads</a> &#8212; search for <strong>XISEM EdgeSensor Linux arm64</strong>, or use the curl command shown in <strong>Infrastructure &#8594; Edge Sensors</strong> when you mint a ZeroConfig pack.</p><p>MSP partners also use <strong>Edge Sensor Prep</strong> &#8212; a Windows USB writer that stages ZeroConfig bundles before a Pi ships. Download from MSP downloads in the console or Infrastructure.</p><h2>What the Edge Scan Sensor does</h2><h3>On-LAN discovery</h3><p>The sensor runs native <strong>LanDiscoveryEngine</strong> sweeps from inside the customer network:</p><ul><li><p>ICMP reachability</p></li><li><p>ARP and neighbor tables for MAC quality on Linux</p></li><li><p>Reverse DNS</p></li><li><p>TCP banner checks</p></li><li><p>SNMP for switches, routers, printers, NAS, VoIP, cameras, and IoT</p></li></ul><p>Discovered devices flow through <code>ingest-network-discovery</code> into your asset inventory and topology views &#8212; correlated with agents, identity, and EDR evidence on the platform.</p><h3>Always-on when workstations sleep</h3><p>Workstations go home at five p.m. The Pi does not. Default <strong>forty-five-minute LAN sweep</strong> cadence keeps inventory fresh on nights and weekends &#8212; the <strong>overnight visibility</strong> badge you will see in Infrastructure when minting a ZeroConfig pack.</p><h3>Site scan nominations</h3><p>Nominate the sensor in <strong>Infrastructure &#8594; Site Scan Settings</strong> the same way you nominate a workstation scanner. Policy arrives via <code>get-agent-scan-policy</code>. Heartbeats confirm the sensor is alive.</p><h3>Registered infrastructure asset</h3><p>The sensor is not a shadow process. It provisions as <code>device_class=infrastructure</code> with <code>asset_role=edge_scan_sensor</code> &#8212; visible in inventory, health dashboards, and compliance scope.</p><h3>Agentless SNMP path</h3><p>SNMP polling from the on-net collector is on the active roadmap for full parity with workstation agentless collectors. MSPs deploying today get LAN discovery and periodic sweeps; SNMP depth expands without replacing hardware.</p><h2>Four provisioning modes &#8212; ship how you sell</h2><p>ModeBest forWhat happens <strong>MSP pre-config</strong>Known client before shipZeroConfig bundle with infeed token on USB <strong>Identity enroll</strong>Label with company and emailAuto-provision on first boot <strong>Phone home</strong>Blank ship to stockMSP claims in Unclaimed Agents and assigns tenant <strong>Site label</strong>Multi-site MSP<code>site_label</code> maps to client site on every payload</p><p>Hardware identity &#8212; serial, model &#8212; is read from Linux device tree for matching and audit.</p><h2>MSP deployment workflow</h2><h3>Step one &#8212; Mint ZeroConfig in the console</h3><p>Open <strong>Infrastructure &#8594; Edge Sensors</strong>. Select client and site. Generate a ZeroConfig pack with credentials, installer URL, and ship checklist.</p><h3>Step two &#8212; Stage USB with Edge Sensor Prep</h3><p>Import the bundle JSON into <strong>XISEM Edge Sensor Prep</strong> on Windows. Write <code>xisem-edge-sensor/</code> to USB &#8212; config, environment, and README for the bench tech.</p><h3>Step three &#8212; Flash and ship the Pi</h3><p>Flash <strong>Raspberry Pi OS Lite 64-bit</strong> with Raspberry Pi Imager. Copy the flash kit boot overlay or USB staging folder. First-boot script expands the filesystem, applies MSP overlay, runs the installer, and reboots clean.</p><p>Supported boards: Pi Zero 2 W, Pi 3, Pi 4, Pi 5, and generic arm64 or x64 headless Linux.</p><h3>Step four &#8212; Nominate and verify</h3><p>In <strong>Site Scan Settings</strong>, nominate the sensor for LAN scans. Within one harvest cycle, confirm assets appear in Infrastructure and topology views.</p><p><strong>Console routes:</strong> <code>/infrastructure?tab=edge-sensors</code> &#183; <code>/infrastructure?tab=site-scans</code> &#183; <code>/admin/unclaimed-agents</code></p><h2>Benefits for MSPs, MSSPs, and direct clients</h2><p><strong>Close the remote-office discovery gap.</strong> Branches without a server or always-on PC finally appear on your map &#8212; the same gap legacy Traverse-style scanners addressed, without a proprietary box.</p><p><strong>ISP-router and flat LANs.</strong> Discovery runs on-net. No dependency on cloud-only scanning that cannot see private RFC1918 space.</p><p><strong>One correlated story.</strong> Edge discoveries sit beside XISEM Agent posture, Anti-Venom browsing telemetry, M365 sign-ins, and EDR detections in the Asset modal &#8212; not a siloed NMS export.</p><p><strong>Transparent economics.</strong> Per-asset pricing means a Pi sensor and a printer both count clearly. No hidden per-user tax on infrastructure.</p><p><strong>Scale with your fleet.</strong> Ship ten Pis to ten sites for less than one enterprise appliance line item. Spares are a thirty-dollar board, not a return merchandise authorization.</p><p><strong>Direct client fit.</strong> Commercial IT teams with warehouses, clinics, or franchise locations get site visibility without leaving a desktop online or buying a second platform.</p><h2>Edge Scan Sensor vs USB Prospecting Tool</h2><p>USB Prospecting ToolEdge Scan Sensor <strong>Purpose</strong>Pre-contract assessmentPersistent enrolled asset <strong>Hardware</strong>Technician laptop or USB stickRaspberry Pi on-site <strong>Duration</strong>Point-in-time visitContinuous sweeps <strong>Install</strong>No agent &#8212; read-only scanHeadless service, no tray <strong>Best moment</strong>First sales meetingAfter client signs</p><p>Use both: <strong>USB Prospecting wins the deal. Edge Sensor keeps the branch visible after onboarding.</strong></p><h2>Honest limitations</h2><ul><li><p>SNMP and SSH agentless depth on the sensor is still expanding &#8212; LAN discovery and periodic sweeps are production-ready; full agentless parity is on the roadmap.</p></li><li><p>Flash kit ships as boot overlay plus installer &#8212; not a single pre-baked image file. MSPs use Pi Imager plus Edge Sensor Prep for repeatable ship kits.</p></li><li><p>Cloud-only SaaS workloads appear through identity and browser signals, not L2 maps &#8212; pair edge discovery with Anti-Venom and M365 infeeds.</p></li></ul><h2>Talk track</h2><p>&gt; "We drop a forty-dollar Raspberry Pi on your branch network. It discovers printers, switches, IoT, and rogue hosts overnight &#8212; and feeds the same Dual-Strike console as your desktops. No appliance subscription. No PC left running. When you are ready, we nominate it for site scans and you see the branch on the same map as headquarters."</p><p><strong>Related reading:</strong> Network topology discovery &#183; USB Prospecting Tool &#183; Evidence doctrine</p><p><strong>Next step:</strong> <a href="https://dual-strike.com">dual-strike.com</a> &#183; Infrastructure &#8594; Edge Sensors &#183; MSP partner program</p><div><hr></div><p><em>Edge Scan Sensor aligns with current XISEM GA releases. Illustrations are representative &#8212; anonymized demo topology.</em></p>]]></content:encoded></item><item><title><![CDATA[Standing privilege → zero]]></title><description><![CDATA[Standing local administrator rights are one of the most common ways a phishing click becomes a fleet-wide incident.]]></description><link>https://press.dual-strike.com/p/standing-privilege-zerohtml</link><guid isPermaLink="false">https://press.dual-strike.com/p/standing-privilege-zerohtml</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Mon, 13 Jul 2026 14:00:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JMT4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc30ebbd-f5d6-4016-b989-e8893555ff53_1024x962.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JMT4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc30ebbd-f5d6-4016-b989-e8893555ff53_1024x962.png 424w, https://substackcdn.com/image/fetch/$s_!JMT4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc30ebbd-f5d6-4016-b989-e8893555ff53_1024x962.png 848w, https://substackcdn.com/image/fetch/$s_!JMT4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc30ebbd-f5d6-4016-b989-e8893555ff53_1024x962.png 1272w, https://substackcdn.com/image/fetch/$s_!JMT4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc30ebbd-f5d6-4016-b989-e8893555ff53_1024x962.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JMT4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc30ebbd-f5d6-4016-b989-e8893555ff53_1024x962.png" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bc30ebbd-f5d6-4016-b989-e8893555ff53_1024x962.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:220,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Dual-Strike XISEM&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Dual-Strike XISEM" title="Dual-Strike XISEM" srcset="https://substackcdn.com/image/fetch/$s_!JMT4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc30ebbd-f5d6-4016-b989-e8893555ff53_1024x962.png 424w, https://substackcdn.com/image/fetch/$s_!JMT4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc30ebbd-f5d6-4016-b989-e8893555ff53_1024x962.png 848w, https://substackcdn.com/image/fetch/$s_!JMT4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc30ebbd-f5d6-4016-b989-e8893555ff53_1024x962.png 1272w, https://substackcdn.com/image/fetch/$s_!JMT4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc30ebbd-f5d6-4016-b989-e8893555ff53_1024x962.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>Standing local administrator rights are one of the most common ways a phishing click becomes a fleet-wide incident.</p><p>Helpdesks grant them because installers break without them. IT keeps them because maintenance windows are unpredictable. Auditors flag them every assessment cycle &#8212; and they come back anyway because "temporary" became culture.</p><p>Classic elevation tools optimize for allowing approved apps. They often stop there: a vendor silo, a tray icon, a log export nobody correlates with identity risk, browsing sessions, or compliance posture.</p><p><strong>Anti-Venom Secure Elevate</strong> takes a different goal: <strong>eliminate standing admin</strong> &#8212; and make every elevation a first-class security event on the same XISEM graph as alerts, investigations, ASPIRE, and compliance.</p><blockquote><p>Privilege on demand. Zero standing admin. Every grant evidence-backed.