HARVEN ships with a Security Knowledge Base (SKB): a catalog of security controls, each measured by a set of ready-to-use metrics with built-in success criteria. This page lists the metrics for each control domain and the tools that can feed them, so you can see at a glance what HARVEN can measure with your stack.
Sources: the type of tool a metric reads from. HARVEN native connectors are listed first; tools after also are similar products you can plug in today through a CSV Import or a JSON Import.
🔗 Correlation: some metrics only make sense when two sources are crossed (for example, accounts in your directory against departures in your HR system). Each correlation says what each source brings. Connect both sides to get a reliable result.
💡 When you add a control, HARVEN only generates the metrics your connected sources can actually compute. The more sources you connect, the more of the catalog you cover. See Connect Data Sources.
Are your endpoints covered by an active, healthy protection agent?
Sources: EDR / XDR — Defender for Endpoint, SentinelOne, Bitdefender GravityZone, Trend Micro Vision One, Sekoia.io; also CrowdStrike Falcon, Cortex XDR, Sophos Intercept X, ESET Protect, Harfanglab
🔗 Correlation: device inventory (Intune, Workspace ONE, NinjaOne, Active Directory; also Jamf, Lansweeper, GLPI) gives the full list of endpoints; the EDR tells which ones carry an agent.
Sources: EDR — Defender for Endpoint, SentinelOne, Bitdefender GravityZone, Trend Micro Vision One; RMM — NinjaOne; also CrowdStrike Falcon, Cortex XDR, Sophos, ESET
🔗 Correlation: device inventory (Intune, NinjaOne, Active Directory; also Jamf, SCCM, Lansweeper) gives when a device first appeared; the EDR (Defender for Endpoint, Bitdefender GravityZone, SentinelOne; also CrowdStrike, Sophos) gives when its agent was installed.
Sources: EDR / XDR / SIEM — Defender for Endpoint, SentinelOne, Trend Micro Vision One, Sekoia.io; also CrowdStrike, Microsoft Sentinel, Splunk, QRadar
🔗 Correlation: asset inventory or CMDB (Active Directory, NinjaOne, Sekoia.io assets; also ServiceNow CMDB, GLPI, iTop, Lansweeper) tells which endpoints are critical; the EDR (Defender for Endpoint, Bitdefender GravityZone, SentinelOne; also CrowdStrike) tells which ones are protected.
Sources: EDR / XDR — Defender for Endpoint, Bitdefender GravityZone, Trend Micro Vision One, SentinelOne, Sekoia.io; also CrowdStrike, Cortex XDR
How quickly and reliably operating system patches are deployed.
Sources: patch management / RMM — Intune, NinjaOne; also WSUS, SCCM, ManageEngine Patch Manager, Automox, Action1
🔗 Correlation: the patch tool gives when a patch was installed; vendor bulletins or a vulnerability scanner (Defender for Endpoint; also Tenable, Qualys, Rapid7) give when it was released.
Sources: Defender for Endpoint, NinjaOne, Intune; also WSUS, SCCM, Tenable, Qualys, Rapid7
Sources: vulnerability management — Defender for Endpoint; also Tenable, Qualys, Rapid7 InsightVM, Greenbone / OpenVAS
Sources: patch management / RMM — NinjaOne, Intune; also WSUS, SCCM, Automox, PDQ Deploy
🔗 Correlation: the vulnerability scanner (Defender for Endpoint; also Tenable, Qualys, Rapid7) gives when a critical CVE was detected and closed; CVE feeds (NVD, CISA KEV) give when it was published.
How widely MFA and SSO protect your users and applications.
Sources: identity provider — Microsoft Entra ID, Google Workspace; also Okta, Duo, JumpCloud, Ping Identity
🔗 Correlation: your application inventory or CMDB (CSV / JSON) tells which apps are critical; the identity provider (Microsoft Entra ID; also Okta) tells which of them enforce MFA.
🔗 Correlation: your application inventory tells which apps are critical; the identity provider (Microsoft Entra ID, Google Workspace; also Okta, OneLogin) tells which are federated through SSO.
🔗 Correlation: the HR system (CSV import or Google BigQuery; also Workday, Lucca, BambooHR, PayFit) gives hire dates; the identity provider (Microsoft Entra ID; also Okta, Google Workspace) tells whether the newcomer enrolled MFA within 30 days.
Sources: sign-in logs — Microsoft Entra ID, Sekoia.io; also Okta, Duo, Microsoft Sentinel, Splunk
How fast access is revoked when people leave, and how clean your accounts stay.
🔗 Correlation: the HR system (CSV import; also Workday, Lucca, BambooHR, PayFit) gives the departure date; the identity provider (Microsoft Entra ID; also Okta, Google Workspace, Active Directory) gives the date the account was disabled.
