Damocles resource centre

Product briefs that explain what you receive and where the capability fits.

Read the current web page first for the complete product or service explanation. Downloadable PDFs remain available where an approved secondary document exists.

Use the material to make a decision

Each brief should answer the questions buyers and operators actually have.

The resource centre brings together the public product explanation, package relationship, managed-service activity, operating model and scope boundaries.

Use the product page to understand the capability, then use the downloadable document for internal circulation or offline review where available.

01

What problem it solves

Understand the operational pain and the outcome the product is intended to improve.

02

What you receive

See the actual capabilities, managed activities, outputs and customer views.

03

What must be scoped

Review the quantities, service responsibilities, dependencies and boundaries confirmed before activation.

Resources

Resources for evaluating, buying and operating Damocles security services.

Explore Guardian products, Damocles security services, technical methodology and downloadable product briefs.

Recommended resources

Start here

Use these entry points for platform evaluation, package selection, technical assurance and procurement review before searching the full library.

Guardian product briefs

Explore Guardian products, managed capabilities and buyer information.

Guardian

Guardian Security Monitoring

Agent, collector and log-source health, alert lifecycle, investigation context and provider operations using compatible monitoring connectors.

Guardian

Guardian Vulnerability Management

Asset and vulnerability posture, prioritised remediation, ownership, evidence and resolution review using compatible assessment connectors.

Guardian

ZeroShield Security Bundles

Package Guardian Core with explicit protection, assurance and managed-defence products without hiding components or responsibilities.

Guardian

Svalinn Managed Web Application Firewall

Managed WAF policy, tuning, traffic protection, attack visibility, change handling and Guardian follow-up for approved applications.

Guardian

Guardian External Vulnerability Monitoring

Continuous monitoring of approved public-facing assets for new or persistent exposure, with accountable remediation and verification.

Guardian

Aegis Managed Defence

Damocles monitoring, alert triage, investigation, escalation, action tracking and service reporting through Guardian.

Guardian

Guardian Product Catalogue

Explore detailed vendor-neutral product briefs covering capability, customer experience, Damocles activity, connectors, onboarding, evidence and responsibilities.

Guardian

Guardian Website Vulnerability Monitoring

Baseline monitoring for approved public websites with findings, owners, evidence and remediation tracking included in Guardian Core.

Guardian

Guardian DNS Protection

Managed DNS policy, malicious-destination blocking, identity context, investigation support and Guardian action follow-up.

Guardian

Guardian Endpoint Protection and Managed Patching

Managed endpoint security, operating-system and supported application patching, restart tracking, exceptions and reporting.

Guardian

Guardian Dark Web Monitoring

Monitor approved domains, staff email addresses and brand terms, then turn material exposure into accountable response.

Guardian

Guardian Plans and Add-ons

Compare Guardian Core, Assurance, Managed Defence and the explicit protection, assurance and managed-service products available as add-ons.

Guardian

Guardian University and Human Risk

Assigned learning, progress, assessment, certificates and human-risk remediation for staff and approved participant experiences.

Guardian

Guardian Katana Website and API Security Testing

Deeper active website and API testing with approved profiles, customer-readable evidence, remediation actions and rescans.

Guardian

Guardian Security Operations

Source health, alerts, investigations, escalation, actions and operational reporting through a connector-neutral Guardian operating model.

Guardian

Guardian Platform Overview

See how Guardian turns security posture, findings and operational signals into owned remediation, reviewable evidence and clear reporting.

Damocles security service briefs

Compare assessment, testing, network-security and managed-security services, then download the detailed technical brief when you need deeper scope information.

Penetration Testing

External network penetration testing

Test exposed hosts, services and remote-access paths to identify exploitable weaknesses that could provide an initial foothold or expose sensitive information.

Penetration Testing

Internal network penetration testing

Test representative internal access to expose weak trust boundaries, credentials, services and privilege paths that could turn one compromised device into broader control.

Penetration Testing

Web application penetration testing

Test the application from public, authenticated, cross-role and integration perspectives to identify weaknesses that could expose accounts, data, privileged functions or business workflows.

Penetration Testing

API penetration testing

Test API endpoints across unauthenticated, authenticated, cross-role and integration contexts to expose access-control, token, input and workflow weaknesses.

Penetration Testing

Wireless penetration testing

Test corporate, guest and representative wireless networks to identify weak authentication, isolation, management and trust paths into connected environments.

Penetration Testing

Active Directory and identity penetration testing

Review and test representative Active Directory access to identify credential, delegation, permission and trust paths that could expand one account into wider administrative control.

Penetration Testing

Mobile application penetration testing

Test the application package, device behaviour and supporting API interactions to expose weaknesses in storage, transport, platform integration and business workflows.

Assessment & Review

Secure code review

Review architecture and source code to trace trust boundaries, sensitive data and security-critical functions that runtime testing may not fully expose.

Assessment & Review

Cloud security review

Review cloud identities, configuration, networking, data services and operational controls to expose excessive access, unintended exposure and weak recovery or monitoring paths.

Assessment & Review

Incident response readiness review

Review plans, roles, access, evidence sources and decision paths through representative scenarios to identify gaps that could delay containment, investigation or recovery.

Network Security

Firewall security review

Compare rulebases, objects, administration and logging with required traffic flows to identify excessive access, stale policy and control gaps.

Network Security

Network segmentation review

Compare the intended trust model with routing, firewall policy, management access and representative traffic paths to identify missing boundaries and practical bypass paths.

Network Security

Remote access and VPN review

Review remote-access architecture, identity, device trust and post-connect controls to identify paths that could turn stolen credentials or an unmanaged device into internal access.

Network Security

Firewall migration and implementation

Review the source policy, target design and migration controls so required connectivity is preserved while stale, excessive or mistranslated access is identified.

Network Security

Network-device hardening

Review representative routers, switches and security appliances against an agreed baseline to identify weak administration, services, protocols and recovery controls.

Network Security

Network resilience and high availability

Review topology, dependencies and high-availability controls, then validate agreed failure scenarios to expose single points of failure and unsafe recovery assumptions.

Managed Security

Managed Security Operations

Review source health, triage, investigation and escalation workflows to identify telemetry gaps, inconsistent decisions and actions that may not reach accountable owners.

Guides & methodology

Technical guidance explaining how Damocles scopes, assesses and reports security work.

Technical Guide

Security Testing Methodology

Exact framework versions, testing perspectives, coverage statuses, evidence, mapping types, limitations and review ownership.