</p></blockquote><p><strong>Explore:</strong> <a href="https://dual-strike.com/antivenom/elevate">dual-strike.com/antivenom/elevate</a> &#183; <a href="https://dual-strike.com/antivenom">dual-strike.com/antivenom</a> &#183; <a href="https://dual-strike.com/">dual-strike.com</a></p><div><hr></div><h2>The standing-admin problem in plain language</h2><p>Local administrator membership is a blunt instrument. It solves today's installer pain and creates tomorrow's lateral movement path.</p><p>The failure mode is familiar across MSP portfolios and enterprise fleets:</p><p>&#8226; Teachers, engineers, or finance staff retain admin "because the projector driver broke last semester."</p><p>&#8226; IT accounts carry standing privilege long after the project that required it ended.</p><p>&#8226; Elevation happens outside any system the SOC monitors &#8212; then expires without proof the fleet returned to least privilege.</p><p>&#8226; Assessors ask who elevated, when, and why &#8212; and the answer is a ticket comment, not a correlated evidence chain.</p><p>Secure Elevate does not replace Active Directory, Intune, or your RMM. XISEM <strong>extends and operationalizes</strong> endpoint privilege &#8212; the same STAP posture we take across the stack: enrich what you already run, correlate it, make it actionable.</p><div><hr></div><h2>How Secure Elevate works</h2><p>Secure Elevate is just-in-time local privilege with full audit into Dual-Strike XISEM &#8212; delivered through <strong>Scout</strong>, the Dual-Strike XISEM endpoint agent.</p><p>&#8226; <strong>Eliminate standing local admin</strong> &#8212; Deploy Elevate, remove standing membership, and let JIT carry installers and admin tasks.</p><p>&#8226; <strong>Tray request or policy auto-match</strong> &#8212; Users request elevation from the Scout tray &#8212; or policy matches process, publisher, hash, or path automatically.</p><p>&#8226; <strong>MIP / Lookout / PSA approval</strong> &#8212; Approve in the privileged console, the Lookout technician companion, or an urgent PSA ticket with Slack / Teams fan-out.</p><p>&#8226; <strong>Timed grant, automatic revoke</strong> &#8212; Scout adds timed Administrators membership (or platform equivalent), then tears it down when the window expires.</p><p>&#8226; <strong>Privilege as a security event</strong> &#8212; Request &#8594; approve &#8594; grant &#8594; expire &#8594; revoke lands as XISEM alerts and audit evidence &#8212; not a vendor silo.</p><p>&#8226; <strong>Re-harvest proof</strong> &#8212; Local admin inventory harvest proves the fleet returned to least privilege after every elevation window.</p><p>&#8226; <strong>Realtime operator awareness</strong> &#8212; Bell, Slack / Teams, and Lookout paths so approvals do not die in an inbox nobody watches.</p><p>&#8226; <strong>Scored with ASPIRE &amp; CAA</strong> &#8212; Elevation context sits next to client posture and Continuous Access Attestation &#8212; not isolated ringfencing.</p><p>Users are not standing admins. When they need privilege, Scout grants a timed membership, then revokes. Measurable goal: <strong>0% standing admin</strong> with re-harvest proof, not a policy PDF.</p><div><hr></div><h2>Least privilege without killing productivity</h2><p>Security teams and helpdesks share the same constraint: block standing admin without blocking the business.</p><p>Secure Elevate supports three approval paths so elevation fits how you already operate:</p><p>&#8226; <strong>Privileged Identity console (MIP)</strong> &#8212; Security and identity teams review and approve with full context.</p><p>&#8226; <strong>Lookout</strong> &#8212; Technicians get mobile-aware notifications for urgent elevation requests.</p><p>&#8226; <strong>PSA integration</strong> &#8212; Urgent tickets with Slack / Teams fan-out when inbox-only approval is too slow.</p><p>Policy auto-match reduces friction for known-good scenarios &#8212; signed installers, approved publishers, hash- or path-bound maintenance tasks &#8212; while keeping human gates for high-risk or novel requests.</p><p>Timed grants mean privilege is <strong>borrowed</strong>, not <strong>owned</strong>. Automatic revoke means the default state returns to least privilege without a cleanup script someone forgets to run.</p><div><hr></div><h2>Elevation that logs into the SOC's plane</h2><p>Elevation products that do not land in your security operations timeline are just another island.</p><p>Secure Elevate optimizes for a different outcome: every elevation visible alongside phishing sessions, DNS blocks, browsing policy hits, identity posture, and compliance mappings &#8212; because it is native to Dual-Strike XISEM, not bolted on afterward.</p><p>That matters when:</p><p>&#8226; An analyst investigates lateral movement and needs to know whether standing admin existed on the asset <strong>during</strong> the incident window.</p><p>&#8226; A vCISO reports least-privilege posture to a board and needs <strong>proof</strong>, not aspiration.</p><p>&#8226; An assessor asks for privileged-access evidence and expects timestamps, approvers, and revocation &#8212; not screenshots.</p><p>Coexist with inventory-class elevation tools if you keep them today. Or replace the island with Scout-native JIT when you are ready. XISEM does not demand rip-and-replace on day one.</p><div><hr></div><h2>The Anti-Venom family &#8212; Elevate is one surface</h2><p>Anti-Venom protects where users and endpoints actually interact with risk. Secure Elevate handles <strong>local privilege</strong>. Sibling products cover adjacent attack paths:</p><p>&#8226; <strong>Anti-Venom Secure Access</strong> &#8212; Browser enforcement: session telemetry, SaaS attribution, Shadow AI visibility, policy in Chrome, Edge, Firefox, and Safari. <a href="https://dual-strike.com/antivenom/access">dual-strike.com/antivenom/access</a></p><p>&#8226; <strong>Anti-Venom Secure Resolve</strong> &#8212; Endpoint DNS protection at the system resolver &#8212; apps and malware that never open a tab still hit policy. Pairs with Secure Access for browser DoH coverage. <a href="https://dual-strike.com/antivenom/resolve">dual-strike.com/antivenom/resolve</a></p><p>&#8226; <strong>Anti-Venom Secure Control</strong> &#8212; Vendor-agnostic desired-state policy and configuration assurance &#8212; detect drift, govern exceptions, map evidence into ASPIRE and compliance. <a href="https://dual-strike.com/antivenom/control">dual-strike.com/antivenom/control</a></p><p>&#8226; <strong>Anti-Venom Secure Elevate</strong> &#8212; Just-in-time local admin with full XISEM audit. <a href="https://dual-strike.com/antivenom/elevate">dual-strike.com/antivenom/elevate</a></p><p>Elevate removes standing privilege on the endpoint. Secure Access governs the browse path. Secure Resolve governs resolver traffic. Secure Control proves configuration stayed where you set it. Together they close the gap between <strong>policy intent</strong> and <strong>observable posture</strong>.</p><p>For cloud OAuth and cross-tenant trust &#8212; a different lens &#8212; see <strong>XISEM Visa</strong>: <a href="https://dual-strike.com/visa">dual-strike.com/visa</a></p><div><hr></div><h2>What we do not claim</h2><p>Public buyers deserve precision:</p><p>&#8226; Secure Elevate does <strong>not</strong> replace Microsoft Entra Privileged Identity Management or cloud admin JIT &#8212; it targets <strong>local</strong> standing privilege on managed endpoints via Scout.</p><p>&#8226; Secure Elevate does <strong>not</strong> remove the need for helpdesk process &#8212; it adds evidence, timed grants, and approval paths helpdesks can defend.</p><p>&#8226; Secure Elevate does <strong>not</strong> guarantee zero incidents &#8212; it eliminates a recurring finding and a recurring lateral-movement enabler with measurable re-harvest proof.</p><p>&#8226; Secure Elevate does <strong>not</strong> require you to uninstall other elevation vendors on day one &#8212; coexistence is supported; consolidation is a program decision.</p><div><hr></div><h2>Who this is for</h2><p>&#8226; MSPs standardizing least privilege across client fleets without breaking installer workflows</p><p>&#8226; K-12 and higher-ed IT teams eliminating standing teacher and lab admin</p><p>&#8226; Government and defense-industrial programs where assessors expect JIT privilege with evidence chains</p><p>&#8226; vCISO and compliance leads tying local admin posture to ASPIRE, CAA, and framework mappings</p><div><hr></div><h2>Next step</h2><p>If standing local admin is still your default &#8212; and your SOC cannot prove otherwise &#8212; start here:</p><p><strong><a href="https://dual-strike.com/antivenom/elevate">dual-strike.com/antivenom/elevate</a></strong> &#183; <strong><a href="https://dual-strike.com/antivenom">dual-strike.com/antivenom</a></strong> &#183; Deploy Scout &#183; Request a demo</p><p>Privilege on demand. Zero standing admin.</p><p>&#8212; The Dual-Strike team</p>]]></content:encoded></item><item><title><![CDATA[Your SaaS, defended at the tenant]]></title><description><![CDATA[Microsoft 365 and Google Workspace are where your business actually runs &#8212; and where attackers actually land.]]></description><link>https://press.dual-strike.com/p/your-saas-defended-at-the-tenanthtml</link><guid isPermaLink="false">https://press.dual-strike.com/p/your-saas-defended-at-the-tenanthtml</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Sun, 12 Jul 2026 14:00:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Y-T1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9b20f10-c454-4bee-9cfc-ecc9a763ec43_1024x962.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Y-T1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9b20f10-c454-4bee-9cfc-ecc9a763ec43_1024x962.png 424w, https://substackcdn.com/image/fetch/$s_!Y-T1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9b20f10-c454-4bee-9cfc-ecc9a763ec43_1024x962.png 848w, https://substackcdn.com/image/fetch/$s_!Y-T1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9b20f10-c454-4bee-9cfc-ecc9a763ec43_1024x962.png 1272w, https://substackcdn.com/image/fetch/$s_!Y-T1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9b20f10-c454-4bee-9cfc-ecc9a763ec43_1024x962.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Y-T1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9b20f10-c454-4bee-9cfc-ecc9a763ec43_1024x962.png" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d9b20f10-c454-4bee-9cfc-ecc9a763ec43_1024x962.