Configuration assessments
The quiet way in is a setting nobody watched.
Patches get the attention; misconfiguration gets the breach. Lavawall® does a deep dive of the critical security settings on Windows, Mac, and Linux, then tells you automatically the moment a machine drifts less secure.
Start my free trial, no credit cardMap it to a framework
Windows · macOS · Linux · automatic drift notifications
One console, three platforms
Windows configuration assessments
A deep dive of critical Windows security settings, from the computer details view or as a fleet summary, so you see where a machine is hardened and where it isn’t.
Mac configuration assessments
Macs carry almost as many security-relevant configurations as Windows. Lavawall® assesses them with the same depth instead of treating Mac as an afterthought.
Linux configuration assessments
Coverage spans many Linux distribution families, so mixed fleets don’t leave blind spots on the servers that matter most.
Drift alerts, not just a snapshot
Lavawall® runs these assessments proactively every day and sends an automatic notification whenever configurations get less secure. You act on the regression when it happens, not months later during an audit or an incident. Export any summary of the settings to Excel, CSV, or tables when you need to share the evidence.

A deep dive on every platform
The same daily assessment reads the security-relevant settings on each machine and scores them, so a per-computer deep dive and a fleet summary tell the same story. It sits alongside the same agent that monitors 7,500+ applications for patching, so configuration and patch state live in one console.

Critical Windows security settings, scored per computer.

Macs carry almost as many security-relevant settings as Windows, assessed with the same depth.

Coverage across many Linux distribution families, so servers aren’t a blind spot.
Evidence your auditor already recognises
Misconfiguration is exactly what hardening controls exist to catch. A clean, scored configuration baseline maps to the frameworks you are measured against, whether the driver is CUI/FCI under CMMC or cardholder data under PCI.
- CMMC 2.0
- NIST CSF 2.0
- CIS Controls v8
- PCI DSS
- ISO 27001
- SOC 2
- HIPAA
- Essential Eight

Want a hardened baseline set for you?
ThreeShield, the CISSP/CISA team behind Lavawall® will define the secure baseline for your Windows, Mac, and Linux fleet and wire the drift alerts to the people who can fix them.
Common questions
- Which operating systems are covered?
- Windows, macOS, and Linux, including many Linux distribution families, all from one console.
- What is configuration drift and why does it matter?
- It’s when settings quietly move away from a secure baseline. It rarely alerts on its own, which is why attackers rely on it, so Lavawall® notifies you automatically when a machine gets less secure.
- Do I have to check every machine manually?
- No, you get a per-computer deep dive, a fleet summary, and automatic notifications on regressions.