🔗 Correlation: same as above — HR departure date against account deactivation date, compared with your SLA.
🔗 Correlation: the HR system (CSV import or Google BigQuery; also Workday, Lucca, BambooHR) lists active employees; the identity provider (Microsoft Entra ID; also Okta, Google Workspace, Active Directory) lists enabled accounts. Accounts with no matching employee are orphaned.
Sources: identity provider — Microsoft Entra ID, Google Workspace, Active Directory (Local Connector); also Okta, JumpCloud
Sources: identity governance — Microsoft Entra ID (Access Reviews); also SailPoint, Saviynt, Okta Identity Governance, or review trackers (CSV)
Controls around admin and privileged accounts.
Sources: Microsoft Entra ID (privileged roles and MFA); also Okta, Active Directory admin groups, CyberArk, Delinea
Sources: Microsoft Entra ID (Access Reviews); also SailPoint, CyberArk, review trackers (CSV)
Sources: Microsoft Entra ID, Active Directory (Local Connector); also AWS CloudTrail, CyberArk / Delinea session logs
Sources: Microsoft Entra ID, Active Directory (Local Connector); also CyberArk, Delinea, Keeper
Sources: Microsoft Entra ID (PIM), Microsoft Azure (RBAC); also CyberArk, Delinea, BeyondTrust, AWS IAM Identity Center
How your users respond to phishing simulations and security training.
Sources: phishing simulation platform — also KnowBe4, Hoxhunt, Cofense, Proofpoint, Gophish, Mantra, Arsen
Sources: phishing simulation platform — same as above
Sources: phishing simulation platform — same as above
🔗 Correlation (optional): the HR system gives departments and managers to target follow-up training.
Sources: phishing simulation platform or email security — also KnowBe4 PAB, Hoxhunt, Proofpoint, Mimecast, Defender for Office 365
🔗 Correlation: the training platform or LMS (also KnowBe4, Moodle, 360Learning, Docebo) lists completions; the HR system or identity provider (Microsoft Entra ID, Google Workspace) lists who should have completed it.
How well your cloud resources are monitored, encrypted and locked down.
Sources: cloud provider — Microsoft Azure; also AWS CloudTrail / Config, GCP Cloud Audit Logs, CSPM tools (Wiz, Prisma Cloud, Orca)
Sources: Microsoft Azure, AWS, Scaleway; also GCP, OVHcloud, Wiz, Prisma Cloud
Sources: Microsoft Entra ID; also AWS IAM, GCP IAM
Sources: Microsoft Azure; also AWS, GCP, Wiz, Prisma Cloud
Sources: Microsoft Azure (RBAC), Microsoft Entra ID; also AWS IAM Access Analyzer, GCP Policy Analyzer, Wiz
Sources: Microsoft Azure, AWS, Scaleway; also GCP, OVHcloud, Wiz, Prisma Cloud
Sources: Microsoft Azure, Intune; also AWS, GCP
🔗 Correlation: the cloud provider (Microsoft Azure; also AWS, GCP) lists instances; the agent tool (Defender for Endpoint, NinjaOne; also Datadog, CloudWatch agent, Azure Monitor) tells which ones report.
Sources: Microsoft Azure, AWS, Scaleway, NinjaOne; also GCP, Lansweeper
🔗 Correlation: each instance's OS version is checked against vendor end-of-life dates.
Sources: Microsoft Azure, Scaleway; also AWS, GCP, cloud cost tools
Sources: Microsoft Azure, AWS, Scaleway; also GCP
Sources: Microsoft Azure; also AWS IAM, GCP IAM, Wiz
Discovery and management of unsanctioned apps and devices.
Sources: CASB — Microsoft Defender for Cloud Apps; also Netskope, Zscaler, Cisco Umbrella
🔗 Correlation: your list of approved applications (CSV / JSON) separates sanctioned from unsanctioned apps.
🔗 Correlation: the identity provider (Microsoft Entra ID, Google Workspace; also Okta) shows who signs in and from which device; the MDM / EDR (Intune, Defender for Endpoint; also Jamf, Workspace ONE, Kandji) tells which devices are managed.
Sources: Microsoft Defender for Cloud Apps, FortiAnalyzer; also Zscaler, Netskope, Palo Alto, Cisco Umbrella
Sources: SIEM / ITSM — Sekoia.io; also Microsoft Sentinel, Splunk, ServiceNow, Jira Service Management
Sources: Microsoft Defender for Cloud Apps; also Netskope, Zscaler
Health and exposure of your network infrastructure.