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:220,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Dual-Strike XISEM&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Dual-Strike XISEM" title="Dual-Strike XISEM" srcset="https://substackcdn.com/image/fetch/$s_!Y-T1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9b20f10-c454-4bee-9cfc-ecc9a763ec43_1024x962.png 424w, https://substackcdn.com/image/fetch/$s_!Y-T1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9b20f10-c454-4bee-9cfc-ecc9a763ec43_1024x962.png 848w, https://substackcdn.com/image/fetch/$s_!Y-T1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9b20f10-c454-4bee-9cfc-ecc9a763ec43_1024x962.png 1272w, https://substackcdn.com/image/fetch/$s_!Y-T1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd9b20f10-c454-4bee-9cfc-ecc9a763ec43_1024x962.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>Microsoft 365 and Google Workspace are where your business actually runs &#8212; and where attackers actually land.</p><p>Not in a SIEM log from last Tuesday. In the tenant itself: a forwarding rule on an executive mailbox, a Drive folder shared with anyone-with-link, a global admin without phishing-resistant MFA, a super admin role that has been active for ninety days without a review.</p><p>Point tools and native admin consoles hold pieces of that truth. What most teams lack is a <strong>single posture program</strong> &#8212; deduplicated findings, drift since baseline, readable evidence, and a path from discovery to remediation without another dashboard island.</p><p>Dual-Strike <strong>XISEM SSPM</strong> (SaaS Security Posture Management) watches the tenant end to end: identity hygiene, mail flow, sharing exposure, admin sprawl, and policy drift. Read-only by default. Bound to ASPIRE, COBRA&#178;, and 100+ compliance frameworks the moment findings land.</p><blockquote><p>Your SaaS, defended at the tenant &#8212; not a spreadsheet you refresh before the audit.</p></blockquote><p><strong>Explore:</strong> <a href="https://dual-strike.com/sspm">dual-strike.com/sspm</a> &#183; <a href="https://dual-strike.com/">dual-strike.com</a></p><div><hr></div><h2>The tenant problem in plain language</h2><p>SaaS security failures rarely announce themselves as "SaaS incidents." They show up as:</p><p>&#8226; External mail forwarding that exfiltrates before anyone notices the transport rule.</p><p>&#8226; Anyone-with-link sharing on folders that contain finance, HR, or engineering artifacts.</p><p>&#8226; Standing global admin or super admin accounts &#8212; some without strong MFA, some without anyone remembering why they exist.</p><p>&#8226; Legacy authentication still enabled while conditional access looks healthy on paper.</p><p>&#8226; Posture that was "fine at baseline" until a setting drifted and nobody got a readable alert.</p><p>Native admin UIs are authoritative. They are also fragmented, role-gated, and poor at telling a <strong>continuous improvement story</strong> for boards, insurers, and assessors.</p><p>SSPM in XISEM does not replace Microsoft Entra, Google Admin, or your GRC platform. XISEM <strong>extends and operationalizes</strong> tenant evidence &#8212; the same alliance posture we describe in STAP: enrich, correlate, score, act.</p><div><hr></div><h2>What SSPM watches</h2><p>SSPM scans baseline posture across identity, mail, files, devices, sharing, admin sprawl, and audit settings &#8212; then alerts only when something actually changes.</p><p>&#8226; <strong>Identity &amp; MFA hygiene</strong> &#8212; Phishing-resistant MFA gaps, legacy auth, conditional access drift, and stale privileged accounts.</p><p>&#8226; <strong>Mail flow &amp; forwarding</strong> &#8212; External forwarding rules, autoforward, transport rules, and exfil-shaped mailbox behavior.</p><p>&#8226; <strong>Sharing &amp; DLP exposure</strong> &#8212; Anyone-with-link, external collaborators, sensitive labels, and policy bypasses across Drive and SharePoint.</p><p>&#8226; <strong>Admin sprawl</strong> &#8212; Global admins, super admins, delegated roles, and standing privilege that should be just-in-time.</p><p>&#8226; <strong>Policy drift</strong> &#8212; Baseline plus deviation. XISEM snapshots your posture and escalates when configuration moves &#8212; not when a static report ages out.</p><p>&#8226; <strong>Audit-ready evidence</strong> &#8212; Every finding is timestamped, scoped to the right client organization, and bound to your compliance mappings.</p><p>Findings are deduplicated, scored, and pre-mapped to frameworks your program already contracts &#8212; CIS, NIST, CMMC, ISO, and dozens more &#8212; so "prove posture" is not a weekend of screenshots.</p><div><hr></div><h2>Connect &#8594; Scan &#8594; Score &#8594; Remediate</h2><p>SSPM is designed for operators who cannot afford a six-month integration project:</p><p>1. <strong>Connect</strong> &#8212; OAuth into Microsoft 365 and Google Workspace. Read-only by default. No agents, no proxies, revocable from your tenant any time.</p><p>2. <strong>Scan</strong> &#8212; Baseline posture across identity, mail, files, sharing, admin sprawl, and audit settings &#8212; typically within minutes of connect.</p><p>3. <strong>Score</strong> &#8212; Findings roll up into your ASPIRE score and feed COBRA&#178; detections plus compliance bindings.</p><p>4. <strong>Remediate</strong> &#8212; Approve fixes manually, ship one-click containment, or hand off to a managed XISEM tier &#8212; your call.</p><p>No rip-and-replace. No migration. Twelve minutes from OAuth to a posture truth your team can act on Monday morning.</p><div><hr></div><h2>SSPM and Visa: two lenses, one platform</h2><p>Cloud SaaS risk splits naturally into two questions:</p><p>&#8226; <strong>What is configured in the tenant?</strong> &#8212; SSPM owns the broader SaaS control plane: identity hygiene, mail, sharing, admin sprawl, drift.</p><p>&#8226; <strong>What apps and trust relationships hold OAuth privilege?</strong> &#8212; <strong>XISEM Visa</strong> owns the app estate and cross-tenant trust: App Registrations, Enterprise Apps, scopes, consent users, XT partners, cross-domain delegation.</p><p>SSPM might flag a global admin without phishing-resistant MFA. Visa might show that same admin consented a high-privilege third-party app last week. <strong>Anti-Venom Secure Access</strong> might reveal users opening a shadow SaaS domain daily. <strong>SaaS / Cloud MFA Coverage</strong> might show those logins were never stepped up.</p><p>Used &#8800; authorized &#8800; MFA-safe &#8800; tenant-hardened. XISEM keeps the lenses separate and the verdict unified.</p><p><strong>Related:</strong> <a href="https://dual-strike.com/visa">dual-strike.com/visa</a> &#183; <a href="https://dual-strike.com/antivenom">dual-strike.com/antivenom</a> &#183; <a href="https://dual-strike.com/shadow-ai">dual-strike.com/shadow-ai</a></p><div><hr></div><h2>A surface, not a silo</h2><p>Most standalone SSPM tools stop at a dashboard of findings. In Dual-Strike XISEM, SaaS posture is one more <strong>evidence stream</strong>:</p><p>&#8226; <strong>ASPIRE</strong> &#8212; Posture score moves like a vital sign; every change traceable to a control, a finding, and a fix.</p><p>&#8226; <strong>COBRA&#178;</strong> &#8212; Detections and correlation across identity, endpoint, browser, and tenant signals.</p><p>&#8226; <strong>Compliance</strong> &#8212; Findings bind to control mappings, POA&amp;M, and assessor-ready binders.</p><p>&#8226; <strong>SOAR &amp; containment</strong> &#8212; One-click escalation where your runbooks support it.</p><p>One platform. One canonical Gateway per client organization. One verdict operators can defend.</p><div><hr></div><h2>What we do not claim</h2><p>Honesty matters in SaaS security sales:</p><p>&#8226; SSPM does <strong>not</strong> replace Microsoft Entra, Google Workspace Admin, or your CASB. XISEM operationalizes tenant evidence those systems produce.</p><p>&#8226; SSPM does <strong>not</strong> substitute for DLP legal review or data-classification policy &#8212; it surfaces misconfigurations and exposure paths with readable proof.</p><p>&#8226; SSPM does <strong>not</strong> guarantee compliance attestation by itself. It feeds the evidence layer your GRC and assessor workflows consume.</p><p>&#8226; SSPM does <strong>not</strong> require agent deployment for baseline tenant scan &#8212; Gateways connect read-only. Endpoint and browser siblings add depth where you enable them.</p><div><hr></div><h2>Who this is for</h2><p>&#8226; MSP and MSSP operators standardizing M365 and Google posture across a portfolio</p><p>&#8226; vCISO teams who need drift visibility between audit windows &#8212; not annual screenshot archaeology</p><p>&#8226; Compliance managers mapping live tenant findings to CIS, NIST, CMMC, and insurer questionnaires</p><p>&#8226; Organizations pairing SSPM with Visa and Anti-Venom for authority, attribution, and endpoint/browser depth</p><div><hr></div><h2>Next step</h2><p>If your SaaS tenants pass an assessment week but cannot prove readiness on an ordinary Tuesday, start here:</p><p><strong><a href="https://dual-strike.com/sspm">dual-strike.com/sspm</a></strong> &#183; Connect Microsoft 365 &#183; Connect Google Workspace &#183; Request a demo</p><p>Connect your tenants. See the truth in twelve minutes.</p><p>&#8212; The Dual-Strike team</p>]]></content:encoded></item><item><title><![CDATA[Every cloud app needs a visa]]></title><description><![CDATA[Your identity provider already knows which cloud apps hold privilege in the tenant.]]></description><link>https://press.dual-strike.com/p/every-cloud-app-needs-a-visahtml</link><guid isPermaLink="false">https://press.dual-strike.com/p/every-cloud-app-needs-a-visahtml</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Sat, 11 Jul 2026 14:00:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uqmf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c64ce12-b63a-488d-877f-4eb61b4a02ab_1024x962.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uqmf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c64ce12-b63a-488d-877f-4eb61b4a02ab_1024x962.png 424w, https://substackcdn.com/image/fetch/$s_!uqmf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c64ce12-b63a-488d-877f-4eb61b4a02ab_1024x962.png 848w, https://substackcdn.com/image/fetch/$s_!uqmf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c64ce12-b63a-488d-877f-4eb61b4a02ab_1024x962.png 1272w, https://substackcdn.com/image/fetch/$s_!uqmf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c64ce12-b63a-488d-877f-4eb61b4a02ab_1024x962.