shorfall
Cryptographic posture management for Microsoft Defender

Find the weak crypto in your Defender estate. Prove it is reported gone.

No new agents: the Defender sensor you already run finds every weak certificate, legacy protocol and quantum-vulnerable key. Each becomes an owned fix that closes only on evidence.

  • First inventory within the hour
  • Runs in your Azure subscription
  • Free for your own estate
order-processorConsumer, TLS 1.2Wave 1: verifyWave 1: verified batch-reportingConsumer, TLS 1.2Wave 1: verifyWave 1: verified web-frontendConsumer, TLS 1.3 payments-api :8443TLS, internet-facingSHA-1, RSA-1024, boundSHA-256, ECDSA P-256, TLS 1.3Wave 2: lockedWave 2: unlockedWave 2: verified identity-svc :443TLS 1.3, no weak crypto dc-01:389 LDAP sql-01:1433, TLS 1.2
  • RSA-2048: quantum-vulnerable (Shor)
  • ECDSA P-256: quantum-vulnerable (Shor)
  • SHA-1: broken today
  • TLS 1.0: still enabled for a vendor
  • OpenSSL 1.1.1: end of life, no ML-KEM path
  • Pinned thumbprint: crypto rigidity
  • X25519MLKEM768: hybrid key exchange
  • ML-DSA-65: FIPS 204
An illustrative first day in a 5,000-device tenant

You already deployed the sensor.

18,292certificates inventoried, nothing installed
11,204quantum-vulnerable keys; 412 protect live services
17recommendations, grouped by what changes them
Today's exposure first

Old ciphers, unknown owners, and whatever breaks when you touch them.

Most estates still run SHA-1 certificates, TLS 1.0 kept alive for one vendor, and thumbprints pinned in web.config. Nobody knows who owns half of it, so every hardening change risks the application nobody remembers. Defender already sees most of the evidence.

The long game is harvest now, decrypt later: RSA and ECC keys guarding data that must stay confidential for years. The inventory is no longer optional:

  • DORAEU financial entities keep a certificate register mandate
  • PCI DSS 4.0inventory of cipher suites and protocols in use mandate
  • EO 14412US federal systems move key establishment to post-quantum algorithms by end of 2030 federal mandate
  • NIST IR 8547draft plan: RSA and ECC deprecated after 2030, removed from the standards by 2035 draft
  • UK NCSCdiscovery and a migration plan by 2028 guidance
  • Microsoft, Apr 2026fifteen countries and the EU recommend or require cryptographic inventories

Microsoft's own guidance is a six-stage lifecycle and a manual integration project. Shorfall runs it for your Defender estate.

The loop

One deployment. Then the loop never stops.

  1. Deploy One-time setup

    One template into your subscription; one script gives the web app's own managed identity read-only Defender roles. First inventory within the hour. No Shorfall identity, no agent, nothing on endpoints.

    Machine.Read.All, AdvancedQuery.Read.All and Vulnerability.Read.All, held by your identity
  1. Discover and inventory

    Advanced Hunting refreshes the passive inventory. Where telemetry is not enough, the published read-only script runs through Live Response, only on the servers you select. Metadata leaves the endpoint; secrets never do.

    CryptoDiscovery.ps1, read-only, hash recorded on every inspection
  2. Map dependencies

    Defender network telemetry becomes a dependency graph: which processes consume each weak service, over which port, with which certificate. You see the blast radius before anything changes.

    DeviceNetworkEvents: source process, target service, bound certificate
  3. Assess, then sequence

    Findings become recommendations grouped by what changes them: one certificate, one policy, one application, each with plain-sentence drivers and an owner. The graph orders the waves: consumers verify first, later waves stay locked until they do.

    Drivers, not bare scores. AIVD, CWI and TNO PQC Migration Handbook method
  4. Verify

    Mark a change done and Shorfall re-inspects, closing the recommendation only when the evidence is gone. Findings carry a lifecycle: new, fixed, reintroduced. Your readiness trend is evidence, not opinion.

The dependency graph

Migrate in an order that breaks nothing.

A certificate is easy to rotate. The services that pin, trust, and negotiate against it are not. Shorfall maps every consumer of a weak service from Defender network telemetry, then orders the migration so consumers prove they accept the replacement cryptography before the service changes.

The metrics

Metrics your board can track. Drivers under every item.

No bare scores. Five programs report coverage-normalized percentages with a target and a trend. Every recommendation lists the drivers behind its tier. Inventory exports as CSV or a CycloneDX 1.6 CBOM.

Replace weak certificate on payments-api :8443 Critical
EvidenceSHA-1, RSA-1024, private key, bound
Consumersorder-processor and batch-reporting, 1,596 connections in 7 days
Defender contextExposure level high, device value high
Applicationpayments-api, owner payments-team, 15-year retention
Mosca testFail: 15 y + 8 y > 2035
FixReissue SHA-256 or ECDSA, rebind :8443, plan ML-DSA
OrderWave 2, after consumers verify TLS 1.3
VerifyRe-inspection closes it only when the evidence is gone
Built for security review

Designed to pass your hardest questions.

01 Read-only

Nothing on your endpoints changes.

The scanner enumerates, parses and reports. It cannot modify registries, certificates, processes or TLS configuration. Remediation stays in your hands; Shorfall verifies it.

02 Secrets stay home

Metadata leaves. Keys never do.

No private keys, no file contents, no tokens, no payloads. Findings carry algorithm, key size, location and confidence, nothing an attacker could use.

03 You hold the script

Published source, recorded hash.

The scanner's source and SHA-256 are on the release feed. Shorfall keeps it current in your own Live Response library, or you upload it yourself, and every inspection records the hash of what actually ran.

04 Your tenant, your identity

Nothing of yours is ever held by us.

Deployed into your Azure subscription from a readable template. Defender roles sit on your own managed identity, evidence in your Cosmos DB, no call home. Delete the resource group and Shorfall is gone.

Early access

See your coverage gap in the first hour.

Deploy Shorfall in your tenant and the passive assessment starts on your estate. The Community edition is free for your own tenant, no device caps, registered to your organisation; service providers operating it for clients need a licence.

Dependency resolved. You reached the end of the graph.
Deploy in your tenant Or talk first. Design partners: 500 to 20,000 Defender devices