AIC capabilities

Analog Informatics Corporation (AIC) builds privileged access, identity, audit, and compliance evidence as modules on one platform. Those modules ship in two products. The AIC Enterprise Privilege Management Suiteâ„¢ is the set of modules enterprise buyers score. AIC CMMC Completeâ„¢ is a new, separate kit for Cybersecurity Maturity Model Certification (CMMC) Level 1, Level 2, and Level 3. Modules are not sold one by one. The Level 2 kit includes the Level 1 kit. The Level 3 kit includes the Level 2 kit. Both products run in the cloud or on premises, in a secure enclave, and on air-gapped systems.

The kits receive constant feeds, generate alerts, mitigate issues, and constantly check each system against its baseline configuration where a feed path exists. That makes continuous compliance possible instead of a point-in-time check. Training is free. We work with the reseller, Managed Service Provider, or service provider the customer already uses.

Capabilities in one kitOne box labeled AIC kit contains five labeled groups: privileged access, identity, audit, evidence, and monitoring.AIC kitPrivileged accessIdentityAuditEvidenceMonitoring
Access, identity, audit, evidence, and monitoring sit in one kit instead of separate products.

Capability list

CapabilityWhat it does
Privileged Identity Management (PIM)Discover systems, accounts, privileged group membership, password age, SSH keys, and cloud access keys. Find where each credential is used, change it, and push the new value to every service, task, application pool, COM+ and DCOM application, connection string, and configuration file that uses it. Covers Windows, macOS, Linux and Unix, Active Directory and LDAP, databases, cloud accounts, network and hardware devices, and applications. Extend to any other platform with SSH and Telnet scripts, browser automation, or the REST API (OpenAPI). Vault and check out credentials. See Privileged Identity Management.
Blast radiusReport how many hosts and services each shared credential reaches, and reduce it by rotating and propagating or by splitting the account into one managed service account per host, with a preview first.
Browser automationChange credentials on devices and services that are managed only through a web page. Ready-made automations ship with the kit. Build your own in the console with a visual workflow builder.
Privileged Access Management (PAM)Live SSH, RDP, and VNC sessions in the browser through a broker, approvals, and command restriction that blocks dangerous commands as they are typed.
Session recordingRecorded SSH, RDP, and VNC sessions with replay on the Level 3 kit.
JumpManaged access path for privileged sessions. The Level 3 kit isolates Jump and records sessions.
Privileged User Management (PUM)Privilege elevation and delegation management: endpoint elevation, delegation, least privilege, application and command control, just-in-time elevation, and privileged activity auditing. Elevate through the Agent on the system or by remote control from the AIC Server, with one-time activation codes, challenge and response, signed grants, or agentless WinRM and SSH. Windows is the most complete today. Apple Mac and Unix/Linux are expanding. See Privileged User Management.
Identity Governance and Administration (IGA)Account lifecycle and periodic access review for kit accounts. Governance across other applications is planned.
Secure Application LaunchStart an application with credentials the user never sees.
Document sharing vaultStore and share sensitive files with classification marking.
Data classificationCMMC, US government, NATO, and national markings with clearances, mandatory access control, and audited formal release. See Data classification.
Conditional accessAllow, step up, or deny sign-in by country, network address, multifactor authentication, and session policy. See Conditional access and threat defense.
Threat intelligence and attack reportDeny sign-in from addresses on threat feeds, and report blocked and failed attempts mapped to MITRE ATT&CK.
Audit and event forwardingPrivileged-action and session records, Windows Event Log, and syslog in RFC 5424, CEF, or LEEF. Route each event type to its own destinations: Splunk, Microsoft Sentinel, Azure Monitor, Datadog, Amazon CloudWatch, Google Cloud Logging, any web service, another AIC Server, email, and ServiceNow or Jira tickets. Text message notices through seven providers. See Logging, SIEM, and event forwarding.
Assessment BinderLiving evidence package shared by the assessor, the Managed Service Provider, and the customer.
Current State ComplianceLedger of control findings with rescan.
Configuration complianceCheck workstations and servers against STIG-oriented baselines, repair known settings with Fix-It, flag what needs IT, and optionally block a system until it complies. See Configuration compliance.
Known default credential detectionScan networks, match systems and devices to licensed public default-password dictionaries, and flag dangerous defaults still in use. See Known default credentials.
VM power schedulingPower off idle workstations and session capacity on a schedule or after idle time, and start them on demand, to cut cloud cost and shrink the attack surface. See VM power scheduling.
Incident ResponseIncident records, detectors, and email or text alerts when a messaging path is configured.
Training and attestationAssign documents to named people and collect a signed attestation.
Governed mailMail for Federal Contract Information or Controlled Unclassified Information inside the kit.
Cryptography and key custodyAWS-LC, which holds a FIPS 140-3 certificate, on server cryptographic paths. Keys in software, in a PKCS#11 HSM, or in a customer-owned AWS KMS, Azure Key Vault Managed HSM, or Google Cloud KMS key. Separate key sets per system group, with rotation and re-encryption. See Key management.
Directory sign-inActive Directory and LDAP sign-in, and Microsoft Entra ID, Okta, Ping Identity, and other OpenID Connect and Security Assertion Markup Language (SAML) 2.0 providers, with another step beyond a password.
High availabilityAutomatic database failover on customer-supplied hosts.
Air-gapped operationThe kits run on connected and fully air-gapped systems on Windows, Linux, and Apple Mac, in the cloud or on premises. The Agent rotates passwords on schedule from a shared seed with local propagation and no server connection, and handles elevation on the system itself. See Air-gapped systems.
Managed Service Provider operationA Managed Service Provider can administer inside the customer boundary.
LocalizationThe operator console ships with 18 language packs. See Localization.
Evidence feedsRecords can feed Competitors and other compliance packages through export and syslog.
Certificate lifecycle managementDiscovery, renewal, and governance of certificates across certificate authorities.
Cloud infrastructure entitlement managementAnalysis of cloud account permissions.
Vulnerability analysisAnalysis of discovered systems for known vulnerabilities. Planned as an add-on module.
Universal host logon bannerOne banner pushed to every system.

The industry terms for these capabilities are on Industry functions.

Screenshots

A live SSH command line, recorded, with a dangerous command blocked as it is typed.
A live, recorded RDP desktop session to a Windows workstation, in the browser.
Endpoint privilege elevation and delegation covers Windows, Unix, approvals, policy, and air-gapped tokens in one place.
Failed sign-ins are mapped to MITRE ATT&CK technique T1110 Brute Force, with top sources and most-tried usernames.

More on Product screenshots.

See it on your use case

Request a demo