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uqmf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c64ce12-b63a-488d-877f-4eb61b4a02ab_1024x962.png" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9c64ce12-b63a-488d-877f-4eb61b4a02ab_1024x962.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:220,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Dual-Strike XISEM&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Dual-Strike XISEM" title="Dual-Strike XISEM" srcset="https://substackcdn.com/image/fetch/$s_!uqmf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c64ce12-b63a-488d-877f-4eb61b4a02ab_1024x962.png 424w, https://substackcdn.com/image/fetch/$s_!uqmf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c64ce12-b63a-488d-877f-4eb61b4a02ab_1024x962.png 848w, https://substackcdn.com/image/fetch/$s_!uqmf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c64ce12-b63a-488d-877f-4eb61b4a02ab_1024x962.png 1272w, https://substackcdn.com/image/fetch/$s_!uqmf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c64ce12-b63a-488d-877f-4eb61b4a02ab_1024x962.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>Your identity provider already knows which cloud apps hold privilege in the tenant. The problem is not that the data is missing &#8212; it is that nobody operationalizes it.</p><p>An permitted user opts the entire organization into a third-party SaaS app. A custom App Registration lands with mail, files, or role-management scopes. A cross-tenant partner relationship opens with inbound trust and auto-consent posture buried in admin portals. Consent is not authorization &#8212; but without a control loop, it becomes standing access anyway.</p><p>Dual-Strike <strong>XISEM Visa</strong> is the cloud app, OAuth, and cross-tenant trust surface in XISEM. Visa inventories what the identity provider authorizes, escalates when posture changes, supports analyst and certification review, and finishes with SOAR playbooks that revoke grants, disable apps, or remove them from the tenant.</p><blockquote><p>Every cloud app needs a visa to operate in your tenant. Issue them deliberately. Revoke the rest.</p></blockquote><p><strong>Explore:</strong> <a href="https://dual-strike.com/visa">dual-strike.com/visa</a> &#183; <a href="https://dual-strike.com/">dual-strike.com</a></p><div><hr></div><h2>The gap in plain language</h2><p>Most organizations discover cloud app risk in one of three painful ways:</p><p>&#8226; A user with consent rights grants org-wide access to a SaaS tool nobody in security has reviewed.</p><p>&#8226; An attacker or insider registers a custom application that holds secrets, certificates, or high-privilege Graph permissions.</p><p>&#8226; A guest-join or B2B cross-tenant path opens a trust relationship that analysts only find after an incident.</p><p>Microsoft Entra and Google Workspace Admin Console hold the truth. What they do not provide, by themselves, is a <strong>continuous control loop</strong> &#8212; readable inventory, deduplicated alerts, certification review, and evidence-backed response in the same platform where your analysts already work.</p><p>Visa closes that loop. It does not replace Entra or Google Admin. XISEM <strong>extends and operationalizes</strong> the evidence those systems produce &#8212; the same STAP posture we take with EDR, DNS, and identity: enrich, correlate, act.</p><div><hr></div><h2>Available now: what Visa inventories</h2><p>Visa mirrors identity-provider truth &#8212; not browser discovery. Operators filter by provider, app kind, and permission mode. Trust &amp; Guests isolates cross-org relationships that are easy to miss in native admin UIs.</p><p>&#8226; <strong>App Registrations</strong> &#8212; Custom Entra app registrations that can hold secrets, certificates, and Graph permissions &#8212; inventoried with publisher, permission mode, and first / last seen.</p><p>&#8226; <strong>Enterprise Apps</strong> &#8212; Service principals and enterprise applications in the directory &#8212; including app-only (application) permissions that never touch a human identity.</p><p>&#8226; <strong>Scopes &amp; permission modes</strong> &#8212; Delegated scopes and application roles side by side. Filter by application vs delegated; high-risk scopes (mail, files, role management) are called out for triage.</p><p>&#8226; <strong>Consent users</strong> &#8212; User consent footprint and admin-consent flags &#8212; who granted what, whether the org is opted in, and how wide the blast radius is.</p><p>&#8226; <strong>Cross-tenant partners (XT Partners)</strong> &#8212; Entra cross-tenant partner orgs &#8212; default domain, inbound and outbound trust, auto-consent posture &#8212; so guest-join and B2B relationships are visible, not buried in portal JSON.</p><p>&#8226; <strong>Trust &amp; Guests / cross-domain</strong> &#8212; Dedicated view for cross-org trust and Google domain-wide delegation. Correlate with guest invite / redeem and cross-tenant sign-in events.</p><p>Evidence arrives through <strong>Microsoft Entra</strong> and <strong>Google Workspace Gateways</strong> &#8212; read-only connectors that harvest OAuth app catalogs, consent posture, and trust relationships into durable Visa rows.</p><div><hr></div><h2>Consent is not authorization</h2><p>Visa exists because the most common cloud-app failures are authorization failures dressed up as convenience:</p><p>&#8226; <strong>App Regs &amp; Enterprise Apps</strong> &#8212; Custom registrations and enterprise apps that gain directory, mail, or Azure function without a security review.</p><p>&#8226; <strong>Org-wide SaaS consent</strong> &#8212; A permitted user opts the entire organization into a third-party SaaS app &#8212; Visa sees the grant, scores the scopes, and escalates.</p><p>&#8226; <strong>High-privilege scopes</strong> &#8212; Mail.ReadWrite, Files.ReadWrite.All, RoleManagement &#8212; alerted with labeled evidence for analysts, not a raw API dump.</p><p>&#8226; <strong>XT partners &amp; guest-join</strong> &#8212; Cross-tenant partners with inbound / outbound trust and auto-consent &#8212; the path a rogue invite &#8594; accept &#8594; guest join can exploit.</p><p>&#8226; <strong>Consent requested &amp; attempted</strong> &#8212; Admin consent requests and attempted grants surface before they become standing access.</p><p>&#8226; <strong>SOAR revoke &amp; disable</strong> &#8212; Kill the OAuth grant, disable the service principal, or remove the app &#8212; with approval gates for destructive actions.</p><p>Readable evidence is the default story. Raw JSON remains available as an audit appendix &#8212; not the primary analyst view.</p><div><hr></div><h2>Inventory &#8594; Detect &#8594; Review &#8594; Act</h2><p>Visa runs one control loop for the entire cloud app estate:</p><p>1. <strong>Inventory</strong> &#8212; App Registrations, Enterprise Apps, OAuth clients, scopes, consent users, XT partners, and cross-domain trust &#8212; durable rows in Visa from Entra and Google Workspace Gateways.</p><p>2. <strong>Detect</strong> &#8212; Posture-deduped alerts when a new app appears, high-privilege scopes land, or consent is requested or attempted &#8212; escalated through Alerts, Lookout, and COBRA&#178;.</p><p>3. <strong>Review</strong> &#8212; Analyst and certification review of publisher trust, application vs delegated permissions, partner inbound/outbound trust, and risk tier.</p><p>4. <strong>Act</strong> &#8212; SOAR playbooks revoke OAuth grants, disable the app, or remove it from the tenant &#8212; human-gated when destructive, evidence-backed when complete.</p><p>That loop is the difference between knowing apps exist in a portal and <strong>governing</strong> them as a security program.</p><div><hr></div><h2>Authority, attribution, and MFA coverage</h2><p>Visa answers <strong>what is authorized in the identity provider</strong>. Sibling XISEM surfaces answer adjacent questions &#8212; without merging product names or confusing discovery with permission.</p><p>&#8226; <strong>SaaS App Attribution</strong> (Anti-Venom Secure Access) &#8212; What is used &#8212; browser-observed SaaS domains users actually open, including shadow and sanctioned apps from session telemetry, not only what the IdP lists.</p><p>&#8226; <strong>Visa</strong> &#8212; What is authorized &#8212; whether that app (or a parallel Graph or Workspace grant) holds consented privilege, and whether an XT partner or cross-domain trust path exists.</p><p>&#8226; <strong>SaaS / Cloud MFA Coverage</strong> &#8212; Was it stepped up &#8212; browser-attested login events show whether SaaS and cloud sign-ins challenged MFA, with gap analysis by app and by user.</p><p>&#8226; <strong>SSPM</strong> &#8212; Tenant posture &#8212; identity hygiene, mail flow, sharing, and admin sprawl across the broader SaaS control plane. Visa owns the app estate and cross-tenant trust; SSPM owns tenant-wide configuration drift.</p><p>&#8226; <strong>Shadow AI</strong> &#8212; AI sprawl &#8212; unsanctioned AI tools in browser, local CLI, and Copilot surfaces. When an AI product also holds Graph or Workspace grants, Visa is the revoke path.</p><p>One verdict, three lenses: <strong>Used &#8800; authorized &#8800; MFA-safe.</strong> When any lens fails, SOAR and certification campaigns close the loop.</p><div><hr></div><h2>Part of the XISEM family &#8212; not Anti-Venom</h2><p>Product names should tell operators where to look:</p><p>&#8226; <strong>Scout</strong> watches endpoints.</p><p>&#8226; <strong>Sonar</strong> watches networks.</p><p>&#8226; <strong>Visa</strong> watches cloud apps and cross-tenant trust.</p><p>&#8226; <strong>Anti-Venom</strong> protects the browse path &#8212; Secure Access, Secure Resolve, Secure Elevate, Secure Control.</p><p>Lookout notifies technicians. COBRA&#178; correlates. ASPIRE scores Access when OAuth and MFA posture move. One platform &#8212; clear product names.</p><div><hr></div><h2>What we do not claim</h2><p>Public buyers deserve precision:</p><p>&#8226; Visa does <strong>not</strong> replace Microsoft Entra, Google Workspace Admin, or your identity provider's native app governance. XISEM extends and operationalizes that evidence.</p><p>&#8226; Visa does <strong>not</strong> enforce Conditional Access by itself. Inventory presence is not a policy engine.</p><p>&#8226; Visa does <strong>not</strong> substitute browser discovery for IdP authority &#8212; and vice versa. Both lenses matter.