Sources: firewall management — also Fortinet FortiManager, Palo Alto Panorama, Check Point, Stormshield, Tufin, AlgoSec
Sources: network documentation or firewall zones — also NetBox, FortiManager, Palo Alto Panorama, Cisco
🔗 Correlation: the network inventory (also NetBox, CMDB) lists segments; the vulnerability scanner (also Tenable, Qualys, Rapid7, Greenbone) tells which were scanned in the last 30 days.
Sources: FortiAnalyzer, Microsoft Azure (network security groups); also FortiGate, Palo Alto, Check Point, AWS security groups, external scanners (Shodan, Censys)
Sources: FortiAnalyzer (device firmware); also FortiManager, Palo Alto Panorama, Cisco
🔗 Correlation: each device's firmware version is checked against the vendor's latest release and advisories.
Protection of sensitive data at rest and when shared.
Sources: Microsoft Azure; also AWS KMS, GCP, BitLocker / FileVault reports, database encryption status
🔗 Correlation (optional): a data classification tool (also Microsoft Purview, Varonis) tells which data stores are sensitive.
Sources: SharePoint (Admin); also Microsoft Purview, Varonis, Netwrix, review trackers (CSV)
Sources: SharePoint (Admin); also Google Drive, Box, Dropbox, Microsoft Purview, Netskope
🔗 Correlation: sharing settings (who can access the file) are crossed with sensitivity labels (which files are sensitive).
Sources: SharePoint (Admin), Microsoft Azure; also Google Workspace admin, Box, Dropbox
Sources: Defender for Endpoint; also Microsoft Purview DLP, Forcepoint, Netskope, ServiceNow
External sharing and guest access in Microsoft 365 (SharePoint, OneDrive, Teams).
Sources: SharePoint (Admin)
Sources: Microsoft Entra ID
Sources: Microsoft Entra ID (guest accounts and Access Reviews)
Sources: SharePoint (Admin)
Coverage and speed of detection and response, mostly fed by your SIEM/XDR.
Sources: SIEM / XDR — Sekoia.io, SentinelOne; also Microsoft Sentinel, Splunk, Elastic Security, QRadar, Google SecOps
Sources: SIEM / XDR — Sekoia.io; also Microsoft Sentinel, Splunk, Elastic Security
Sources: SIEM / XDR or on-call — Sekoia.io, Opsgenie; also Microsoft Sentinel, Splunk, PagerDuty, TheHive
Sources: SIEM / XDR — Sekoia.io; also Microsoft Sentinel, Splunk, CrowdStrike
Sources: SIEM / XDR or on-call — Sekoia.io, Opsgenie; also Microsoft Sentinel, Splunk, PagerDuty
Sources: SIEM / XDR — Sekoia.io, SentinelOne; also Microsoft Sentinel, Splunk, TheHive
Sources: SIEM / XDR, on-call or ITSM — Sekoia.io, FortiAnalyzer, Opsgenie; also Microsoft Sentinel, Splunk, PagerDuty, ServiceNow, TheHive
Raw data is only half the story. Every metric above is refined by your Workspace Context (your business and IT environment) and by your specific rules. The same value can mean very different things in two organizations: 80% EDR coverage is a real gap if the missing devices are production servers, and a non-issue if they are personal phones that are out of scope.
HARVEN uses your context to decide what to count, what to compare against, and what to leave out. A few examples of IT context fields and how they shape your metrics:
Workstation Count and Workstation Management: anchor endpoint coverage metrics, so a device missing from the EDR is spotted even when your inventory is incomplete.
Critical Servers and Critical Applications: define what "critical" means in % Critical Endpoints Without EDR, % Critical Apps MFA-Protected or % Critical Apps using SSO.
Cloud Providers and Hosting: tell HARVEN which cloud posture checks apply, and whether an on-premises estate is expected.
Remote Access Methods and Network Architecture: frame the exposure and segmentation metrics.
SaaS Used and Managed Services: separate sanctioned apps from shadow IT, and clarify which controls a third party runs.
Primary Domains: scope identity metrics to your own accounts.
On top of the context, specific rules adjust how a metric is calculated. You can accept the rules HARVEN suggests from your profile, or write your own in plain language:
Scope rules: "Do not count accounts in the service_accounts or guests groups", "Exclude kiosk devices from EDR coverage".
Other rules: "Admin passwords must be rotated every 180 days", "Use NinjaOne as the primary source for vulnerability metrics, not Defender".
Constraints and known technical debt (a legacy server that can't be patched, an app incompatible with MFA) are also taken into account, so they show up as accepted or planned rather than as new findings.
👉 Filling in your context is the single biggest lever on metric accuracy. Learn how in Setup Organization Context.
Browse every supported source: Data Sources — Index
Deploy a control: Generate your first Control
Explore a metric: Exploring Metric Details
Need a metric that isn't listed? Create a new Metric from a Prompt
Using a tool that isn't listed here? Tell us at [email protected].