Skip to content

The finding catalog

36 canonically-identified finding classes. Your scanner reports instances; the catalog gives each instance a permanent identity, a tier, an owner, and a deadline. Every entry carries the rationale for its tier — including the mistake teams most often make when classifying it.

Showing 36 of 36 findings

BCN-T1-NET-001Tier 1 · Critical24 hours

Internet-Exposed Remote Administration Services

SSH, RDP, SMB, or equivalent management protocols reachable from the public internet.

T1190T1133T1110
BCN-T1-NET-002Tier 1 · Critical24 hours

Publicly Accessible Storage and Data Services

Object storage, file shares, or managed data services readable without authentication from the internet.

T1530T1619
BCN-T1-NET-003Tier 1 · Critical72 hours

No Segmentation Between Trust Zones

A compromise of any low-value host grants unrestricted network reachability to critical systems.

T1021T1210T1570
BCN-T1-IAM-001Tier 1 · Critical24 hours

Missing MFA on Privileged Accounts

Administrative, root, or break-glass accounts authenticate with a single factor.

T1078T1110T1621
BCN-T1-IAM-002Tier 1 · Critical48 hours

Excessive Standing Privilege

Accounts hold permanent administrative rights far beyond what their role requires.

T1078.004T1098
BCN-T1-IAM-003Tier 1 · Critical72 hours

Long-Lived Privileged Credentials

Privileged API keys, access keys, or service credentials that never expire and are not rotated.

T1552T1552.001T1078.004
BCN-T1-DAT-001Tier 1 · Critical24 hours

Injection Flaws on Internet-Facing Applications

SQL, NoSQL, OS command, or template injection reachable from an unauthenticated request.

T1190T1059
BCN-T1-DAT-002Tier 1 · Critical24 hours

Unauthenticated Database Endpoints

MongoDB, Redis, Elasticsearch, or similar services accepting internet connections with no authentication.

T1530T1213T1485
BCN-T1-DAT-003Tier 1 · Critical48 hours

Unencrypted Sensitive Data at Rest

Regulated or business-critical data stored without encryption on systems exposed to compromise.

T1530T1005
BCN-T1-PRC-001Tier 1 · Critical24 hours

Known-Exploited Vulnerabilities

Unpatched CVEs with confirmed exploitation in the wild, on systems an attacker can reach.

T1190T1203T1068
BCN-T1-PRC-002Tier 1 · Critical24 hours

Exposed Management and Orchestration Interfaces

Kubernetes dashboards, CI/CD consoles, hypervisor managers, or admin panels reachable from the internet.

T1133T1610T1552.007
BCN-T1-PRC-003Tier 1 · Critical48 hours

No Availability Protection on Revenue-Critical Services

Business-critical services with no rate limiting, no DDoS mitigation, and no capacity isolation.

T1498T1499
BCN-T2-NET-001Tier 2 · Regulatory30 days

Regulated Environment Segmentation Gaps

Insufficient isolation around a cardholder, health, or otherwise regulated data environment.

T1021
BCN-T2-NET-002Tier 2 · Regulatory30 days

Insufficient Logging and Retention

Security-relevant events are not captured, not centralised, or not retained for the required period.

T1562.008T1070
BCN-T2-NET-003Tier 2 · Regulatory30 days

Missing Intrusion Detection Coverage

No detection capability at network boundaries or across critical segments.

T1562.001
BCN-T2-IAM-001Tier 2 · Regulatory30 days

Non-Compliant Authentication Policy

Password and authentication settings that do not meet the applicable regulatory standard.

T1110T1078
BCN-T2-IAM-002Tier 2 · Regulatory30 days

Missing Periodic Access Reviews

No recurring, evidenced certification that granted access remains appropriate.

T1078
BCN-T2-IAM-003Tier 2 · Regulatory30 days

Ungoverned Service Accounts

Non-human identities without owners, documented purpose, or lifecycle management.

T1078.004T1136
BCN-T2-DAT-001Tier 2 · Regulatory30 days

Encryption Below Regulatory Standard

Data is encrypted, but with algorithms, key lengths, or key management that fail the applicable requirement.

T1040
BCN-T2-DAT-002Tier 2 · Regulatory30 days

Data Retention and Deletion Non-Compliance

Personal or regulated data kept beyond its lawful basis, or deletion requests not honoured throughout.

T1213
BCN-T2-DAT-003Tier 2 · Regulatory30 days

Absent Data Classification

No scheme identifying which data is sensitive, where it lives, and which controls apply.

T1213
BCN-T2-PRC-001Tier 2 · Regulatory30 days

Vulnerability Management Process Gaps

No defined scanning cadence, remediation SLA, or exception process — or incomplete asset coverage.

T1190
BCN-T2-PRC-002Tier 2 · Regulatory30 days

Change Management Control Gaps

Production changes without review, approval, testing, or a recorded rollback path.