</p><p>&#8226; Visa does <strong>not</strong> ask you to rip out your CASB or SSPM vendor. Keep them. XISEM correlates what they cannot see alone when Gateways and sibling surfaces are connected.</p><div><hr></div><h2>Who this is for</h2><p>&#8226; MSP and MSSP security leads managing multi-tenant M365 and Google Workspace portfolios</p><p>&#8226; vCISO and identity teams tired of Graph JSON archaeology for OAuth reviews</p><p>&#8226; Compliance and audit stakeholders who need readable evidence chains for app consent and cross-tenant trust</p><p>&#8226; Organizations closing Shadow AI and SaaS sprawl &#8212; where browser attribution finds usage and Visa confirms grants</p><div><hr></div><h2>Next step</h2><p>If your cloud app estate lives in admin portals nobody reviews until something breaks, start here:</p><p><strong><a href="https://dual-strike.com/visa">dual-strike.com/visa</a></strong> &#183; <strong><a href="https://dual-strike.com/">dual-strike.com</a></strong> &#183; Connect your Entra or Google Workspace Gateway &#183; Request a demo</p><p>Issue visas deliberately. Revoke the rest.</p><p>&#8212; The Dual-Strike team</p>]]></content:encoded></item><item><title><![CDATA[Compliance that works every day]]></title><description><![CDATA[Government and defense-industrial cybersecurity has a calendar problem.]]></description><link>https://press.dual-strike.com/p/compliance-that-works-every-dayhtml</link><guid isPermaLink="false">https://press.dual-strike.com/p/compliance-that-works-every-dayhtml</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Fri, 10 Jul 2026 14:00:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Xc3j!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86cf2c8f-aba1-4049-a4c3-2ca9a1937f73_1024x962.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Xc3j!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86cf2c8f-aba1-4049-a4c3-2ca9a1937f73_1024x962.png 424w, https://substackcdn.com/image/fetch/$s_!Xc3j!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86cf2c8f-aba1-4049-a4c3-2ca9a1937f73_1024x962.png 848w, https://substackcdn.com/image/fetch/$s_!Xc3j!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86cf2c8f-aba1-4049-a4c3-2ca9a1937f73_1024x962.png 1272w, https://substackcdn.com/image/fetch/$s_!Xc3j!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86cf2c8f-aba1-4049-a4c3-2ca9a1937f73_1024x962.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Xc3j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86cf2c8f-aba1-4049-a4c3-2ca9a1937f73_1024x962.png" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/86cf2c8f-aba1-4049-a4c3-2ca9a1937f73_1024x962.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:220,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Dual-Strike XISEM&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Dual-Strike XISEM" title="Dual-Strike XISEM" srcset="https://substackcdn.com/image/fetch/$s_!Xc3j!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86cf2c8f-aba1-4049-a4c3-2ca9a1937f73_1024x962.png 424w, https://substackcdn.com/image/fetch/$s_!Xc3j!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86cf2c8f-aba1-4049-a4c3-2ca9a1937f73_1024x962.png 848w, https://substackcdn.com/image/fetch/$s_!Xc3j!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86cf2c8f-aba1-4049-a4c3-2ca9a1937f73_1024x962.png 1272w, https://substackcdn.com/image/fetch/$s_!Xc3j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86cf2c8f-aba1-4049-a4c3-2ca9a1937f73_1024x962.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>Government and defense-industrial cybersecurity has a calendar problem.</p><p>Most programs can assemble a binder for an assessment window. Fewer can answer &#8212; <strong>today</strong> &#8212; whether they are audit-ready against the frameworks they contracted, which controls fail with proof, and which remediations will move posture this sprint.</p><p>Authorizing officials want trajectory. Assessors want evidence. Operators want actions. Spreadsheet POA&amp;Ms and annual screenshot archaeology satisfy none of them for long.</p><p>Dual-Strike <strong>XISEM for Government (XISEM GOV)</strong> is the cyber operations platform for that reality: discover, secure, measure, and <strong>continuously prove</strong> compliance posture across mission systems, identities, endpoints, and enclaved workloads.</p><blockquote><p>One platform to discover, secure, measure, and continuously prove compliance posture across every mission system, identity, endpoint, and enclaved workload.</p></blockquote><p><strong>Explore:</strong> <a href="https://dual-strike.com/solutions/government">dual-strike.com/solutions/government</a></p><div><hr></div><h2>The government problem in plain language</h2><p>Agencies, state programs, and Defense Industrial Base contractors drown in point tools. Each tool owns a slice of truth. None owns the program narrative.</p><p>The failure mode is predictable:</p><p>&#8226; NIST and CMMC readiness lives in a GRC spreadsheet that lags live systems by months.</p><p>&#8226; FedRAMP-family and StateRAMP programs scramble between 3PAO milestones instead of operating posture every day.</p><p>&#8226; Privileged access is still standing admin because &#8220;the maintenance window required it.&#8221;</p><p>&#8226; Browsing and SaaS risk &#8212; including Shadow AI and exfiltration-oriented behavior &#8212; sits outside the compliance story for Controlled Unclassified Information and export-sensitive work.</p><p>&#8226; When an assessor asks for proof, the answer is a folder of screenshots with no provenance chain.</p><p>XISEM GOV is not another SIEM that only stores logs, and it is not a GRC tool that only tracks policies. It turns <strong>live telemetry into defensible control evidence</strong>, plans of action and milestones (POA&amp;M), and assessor-ready binders &#8212; every day.</p><p>GRC tracks intent. XISEM feeds <strong>evidence</strong>. They complement.</p><div><hr></div><h2>Built for framework-first missions</h2><p>Government buyers are measured against frameworks &#8212; not feature lists. XISEM GOV maps evidence already in the platform to the programs those missions live under:</p><p>&#8226; Program pressure: ------------------ &#183; Meet: ------ &#183; Exceed: --------</p><p>&#8226; Program pressure: <strong>NIST CSF / SP 800-53 / SP 800-171</strong> &#183; Meet: Live control mapping and daily evidence against the frameworks your program contracts &#183; Exceed: ASPIRE&#8482; / MAVICE&#8480; trajectory an authorizing official or CISO can defend &#8212; not annual screenshot archaeology</p><p>&#8226; Program pressure: <strong>CMMC Levels 1&#8211;3</strong> &#183; Meet: Level-scoped packs, POA&amp;M, and readable evidence chains for CUI environments &#183; Exceed: Ranked remediation that moves assessor outcomes this sprint &#8212; not spreadsheet theater</p><p>&#8226; Program pressure: <strong>FedRAMP / GovRAMP / StateRAMP / TX-RAMP</strong> &#183; Meet: Framework operations, binders, and accreditation-status tracking between 3PAO milestones &#183; Exceed: Continuous posture <strong>without</strong> claiming an authorization Dual-Strike has not officially attained</p><p><strong>Framework center of gravity:</strong> NIST CSF 2.0 &#183; NIST 800-171 &#183; NIST 800-53 &#183; CMMC L1&#8211;L3 &#183; FedRAMP &#183; GovRAMP &#183; StateRAMP &#183; TX-RAMP &#183; ITAR-supporting program controls &#183; DFARS cyber expectations</p><p><strong>Meet the frameworks. Exceed the binder scramble.</strong></p><div><hr></div><h2>What an authorizing official actually needs</h2><h3>Framework-first compliance</h3><p>Select the contracted set &#8212; NIST CSF, 800-171, 800-53, CMMC, FedRAMP-family packs &#8212; and operate against <strong>that</strong> set with evidence refreshed daily. Framework mapping only hurts when it is a January spreadsheet. Tie controls to live telemetry and compliance becomes a running program, not a fire drill.</p><h3>POA&amp;M and binders with provenance</h3><p>Remediation needs owners, due dates, and proof. XISEM GOV generates POA&amp;M from live control failures and packages assessor-ready binders with mappings, evidence, and provenance &#8212; so the package is a product of operations, not a weekend of archaeology.</p><h3>Secure Elevate &#8212; least privilege you can defend</h3><p>Standing administrator rights are a recurring finding and a recurring incident path. <strong>Secure Elevate</strong> eliminates standing admin and replaces it with just-in-time elevation <strong>with evidence</strong> for privileged workflows &#8212; the kind of access story an assessor and a program security officer can both accept.</p><h3>Secure Resolve and Secure Access &#8212; endpoint and browsing risk in the compliance story</h3><p><strong>Secure Resolve</strong> blocks phishing, malware, and malicious domains at the endpoint. <strong>Secure Access</strong> (Anti-Venom Secure Access) surfaces browser extensions, Shadow AI, risky SaaS, and exfiltration-oriented browsing &#8212; including signals that matter for CUI and export-sensitive environments.</p><p>Endpoint and browser risk are not &#8220;IT hygiene side quests.&#8221; They are control evidence.</p><h3>ASPIRE&#8482; and MAVICE&#8480; &#8212; executive truth with drill-down</h3><p><strong>ASPIRE&#8482;</strong> answers technical posture. <strong>MAVICE&#8480;</strong> answers maturity. Together they support the questions authorizing officials, CISOs, and boards actually ask:</p><p>&#8226; Are we audit-ready against our contracted frameworks <em>today</em>?</p><p>&#8226; Which controls fail, and what evidence proves it?</p><p>&#8226; What are the top remediations that move CMMC / NIST posture this sprint?</p><p>&#8226; Can we show continuous improvement to an AO, 3PAO, prime, or board?</p><p>Vendor scores without evidence are theater. Scores with drill-down to readable proof are a management system.</p><h3>Readable evidence doctrine</h3><p>Assessors and analysts should not be asked to decode raw JSON as the primary story. XISEM presents <strong>human-readable, complete evidence</strong> &#8212; labeled fields, structured detail, full pertinent facts. Raw JSON remains available as an audit appendix, not the default narrative.</p><p>That doctrine matters when a C3PAO or agency reviewer opens the console. They get evidence chains and binders &#8212; not an opaque vendor dashboard as the only artifact.