The finding catalog
36 canonically-identified finding classes. Your scanner reports instances; the catalog gives each instance a permanent identity, a tier, an owner, and a deadline. Every entry carries the rationale for its tier — including the mistake teams most often make when classifying it.
Stop active bleeding
Maintain the licence to operate
Reduce the rate at which the first two tiers refill
Showing 36 of 36 findings
BCN-T1-NET-001Tier 1 · Critical24 hoursInternet-Exposed Remote Administration Services
SSH, RDP, SMB, or equivalent management protocols reachable from the public internet.
BCN-T1-NET-002Tier 1 · Critical24 hoursPublicly Accessible Storage and Data Services
Object storage, file shares, or managed data services readable without authentication from the internet.
BCN-T1-NET-003Tier 1 · Critical72 hoursNo Segmentation Between Trust Zones
A compromise of any low-value host grants unrestricted network reachability to critical systems.
BCN-T1-IAM-001Tier 1 · Critical24 hoursMissing MFA on Privileged Accounts
Administrative, root, or break-glass accounts authenticate with a single factor.
BCN-T1-IAM-002Tier 1 · Critical48 hoursExcessive Standing Privilege
Accounts hold permanent administrative rights far beyond what their role requires.
BCN-T1-IAM-003Tier 1 · Critical72 hoursLong-Lived Privileged Credentials
Privileged API keys, access keys, or service credentials that never expire and are not rotated.
BCN-T1-DAT-001Tier 1 · Critical24 hoursInjection Flaws on Internet-Facing Applications
SQL, NoSQL, OS command, or template injection reachable from an unauthenticated request.
BCN-T1-DAT-002Tier 1 · Critical24 hoursUnauthenticated Database Endpoints
MongoDB, Redis, Elasticsearch, or similar services accepting internet connections with no authentication.
BCN-T1-DAT-003Tier 1 · Critical48 hoursUnencrypted Sensitive Data at Rest
Regulated or business-critical data stored without encryption on systems exposed to compromise.
BCN-T1-PRC-001Tier 1 · Critical24 hoursKnown-Exploited Vulnerabilities
Unpatched CVEs with confirmed exploitation in the wild, on systems an attacker can reach.
BCN-T1-PRC-002Tier 1 · Critical24 hoursExposed Management and Orchestration Interfaces
Kubernetes dashboards, CI/CD consoles, hypervisor managers, or admin panels reachable from the internet.
BCN-T1-PRC-003Tier 1 · Critical48 hoursNo Availability Protection on Revenue-Critical Services
Business-critical services with no rate limiting, no DDoS mitigation, and no capacity isolation.
BCN-T2-NET-001Tier 2 · Regulatory30 daysRegulated Environment Segmentation Gaps
Insufficient isolation around a cardholder, health, or otherwise regulated data environment.
BCN-T2-NET-002Tier 2 · Regulatory30 daysInsufficient Logging and Retention
Security-relevant events are not captured, not centralised, or not retained for the required period.
BCN-T2-NET-003Tier 2 · Regulatory30 daysMissing Intrusion Detection Coverage
No detection capability at network boundaries or across critical segments.
BCN-T2-IAM-001Tier 2 · Regulatory30 daysNon-Compliant Authentication Policy
Password and authentication settings that do not meet the applicable regulatory standard.
BCN-T2-IAM-002Tier 2 · Regulatory30 daysMissing Periodic Access Reviews
No recurring, evidenced certification that granted access remains appropriate.
BCN-T2-IAM-003Tier 2 · Regulatory30 daysUngoverned Service Accounts
Non-human identities without owners, documented purpose, or lifecycle management.
BCN-T2-DAT-001Tier 2 · Regulatory30 daysEncryption Below Regulatory Standard
Data is encrypted, but with algorithms, key lengths, or key management that fail the applicable requirement.
BCN-T2-DAT-002Tier 2 · Regulatory30 daysData Retention and Deletion Non-Compliance
Personal or regulated data kept beyond its lawful basis, or deletion requests not honoured throughout.
BCN-T2-DAT-003Tier 2 · Regulatory30 daysAbsent Data Classification
No scheme identifying which data is sensitive, where it lives, and which controls apply.
BCN-T2-PRC-001Tier 2 · Regulatory30 daysVulnerability Management Process Gaps
No defined scanning cadence, remediation SLA, or exception process — or incomplete asset coverage.
BCN-T2-PRC-002Tier 2 · Regulatory30 daysChange Management Control Gaps
Production changes without review, approval, testing, or a recorded rollback path.
BCN-T2-PRC-003Tier 2 · Regulatory30 daysUntested Incident Response Capability
No incident response plan, or a plan that has never been exercised.
BCN-T3-NET-001Tier 3 · Best Practices90 daysNon-Critical Service Exposure
Unnecessary services reachable on internal networks, expanding attack surface without immediate risk.
BCN-T3-NET-002Tier 3 · Best Practices90 daysCloud Network Hardening Gaps
Cloud network configuration diverging from CIS Benchmark or provider best practice.
