ASPIRE scoring: six pillars, one asset story
Every managed endpoint in Dual-Strike XISEM carries an ASPIRE score: a letter grade and numeric posture derived from six correlated pillars. ASPIRE is platform interpretation — built from agent evidence, extension attestation, identity linkage, and integration health.
The six pillars
• Access — Conditional Access alignment, privileged exposure
• Security — EDR presence, patch posture, hardening signals
• Posture — Agent harvest completeness, baseline drift
• Identity — User-device binding, Entra linkage
• Reputation — Threat intel hits, risky domain exposure
• Environment — Location class (office/home/unknown), network context
Scores roll up to A+ through F with numeric backing so auditors can drill into which pillar moved — not just “risk went up.”
Where you see ASPIRE
• Asset modal — primary investigative console per device
• Inventory / posture surfaces — fleet rollups by client
• Custom dashboards — vCISO views for QBRs
• Detections — “posture regression” rules when pillars drop sharply
Extension attestation matters
Anti-Venom Extension Health feeds the Security and Posture pillars. An endpoint with a healthy agent but no browser extension may still score well on server-class assets — but user workstations without extension coverage show gaps intentionally (truthful signal, not alarm fatigue).
Operator playbook
1. Open a pilot user’s workstation in Asset modal
2. Note pillar breakdown — which is weakest?
3. Cross-check Browsing Insights and Extension Health on same device
4. Remediate (deploy extension, fix EDR gap, patch) and watch pillar recovery over 48h
Route: /assets → select device → ASPIRE tab
Docs: Support wiki → ASPIRE & asset investigation · dual-strike.com
Screenshot is illustrative demo data (Northwind Traders) — replace with your redacted capture in Substack if desired.