</p><h3>Siloed mission tenancy</h3><p>Client and agency data stays siloed. Attribution is enforced at write time. Managed service provider rollups must not bleed one mission&#8217;s identities, events, or assets into another. Isolation is not a UI filter; it is a platform rule.</p><h3>FedRAMP journey surfaces &#8212; honest by design</h3><p>XISEM GOV includes accreditation-status tracking and compliance POA&amp;M surfaces for executive reporting <strong>between</strong> 3PAO milestones. That is operational support for a FedRAMP-oriented journey.</p><p>It is <strong>not</strong> a claim that Dual-Strike is FedRAMP authorized unless that status is separately attained and published. We support FedRAMP-oriented <strong>operations and evidence</strong>. Authorization status is separate &#8212; and we will not pretend otherwise.</p><h3>ITAR-supporting controls &#8212; not a legal determination engine</h3><p>For export-controlled programs, XISEM GOV supports the <strong>program security</strong> story: identity hygiene, least privilege, endpoint controls, and browsing / exfiltration-oriented signals with defensible audit evidence.</p><p>Legal ITAR determinations stay with counsel and the Empowered Official. The platform supports the controls; it does not replace the legal determination.</p><div><hr></div><h2>Designed for operators, not alert theater</h2><p>A Cyber Operations Platform does three jobs well:</p><p>1. <strong>Discover</strong> the mission footprint &#8212; assets, identities, SaaS, endpoints</p><p>2. <strong>Secure</strong> with Elevate / Resolve / Access &#8212; least privilege and endpoint / browsing risk</p><p>3. <strong>Prove</strong> with daily evidence, POA&amp;M, binders, and ASPIRE / MAVICE trajectory</p><p>Logs are inputs. Evidence is the product. Action is the outcome.</p><p>That is why XISEM GOV fits agencies, DIB primes and subcontractors, state and local programs under GovRAMP / StateRAMP / TX-RAMP pressure, and government-focused MSPs who cannot afford another console that only pages people.</p><div><hr></div><h2>What we do not claim</h2><p>Public-sector buyers deserve precision:</p><p>&#8226; We do <strong>not</strong> claim FedRAMP authorization Dual-Strike has not officially attained.</p><p>&#8226; We do <strong>not</strong> issue ITAR licenses or legal determinations.</p><p>&#8226; We do <strong>not</strong> replace agency SOC-as-a-service mandates or official PMO / ATO packages.</p><p>&#8226; We do <strong>not</strong> position XISEM as &#8220;instead of&#8221; your EDR, identity provider, or GRC system &#8212; we extend and operationalize evidence those systems produce.</p><div><hr></div><h2>Who this is for</h2><p>&#8226; CISOs, ISSOs, and compliance managers who live under NIST / CMMC calendars</p><p>&#8226; Authorizing officials, CIOs, and program executives who need trajectory, not theater</p><p>&#8226; Defense Industrial Base primes and subcontractors protecting CUI</p><p>&#8226; State and local programs under GovRAMP / StateRAMP / TX-RAMP expectations</p><p>&#8226; C3PAOs, systems integrators, and government MSPs / MSSPs who need readable evidence packages</p><div><hr></div><h2>Next step</h2><p>If your program can pass an assessment week but cannot prove readiness on an ordinary Tuesday, start here:</p><p><strong><a href="https://dual-strike.com/solutions/government">dual-strike.com/solutions/government</a></strong> &#183; Contact government sales &#183; Request a demo</p><p>Audit-ready today. Every day.</p><p>&#8212; The Dual-Strike team</p>]]></content:encoded></item><item><title><![CDATA[Every campus. One cyber posture.]]></title><description><![CDATA[K-12 cybersecurity has a visibility problem dressed up as a tooling problem.]]></description><link>https://press.dual-strike.com/p/every-campus-one-cyber-posturehtml</link><guid isPermaLink="false">https://press.dual-strike.com/p/every-campus-one-cyber-posturehtml</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Thu, 09 Jul 2026 14:00:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FA7F!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36b93605-788a-4a2a-b446-a73866bb8fa4_1024x962.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FA7F!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36b93605-788a-4a2a-b446-a73866bb8fa4_1024x962.png 424w, https://substackcdn.com/image/fetch/$s_!FA7F!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36b93605-788a-4a2a-b446-a73866bb8fa4_1024x962.png 848w, https://substackcdn.com/image/fetch/$s_!FA7F!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36b93605-788a-4a2a-b446-a73866bb8fa4_1024x962.png 1272w, https://substackcdn.com/image/fetch/$s_!FA7F!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36b93605-788a-4a2a-b446-a73866bb8fa4_1024x962.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FA7F!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36b93605-788a-4a2a-b446-a73866bb8fa4_1024x962.png" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/36b93605-788a-4a2a-b446-a73866bb8fa4_1024x962.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:220,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Dual-Strike XISEM&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Dual-Strike XISEM" title="Dual-Strike XISEM" srcset="https://substackcdn.com/image/fetch/$s_!FA7F!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36b93605-788a-4a2a-b446-a73866bb8fa4_1024x962.png 424w, https://substackcdn.com/image/fetch/$s_!FA7F!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36b93605-788a-4a2a-b446-a73866bb8fa4_1024x962.png 848w, https://substackcdn.com/image/fetch/$s_!FA7F!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36b93605-788a-4a2a-b446-a73866bb8fa4_1024x962.png 1272w, https://substackcdn.com/image/fetch/$s_!FA7F!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36b93605-788a-4a2a-b446-a73866bb8fa4_1024x962.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>K-12 cybersecurity has a visibility problem dressed up as a tooling problem.</p><p>Most districts already own an endpoint product, a filter, and a Microsoft 365 or Google Workspace tenancy. What they rarely own is a single, honest answer to the questions a superintendent and a school board actually ask:</p><p>1. <strong>Are we more secure than last month?</strong></p><p>2. <strong>Which schools or campuses are at greatest risk?</strong></p><p>3. <strong>What are the top five actions that will improve our posture?</strong></p><p>4. <strong>Can we prove improvement for grants, insurers, and state reporting?</strong></p><p>Those are not SIEM questions. They are <strong>operations</strong> questions. Dual-Strike <strong>XISEM for Education (XISEM EDU)</strong> is built for that reality: a cyber operations platform for districts that do not have a twenty-person security operations center &#8212; and should not need one to run a defensible program.</p><blockquote><p>One platform to discover, secure, measure, and prove continuous improvement across every student, staff member, classroom, and campus.</p></blockquote><p><strong>Explore:</strong> <a href="https://dual-strike.com/solutions/education">dual-strike.com/solutions/education</a></p><div><hr></div><h2>The district problem in plain language</h2><p>Schools face ransomware, credential theft, and data exposure with staffing that would be called &#8220;under-resourced&#8221; in any private enterprise. Point tools create alert noise. Boards and grantors ask for <strong>measurable improvement</strong>, not another dashboard login.</p><p>The failure mode is familiar:</p><p>&#8226; Inventory lives in three places and none of them know about the smart board, the lab printer, or the Chromebook that never joined the right OU.</p><p>&#8226; Teachers still have standing local admin &#8220;because the projector driver broke last semester.&#8221;</p><p>&#8226; Filtering works on campus and softens once students and staff leave the network.</p><p>&#8226; Compliance evidence is assembled in January for a binder that is stale by March.</p><p>&#8226; When something happens, the story is scattered across logs, tickets, and screenshots &#8212; not a readable timeline a small team can act on.</p><p>XISEM EDU does not ask districts to throw away what already works. It <strong>correlates</strong> identity, assets, browsing, endpoint controls, and compliance evidence into one posture story those tools cannot tell alone.</p><div><hr></div><h2>Built for the Enhancing K-12 Cybersecurity Act agenda</h2><p>The bipartisan <a href="https://www.nextgov.com/cybersecurity/2023/04/lawmakers-reintroduce-bill-bolster-cybersecurity-k-12-schools/385366/">Enhancing K-12 Cybersecurity Act</a> (reintroduced 2023) points CISA toward three outcomes for primary and secondary schools:</p><p>1. <strong>Information, best practices, and training</strong> through a cybersecurity information exchange</p><p>2. <strong>Incident visibility</strong> through voluntary K-12 cyber incident tracking</p><p>3. <strong>Technology improvement</strong> &#8212; helping schools deploy cybersecurity capabilities against real risks to school information systems</p><p>XISEM EDU is not a substitute for CISA programs or mandated reporting. It is the <strong>district operating layer</strong> that turns that agenda into daily posture, measurable improvement, and audit-ready proof.</p><p>&#8226; What the Act pushes toward: ---------------------------- &#183; How XISEM EDU meets it: ------------------------ &#183; How XISEM EDU goes further: ----------------------------</p><p>&#8226; What the Act pushes toward: Information, best practices &amp; training &#183; How XISEM EDU meets it: CISA-aligned guidance in live compliance dashboards &#8212; not a static PDF toolkit &#183; How XISEM EDU goes further: Live top-five actions and campus risk ranking every day</p><p>&#8226; What the Act pushes toward: Incident tracking &amp; threat landscape &#183; How XISEM EDU meets it: Evidence-driven detections, alerts, and readable investigation timelines &#183; How XISEM EDU goes further: Optional Community Gateway &#8212; anonymized ESC/SEA trends without student PII</p><p>&#8226; What the Act pushes toward: Deploy cybersecurity capabilities &#183; How XISEM EDU meets it: Scout agents, Secure Elevate / Resolve / Access, Microsoft 365 + Google Workspace + Active Directory identity &#183; How XISEM EDU goes further: Automated grant evidence &#8212; before/after posture and control proof packs</p><p><strong>Meet the Act. Exceed the toolkit.