BCN-T3-NET-003Tier 3 · Best Practices90 daysIncomplete Egress Filtering
Unrestricted outbound connectivity, permitting unconstrained command-and-control and exfiltration.
BCN-T3-IAM-001Tier 3 · Best Practices90 daysCoarse-Grained Role Design
Roles that are scoped but still broader than the tasks they support.
BCN-T3-IAM-002Tier 3 · Best Practices90 daysManual Credential Lifecycle
Credential provisioning, rotation, and revocation performed by hand rather than automatically.
BCN-T3-IAM-003Tier 3 · Best Practices90 daysFragmented Identity Federation
Applications with local accounts outside the central identity provider.
BCN-T3-DAT-001Tier 3 · Best Practices90 daysNo Data Loss Prevention Coverage
No technical control detecting or preventing sensitive data leaving approved channels.
BCN-T3-DAT-002Tier 3 · Best Practices90 daysUnverified Backup Restoration
Backups are taken but restoration has never been tested end to end.
BCN-T3-DAT-003Tier 3 · Best Practices90 daysDatabase Configuration Hardening
Database settings diverging from benchmark without creating direct exposure.
BCN-T3-PRC-001Tier 3 · Best Practices90 daysContainer and Image Hardening
Containers running as root, from oversized base images, or without runtime constraints.
BCN-T3-PRC-002Tier 3 · Best Practices90 daysCI/CD Pipeline Hardening
Build pipelines without dependency pinning, artefact signing, or runner isolation.
BCN-T3-PRC-003Tier 3 · Best Practices90 daysInfrastructure-as-Code Security Gaps
Infrastructure defined in code without security scanning, policy enforcement, or drift detection.
By security domain
Each domain answers one question about your estate. Findings are distributed across all three tiers within every domain.
Network
NETWhat can be reached, and from where?
9 finding classes
Identity & Access Management
IAMWho can act, and how strongly is that proven?
9 finding classes
Data Protection
DATWhat happens to the data if everything else fails?
9 finding classes
Processing Protection
PRCIs the compute that runs the business trustworthy and available?
9 finding classes
By MITRE ATT&CK technique
The catalog references 42 distinct ATT&CK techniques. Detection engineering and remediation work from the same references.
| Technique | Name | Beacon findings |
|---|---|---|
| T1005 | Data from Local System | |
| T1021 | Remote Services | |
| T1040 | Network Sniffing | |
| T1041 | Exfiltration Over C2 Channel | |
| T1046 | Network Service Discovery | |
| T1048 | Exfiltration Over Alternative Protocol | |
| T1059 | Command and Scripting Interpreter | |
| T1068 | Exploitation for Privilege Escalation | |
| T1070 | Indicator Removal | |
| T1071 | Application Layer Protocol | |
| T1078 | Valid Accounts | |
| T1078.004 | Valid Accounts: Cloud Accounts | |
| T1098 | Account Manipulation | |
| T1110 | Brute Force | |
| T1133 | External Remote Services | |
| T1136 | Create Account | |
| T1190 | Exploit Public-Facing Application | |
| T1195 | Supply Chain Compromise | |
| T1195.002 | Compromise Software Supply Chain | |
| T1203 | Exploitation for Client Execution | |
| T1210 | Exploitation of Remote Services | |
| T1213 | Data from Information Repositories | |
| T1485 | Data Destruction | |
| T1486 | Data Encrypted for Impact | |
| T1490 | Inhibit System Recovery | |
| T1498 | Network Denial of Service | |
| T1499 | Endpoint Denial of Service | |
| T1530 | Data from Cloud Storage | |
| T1552 | Unsecured Credentials | |
| T1552.001 | Credentials In Files | |
| T1552.004 | Private Keys | |
| T1552.007 | Container API | |
| T1562.001 | Impair Defenses: Disable or Modify Tools | |
| T1562.008 | Impair Defenses: Disable Cloud Logs | |
| T1567 | Exfiltration Over Web Service | |
| T1570 | Lateral Tool Transfer | |
| T1578 | Modify Cloud Compute Infrastructure | |
| T1580 | Cloud Infrastructure Discovery | |
| T1610 | Deploy Container | |
| T1611 | Escape to Host | |
| T1619 | Cloud Storage Object Discovery | |
| T1621 | Multi-Factor Authentication Request Generation |
By compliance framework
Beacon does not replace these standards. It maps to them, so that compliance-driven work is scheduled rather than competing with threat-driven work for the same urgency.
ISO/IEC 27001:2022
30 findingsPCI DSS v4.0
25 findingsSOC 2
22 findingsNIST CSF 2.0
16 findingsGDPR
9 findingsHIPAA
8 findingsCIS Benchmarks
3 findingsNIST SP 800-63B
1 findingsNIST SP 800-190
1 findingsSLSA
1 findingsNIST SSDF
1 findingsUsing the catalog in your own tooling
The catalog is published as machine-readable JSON under GPL-3.0 so it can be embedded in scanners, ticketing systems, and reporting pipelines. Cite findings by identifier — identifiers are permanent, which is what makes them safe to reference in a report someone will read years from now.