T1195
BCN-T2-PRC-003Tier 2 · Regulatory30 days

Untested Incident Response Capability

No incident response plan, or a plan that has never been exercised.

T1486
BCN-T3-NET-001Tier 3 · Best Practices90 days

Non-Critical Service Exposure

Unnecessary services reachable on internal networks, expanding attack surface without immediate risk.

T1046
BCN-T3-NET-002Tier 3 · Best Practices90 days

Cloud Network Hardening Gaps

Cloud network configuration diverging from CIS Benchmark or provider best practice.

T1580
BCN-T3-NET-003Tier 3 · Best Practices90 days

Incomplete Egress Filtering

Unrestricted outbound connectivity, permitting unconstrained command-and-control and exfiltration.

T1071T1041T1048
BCN-T3-IAM-001Tier 3 · Best Practices90 days

Coarse-Grained Role Design

Roles that are scoped but still broader than the tasks they support.

T1078
BCN-T3-IAM-002Tier 3 · Best Practices90 days

Manual Credential Lifecycle

Credential provisioning, rotation, and revocation performed by hand rather than automatically.

T1552
BCN-T3-IAM-003Tier 3 · Best Practices90 days

Fragmented Identity Federation

Applications with local accounts outside the central identity provider.

T1078
BCN-T3-DAT-001Tier 3 · Best Practices90 days

No Data Loss Prevention Coverage

No technical control detecting or preventing sensitive data leaving approved channels.

T1048T1567
BCN-T3-DAT-002Tier 3 · Best Practices90 days

Unverified Backup Restoration

Backups are taken but restoration has never been tested end to end.

T1490T1486
BCN-T3-DAT-003Tier 3 · Best Practices90 days

Database Configuration Hardening

Database settings diverging from benchmark without creating direct exposure.

T1213
BCN-T3-PRC-001Tier 3 · Best Practices90 days

Container and Image Hardening

Containers running as root, from oversized base images, or without runtime constraints.

T1610T1611
BCN-T3-PRC-002Tier 3 · Best Practices90 days

CI/CD Pipeline Hardening

Build pipelines without dependency pinning, artefact signing, or runner isolation.

T1195.002T1552.004
BCN-T3-PRC-003Tier 3 · Best Practices90 days

Infrastructure-as-Code Security Gaps

Infrastructure defined in code without security scanning, policy enforcement, or drift detection.

T1578
Cross-reference

By security domain

Each domain answers one question about your estate. Findings are distributed across all three tiers within every domain.

Cross-reference

By MITRE ATT&CK technique

The catalog references 42 distinct ATT&CK techniques. Detection engineering and remediation work from the same references.

TechniqueNameBeacon findings
T1005Data from Local System
T1021Remote Services
T1040Network Sniffing
T1041Exfiltration Over C2 Channel
T1046Network Service Discovery
T1048Exfiltration Over Alternative Protocol
T1059Command and Scripting Interpreter
T1068Exploitation for Privilege Escalation
T1070Indicator Removal
T1071Application Layer Protocol
T1078Valid Accounts
T1078.004Valid Accounts: Cloud Accounts
T1098Account Manipulation
T1110Brute Force
T1133External Remote Services
T1136Create Account
T1190Exploit Public-Facing Application
T1195Supply Chain Compromise
T1195.002Compromise Software Supply Chain
T1203Exploitation for Client Execution
T1210Exploitation of Remote Services
T1213Data from Information Repositories
T1485Data Destruction
T1486Data Encrypted for Impact
T1490Inhibit System Recovery
T1498Network Denial of Service
T1499Endpoint Denial of Service
T1530Data from Cloud Storage
T1552Unsecured Credentials
T1552.001Credentials In Files
T1552.004Private Keys
T1552.007Container API
T1562.001Impair Defenses: Disable or Modify Tools
T1562.008Impair Defenses: Disable Cloud Logs
T1567Exfiltration Over Web Service
T1570Lateral Tool Transfer
T1578Modify Cloud Compute Infrastructure
T1580Cloud Infrastructure Discovery
T1610Deploy Container
T1611Escape to Host
T1619Cloud Storage Object Discovery
T1621Multi-Factor Authentication Request Generation
Cross-reference

By compliance framework

Beacon does not replace these standards. It maps to them, so that compliance-driven work is scheduled rather than competing with threat-driven work for the same urgency.

NIST SP 800-63B

1 findings

NIST SP 800-190

1 findings

SLSA

1 findings

NIST SSDF

1 findings

Using the catalog in your own tooling

The catalog is published as machine-readable JSON under GPL-3.0 so it can be embedded in scanners, ticketing systems, and reporting pipelines. Cite findings by identifier — identifiers are permanent, which is what makes them safe to reference in a report someone will read years from now.