</strong></p><div><hr></div><h2>What a superintendent actually needs</h2><h3>Complete campus discovery</h3><p>Security programs fail when they only know about the Windows laptop that enrolled cleanly. XISEM EDU discovers across the real campus footprint: Windows, macOS, Chromebooks (where supported), Linux, mobile, network gear, printers, IoT, cameras, smart boards, and lab equipment.</p><p>You cannot protect what you cannot see &#8212; and you cannot rank campus risk without a complete inventory.</p><h3>Identity for schools</h3><p>Districts run hybrid identity worlds. XISEM EDU correlates <strong>Microsoft 365</strong>, <strong>Google Workspace</strong>, and <strong>Active Directory / LDAP</strong> so dormant accounts, privilege creep, and impossible travel / geo-velocity show up as identity posture &#8212; with staff versus student context where the environment supports it.</p><p>Identity is not a separate product silo. It is part of the same story as the device and the browsing session.</p><h3>Secure Elevate &#8212; end standing admin for teachers and IT</h3><p>Standing local administrator rights are still one of the most common ways a phishing click becomes a district-wide incident. <strong>Secure Elevate</strong> eliminates permanent teacher and IT admin rights and replaces them with just-in-time elevation <strong>with evidence</strong> &#8212; so helpdesk workflows still work, and auditors can see who elevated, when, and why.</p><h3>Secure Resolve &#8212; protection that travels</h3><p>Students and staff leave campus. Threats do not respect the firewall. <strong>Secure Resolve</strong> blocks phishing, malware, and inappropriate domains at the endpoint &#8212; on campus or at home &#8212; so filtering posture is not a building-hours feature.</p><h3>Secure Access &#8212; Shadow AI, risky SaaS, and browser risk</h3><p>Classroom and staff browsing is where Shadow AI tools, risky SaaS, and exfiltration-oriented behavior show up first. <strong>Secure Access</strong> (Anti-Venom Secure Access) monitors browser extensions, Shadow AI usage, risky SaaS, and data-exfiltration oriented browsing signals &#8212; so IT can teach, policy, and remediate with facts instead of rumor.</p><h3>Compliance without the binder chase</h3><p>Grantors, insurers, and state programs ask for alignment to <strong>CIS Controls</strong>, <strong>NIST Cybersecurity Framework</strong>, and <strong>CISA K-12 guidance</strong>. XISEM EDU maps live evidence into compliance dashboards, daily control refresh, plans of action and milestones (POA&amp;M), and grant-ready packs &#8212; so &#8220;prove improvement&#8221; is not a weekend of screenshots.</p><h3>ASPIRE&#8482; and MAVICE&#8480; &#8212; scores that answer human questions</h3><p><strong>ASPIRE&#8482;</strong> is technical posture truth. <strong>MAVICE&#8480;</strong> is maturity. Together they answer board-level questions without translating ten thousand alerts:</p><p>&#8226; Are we more secure than last month?</p><p>&#8226; Which campuses are at risk?</p><p>&#8226; What are the top five actions?</p><p>Scores without drill-down are vanity. XISEM EDU ties letter grades and trends back to evidence a small team can act on.</p><h3>Community Gateway (optional) &#8212; share trends, not student data</h3><p>Educational Service Centers and State Education Agencies need regional awareness without becoming a privacy liability. The optional <strong>Community Gateway</strong> supports anonymized, aggregated rollups for ransomware, phishing, and vulnerable-technology trends &#8212; without exposing student personally identifiable information in shared telemetry.</p><p>Districts stay siloed. Shared views stay privacy-first and FERPA-aware by design.</p><div><hr></div><h2>Designed for thin IT teams</h2><p>XISEM EDU is intentionally <strong>not</strong> another alert factory.</p><p>A district with two or three technology staff members cannot live inside a log warehouse. They need:</p><p>&#8226; <strong>Discovery</strong> that covers classroom reality</p><p>&#8226; <strong>Controls</strong> that fit helpdesk workflows (Elevate / Resolve / Access)</p><p>&#8226; <strong>Measurement</strong> a superintendent can understand</p><p>&#8226; <strong>Evidence</strong> that survives a grant review or insurance questionnaire</p><p>That is the difference between a cyber operations platform and a pile of point products that never become a program.</p><div><hr></div><h2>What we do not claim</h2><p>Honesty matters in public sector sales:</p><p>&#8226; XISEM EDU does <strong>not</strong> replace CISA, MS-ISAC, or mandated incident reporting to federal or state agencies.</p><p>&#8226; It does <strong>not</strong> claim to be a complete legal FERPA determination engine &#8212; it supports a privacy-aware operating posture (siloed tenants, minimized student data in shared views, anonymized community trends).</p><p>&#8226; It does <strong>not</strong> ask you to rip out your EDR or web filter. Keep them. XISEM correlates what they cannot see alone.</p><div><hr></div><h2>Who this is for</h2><p>&#8226; District CIOs and Directors of Technology</p><p>&#8226; Superintendents and board cyber committees who need measurable improvement</p><p>&#8226; Educational Service Centers and State Education Agency cybersecurity coordinators</p><p>&#8226; Education-focused MSPs and MSSPs supporting multi-district portfolios</p><div><hr></div><h2>Next step</h2><p>If your district is drowning in tools and still cannot answer &#8220;are we better than last month,&#8221; start here:</p><p><strong><a href="https://dual-strike.com/solutions/education">dual-strike.com/solutions/education</a></strong> &#183; Contact education sales &#183; Request a demo</p><p>Secure the classroom. Prove the posture.</p><p>&#8212; The Dual-Strike team</p>]]></content:encoded></item><item><title><![CDATA[Introducing STAP: Strategic Technology Alliance Program]]></title><description><![CDATA[If you run an MSP, you already bought the stack.]]></description><link>https://press.dual-strike.com/p/introducing-stap-strategic-technology-alliance-programhtml</link><guid isPermaLink="false">https://press.dual-strike.com/p/introducing-stap-strategic-technology-alliance-programhtml</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Wed, 08 Jul 2026 14:00:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ULrL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f4aabdc-a8a7-49d0-94c6-5cde25eb1641_1024x962.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ULrL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f4aabdc-a8a7-49d0-94c6-5cde25eb1641_1024x962.png 424w, https://substackcdn.com/image/fetch/$s_!ULrL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f4aabdc-a8a7-49d0-94c6-5cde25eb1641_1024x962.png 848w, https://substackcdn.com/image/fetch/$s_!ULrL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f4aabdc-a8a7-49d0-94c6-5cde25eb1641_1024x962.png 1272w, https://substackcdn.com/image/fetch/$s_!ULrL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f4aabdc-a8a7-49d0-94c6-5cde25eb1641_1024x962.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ULrL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f4aabdc-a8a7-49d0-94c6-5cde25eb1641_1024x962.png" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0f4aabdc-a8a7-49d0-94c6-5cde25eb1641_1024x962.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:220,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Dual-Strike XISEM&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Dual-Strike XISEM" title="Dual-Strike XISEM" srcset="https://substackcdn.com/image/fetch/$s_!ULrL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f4aabdc-a8a7-49d0-94c6-5cde25eb1641_1024x962.png 424w, https://substackcdn.com/image/fetch/$s_!ULrL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f4aabdc-a8a7-49d0-94c6-5cde25eb1641_1024x962.png 848w, https://substackcdn.com/image/fetch/$s_!ULrL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f4aabdc-a8a7-49d0-94c6-5cde25eb1641_1024x962.png 1272w, https://substackcdn.com/image/fetch/$s_!ULrL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f4aabdc-a8a7-49d0-94c6-5cde25eb1641_1024x962.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>If you run an MSP, you already bought the stack. PSA. RMM. EDR. Identity. DNS. Browser controls. You don't need another vendor telling you to rip and replace.</p><p>You need a <strong>Cyber Operations Platform</strong> that makes what you already run <strong>more valuable</strong> &#8212; correlated, reportable, and actionable for technicians and executives alike.</p><p>That's what the <strong>Strategic Technology Alliance Program (STAP)</strong> is for.</p><p>STAP is <strong>not</strong> an integrations program. It's a <strong>technology alliance framework</strong>: mutual value between Vysion Technology Solutions, alliance partners, MSPs, MSSPs, MIPs, and shared customers.</p><div><hr></div><h2>What STAP means for your operation</h2><p>Dual-Strike XISEM <strong>extends, enriches, operationalizes, and orchestrates</strong> existing technology investments. Every alliance partner should feel that XISEM improves adoption, visibility, executive reporting, operational intelligence, and customer outcomes for their platform.</p><p>Three concepts to remember:</p><p>1. <strong>Cyber Operations Platform</strong> &#8212; XISEM is the layer above your tools, not a substitute for them.</p><p>2. <strong>Shared Security Context</strong> &#8212; telemetry from every alliance enriches every other source continuously.</p><p>3. <strong>Operational Intelligence</strong> &#8212; correlated events become decisions your team can act on Monday morning.</p><div><hr></div><h2>Shared Security Context</h2><p>Products don't operate in silos. Telemetry from Microsoft, EDR, identity, DNS, browsers, Scout, and alliance gateways flows into one shared context &#8212; then becomes Operational Intelligence.