- Blast radius
- Pick a compromised account or VM and see what an attacker reaches across every platform, and which fixes break the most paths.
- Paths are inferred from configuration, with the confidence of each hop shown.
- OT segmentation lens
- Declare Purdue levels on scope zones and VSAT checks that OT and IT workloads do not share hosts, virtual switches, management planes, admin accounts or network paths.
- Virtualization layer only. No OT network scanning, industrial protocols or field devices.
- Ransomware readiness
- Declare your backup systems and VSAT checks whether an attacker path reaches them, whether they run alongside production and whether production admins control them, plus how many hypervisors each account controls.
- Backup software itself is not audited. Paths are inferred from configuration.
- AI & GPU isolation
- GPU passthrough and sharing, IOMMU, ACS overrides, SR-IOV next to management traffic, exposed model and dataset storage, and reachable Kubernetes control planes.
- Reads configuration only; no GPU workload or model inspection.
- Audit pack
- One control matrix across NIST SP 800-53, IEC 62443-3-3, DISA STIG and ATT&CK mitigations, with your sign-offs and exceptions, the evidence package and its receipt. CIS through your own licensed benchmark.
- Each mapping shows whether it has been reviewed. A satisfied control is not a certification.
- MITRE ATT&CK mapping
- Attack-path hops and rules map to ATT&CK techniques. Every run writes
attack-layer.json for the ATT&CK Navigator.
- Technique scores reflect configuration, not observed adversary activity.
- Audit integrity
- When the customer runs VSAT for you: the platforms' own change history for the engagement, earlier runs by the same account,
-CollectOnly, and a receipt code read aloud that proves later the package is the one from that session.
- History only goes back as far as the platforms keep logs. Short or cleared history is reported, never hidden.
- Drift between runs
- Pass
-Baseline a previous evidence package to see new, resolved, changed and unassessed items, including asset and NSX rule changes.
- Evidence that disappeared is shown as unassessed, never as resolved.
- Explainable attack paths
- Paths inferred from segments, gateways and firewall rules, each explained rule by rule, plus privilege paths and chokepoint ranking.
- Inferred from configuration. Not proof of reachability or exploitability.
- Failure-impact explorer
- A dependency model of which workloads rely on a host, uplink, datastore, switch or NSX Edge.
- A configuration model. VSAT injects no failures and does not prove failover.
- Remediation work packages
- Corrective actions grouped by owning team, ready for ticketing through
worklist.csv.
- Guidance only. VSAT never applies a change.
- Collect once, replay, share
-Replay re-evaluates a saved evidence package offline with no credentials. -Redact writes a sharing copy with consistent pseudonyms.
- Evidence packages are hashed, not encrypted. Protect them with your own controls.