</p><p>```mermaid</p><p>flowchart TB</p><p>MS[Microsoft]</p><p>S1[SentinelOne]</p><p>TL[ThreatLocker]</p><p>GZ[Guardz]</p><p>PT[Petra]</p><p>DNS[DNS]</p><p>BR[Browsers]</p><p>ID[Identity]</p><p>SC[Scout]</p><p>SN[Sonar]</p><p>CB[COBRA&#178;]</p><p>SSC[Shared Security Context]</p><p>OI[Operational Intelligence]</p><p>MS --&gt; SSC</p><p>S1 --&gt; SSC</p><p>TL --&gt; SSC</p><p>GZ --&gt; SSC</p><p>PT --&gt; SSC</p><p>DNS --&gt; SSC</p><p>BR --&gt; SSC</p><p>ID --&gt; SSC</p><p>SC --&gt; SSC</p><p>SN --&gt; SSC</p><p>CB --&gt; SSC</p><p>SSC --&gt; OI</p><p>```</p><div><hr></div><h2>Messaging: do this, not that</h2><p>&#8226; XISEM replaces SentinelOne &#8212; XISEM operationalizes SentinelOne telemetry</p><p>&#8226; XISEM replaces ThreatLocker &#8212; XISEM extends ThreatLocker policy intelligence through Shared Security Context</p><p>&#8226; XISEM replaces Huntress &#8212; XISEM enriches Huntress detections with browser, identity, DNS, compliance, and organizational context</p><p>&#8226; XISEM integrates with Guardz &#8212; XISEM operationalizes Guardz intelligence through graph correlation and executive reporting</p><p><strong>Never state or imply:</strong> replace &#183; compete with &#183; alternative to &#183; instead of</p><p><strong>Preferred language:</strong> extends &#183; enriches &#183; correlates &#183; operationalizes &#183; orchestrates &#183; amplifies &#183; unifies &#183; enhances</p><div><hr></div><h2>Launch Packs (curated onboarding)</h2><p>STAP onboarding is organized into <strong>Launch Packs</strong> &#8212; not one-off vendor checkboxes:</p><p>&#8226; <strong>MSP Essentials</strong> &#8212; XISEM, SuperOps, Microsoft 365, Anti-Venom</p><p>&#8226; <strong>Identity Protection</strong> &#8212; XISEM, Petra, Keeper</p><p>&#8226; <strong>Business Protection</strong> &#8212; XISEM, Guardz, Anti-Venom</p><p>&#8226; <strong>Endpoint Security</strong> &#8212; XISEM, SentinelOne, ThreatLocker, Huntress</p><p>&#8226; <strong>Compliance</strong> &#8212; XISEM, Petra, ASPIRE, MAVICE, CAA</p><p>Select a Launch Pack in <strong>Partner Center &#8594; New Prospect</strong> when standing up a new evaluation.</p><div><hr></div><h2>Priority alliances (where we're investing first)</h2><p><strong>Priority 1:</strong> SuperOps &#183; Petra &#183; Guardz</p><p><strong>Priority 2:</strong> SentinelOne &#183; ThreatLocker &#183; Huntress &#183; Keeper &#183; Proofpoint &#183; DNSFilter</p><p>Each alliance in Partner Center shows status, gateway availability, Launch Pack placement, evaluation support, and documentation links.</p><div><hr></div><h2>What you can do today</h2><p>&#8226; <strong>Explore alliances:</strong> <a href="https://dual-strike.com/partners">dual-strike.com/partners</a></p><p>&#8226; <strong>Program overview:</strong> <a href="https://dual-strike.com/support/stap-strategic-technology-alliance-program">dual-strike.com/support/stap-strategic-technology-alliance-program</a></p><p>&#8226; <strong>MSP partners:</strong> apply through Partner Center for Launch Packs, evaluations, and federation</p><p>We won't ask you to abandon the vendors your clients already trust. We will help you <strong>operationalize</strong> them &#8212; together &#8212; through Shared Security Context.</p><p>&#8212; The Dual-Strike team</p>]]></content:encoded></item><item><title><![CDATA[Introducing Anti-Venom Secure Resolve]]></title><description><![CDATA[Roaming DNS is still the quiet gap in endpoint security.]]></description><link>https://press.dual-strike.com/p/introducing-anti-venom-secure-resolvehtml</link><guid isPermaLink="false">https://press.dual-strike.com/p/introducing-anti-venom-secure-resolvehtml</guid><dc:creator><![CDATA[Andrew Streetman]]></dc:creator><pubDate>Tue, 07 Jul 2026 14:00:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QlWh!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4987661-50b7-4cd3-9581-f8f5234e308b_128x128.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pQ6f!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72120f67-6e4c-49af-83b1-31ee12f6db44_1024x962.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pQ6f!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72120f67-6e4c-49af-83b1-31ee12f6db44_1024x962.png 424w, https://substackcdn.com/image/fetch/$s_!pQ6f!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72120f67-6e4c-49af-83b1-31ee12f6db44_1024x962.png 848w, https://substackcdn.com/image/fetch/$s_!pQ6f!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72120f67-6e4c-49af-83b1-31ee12f6db44_1024x962.png 1272w, https://substackcdn.com/image/fetch/$s_!pQ6f!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72120f67-6e4c-49af-83b1-31ee12f6db44_1024x962.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pQ6f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72120f67-6e4c-49af-83b1-31ee12f6db44_1024x962.png" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72120f67-6e4c-49af-83b1-31ee12f6db44_1024x962.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:220,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Dual-Strike XISEM&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Dual-Strike XISEM" title="Dual-Strike XISEM" srcset="https://substackcdn.com/image/fetch/$s_!pQ6f!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72120f67-6e4c-49af-83b1-31ee12f6db44_1024x962.png 424w, https://substackcdn.com/image/fetch/$s_!pQ6f!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72120f67-6e4c-49af-83b1-31ee12f6db44_1024x962.png 848w, https://substackcdn.com/image/fetch/$s_!pQ6f!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72120f67-6e4c-49af-83b1-31ee12f6db44_1024x962.png 1272w, https://substackcdn.com/image/fetch/$s_!pQ6f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72120f67-6e4c-49af-83b1-31ee12f6db44_1024x962.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>Roaming DNS is still the quiet gap in endpoint security.</p><p>Users leave the office. VPN split-tunnel fights the roaming client. Windows 11 enables encrypted DNS in Settings. Browsers send queries around the OS resolver. The SIEM gets a vendor export from last month &#8212; not proof that a block happened on <em>this</em> laptop, for <em>this</em> user, <em>now</em>.</p><p><strong>Anti-Venom Secure Access</strong> already covers the browser: session telemetry, verdict watermarks, AI-tool visibility, and policy in Chrome, Edge, and Firefox &#8212; correlated in <strong>Browsing Insights</strong> and investigations.</p><p>Today we name the network half:</p><h2>Anti-Venom Secure Resolve</h2><p>Dual-Strike XISEM&#8217;s first-party <strong>endpoint DNS protection</strong> &#8212; a lightweight bolt-on that works <strong>with</strong> Secure Access, not instead of it.</p><p>&#8226; <strong>Browser &#8212; Anti-Venom Secure Access</strong> &#8212; Tabs, sessions, phishing paths, SaaS and AI-tool policy</p><p>&#8226; <strong>Network / resolver &#8212; Anti-Venom Secure Resolve</strong> &#8212; OS and app DNS before traffic leaves the endpoint</p><p>Same Anti-Venom family. Different surface. One correlated picture in the console.</p><h2>Why two products?</h2><p><strong>No single hook sees every query.</strong></p><p>&#8226; <strong>Secure Access</strong> &#8212; inside the browser, including DoH bypass paths and session-level policy</p><p>&#8226; <strong>Secure Resolve</strong> &#8212; at the system resolver: apps, scripts, and background agents that never open a tab</p><p>Together they cover home ISP routers, split-tunnel VPN, Win10/Win11 encrypted DNS, and non-browser software that still phones home over DNS. Neither replaces your EDR. Both feed Dual-Strike XISEM&#8217;s evidence doctrine &#8212; neutral facts in, correlated posture and investigations out.</p><h2>What Secure Resolve does</h2><p>Paired with the <strong>Dual-Strike XISEM Agent</strong> on Windows 10 and 11:</p><p>&#8226; <strong>Local-first policy</strong> &#8212; lists cached on the endpoint; cloud for sync and evidence</p><p>&#8226; <strong>VPN- and NRPT-aware</strong> &#8212; internal zones stay on VPN DNS; yields to known relays instead of fighting them</p><p>&#8226; <strong>Encrypted upstream</strong> &#8212; aligned with modern Windows DoH/DoT</p><p>&#8226; <strong>Evidence in the same pane</strong> &#8212; batched query and block events for ASPIRE, COBRA&#178;, and investigations</p><p>&#8226; <strong>MSP policy packs</strong> &#8212; one baseline, per-client exceptions, approve/deny without a second vendor console</p><p>&#8226; <strong>Learning mode first</strong> &#8212; log would-block before enforce, like Secure Access</p><p><strong>Defense in depth:</strong> Resolve blocks C2 and unwanted categories at the resolver. Secure Access enforces browser policy on what users actually visit. When browser DoH bypasses OS DNS, Secure Access still sees it. When malware resolves a domain outside the browser, Secure Resolve still sees it.</p><h2>Your DNS, your choice</h2><p>Already on <strong>DNSFilter</strong> or another DNS Gateway? Keep it. Third-party DNS stays in the open integration fabric &#8212; evidence in, correlation out. Secure Resolve is the <strong>first-party bolt-on</strong> for MSPs who want policy and unblock workflow inside Dual-Strike XISEM. Run either, or both while you migrate.</p><h2>Who it is for</h2><p>MSPs standardizing browser and resolver policy on one console. vCISO teams tired of &#8220;DNS active&#8221; posture with no per-endpoint proof. Distributed shops where legacy roaming clients break on VPN and Win11. Existing <strong>Secure Access</strong> customers adding resolver coverage without a second product story.</p><h2>Availability</h2><p><strong>Anti-Venom Secure Resolve</strong> ships on the <strong>Dual-Strike XISEM Agent 8.8+</strong> line as a bolt-on SKU &#8212; same release train as the Windows agent and Edge Scan Sensor.</p><p>&#8226; <strong>Now</strong> &#8212; Product naming and MSP preview enrollment</p><p>&#8226; <strong>Next</strong> &#8212; Windows resolver preview &#8212; audit mode and DNS evidence in investigations</p><p>&#8226; <strong>GA</strong> &#8212; Enforce mode, unified block/unblock with existing DNS Gateways, in-console policy packs</p><p><strong>Early access:</strong> Reply here or reach us via <a href="https://dual-strike.com/">dual-strike.com</a> &#8212; share your Secure Access footprint, VPN mix, and any third-party DNS Gateway.</p><p><strong>Already on Secure Access?</strong> No browser redeploy required. Resolve adds the resolver layer when you are ready.</p><p><strong>Downloads (agent + extension today):</strong> <a href="https://dual-strike.com/downloads">dual-strike.com/downloads</a></p><blockquote><p><strong>Secure Access protects the browser. Secure Resolve protects the resolver. Dual-Strike XISEM connects both to identity, device, and investigation &#8212; so DNS is evidence, not a checkbox.</strong></p></blockquote><div><hr></div><p><em>Anti-Venom Secure Access and Anti-Venom Secure Resolve are components of Dual-Strike XISEM. Third-party DNS integrations remain optional. Confirm current GA status on dual-strike.com before customer commitments.</em></p>]]></content:encoded></item></channel></rss>