LEX Agent

Lockbase EXposure Agent — cut the standing attack paths across identity and high-impact exposure, before they're exploited.

Surface the standing, reducible escalation-path preconditions across identity and high-impact exposure — standing privilege, over-broad grants, stale access edges, exploitable assets — that you can right-size, harden, or retire to shrink attack surface before an attacker uses them. Every finding comes with its risk level, the escalation path, and the specific reduction action.

[ DESIGNED FOR ]

Designed for CISOs and security leaders who need to know which standing attack paths to cut first — across Microsoft identity, sign-in, Entra, exposure-graph, and posture data — without manually correlating consoles. The Lockbase Exposure Agent turns fragmented Microsoft telemetry into ranked, actionable exposure-reduction judgment.

live // LEX_AGENT.describe()

What it
actually does

> Three-paragraph technical brief. No marketing fluff. Read top to bottom — it walks the agent's job from input to output.

  1. [ POSITIONING ] 01 / 03

    The Lockbase Exposure Agent (LEX = Lockbase EXposure) is a risk-reduction agent for Microsoft Security Copilot. It finds standing, reducible escalation-path preconditions across identity and high-impact exposure — conditions that exist right now, like standing privilege, an over-broad grant, a stale access edge, weak posture, credential material at rest, or an exposed asset — that you can remove, right-size, harden, or retire to shrink attack surface before an attacker exploits it (think the BloodHound / AzureHound standing edges you can cut). It is deliberately not attack detection or alerting — that is the SOC's lane — and not a general CVE or config-hygiene scanner.

  2. [ OPERATING MODEL ] 02 / 03

    LEX runs in three modes plus a topic router. The Risk Scorecard gives a compact, one-line-per-category triage across every area, worst-first — the place to start. Category Deep-Dive returns full findings for a chosen area, ranked P1→P4. Focus Validation tracks or validates a specific entity, finding, or claim. A topic router maps a plain-language question — "how is my Active Directory looking?" — to the right recipe of skills instead of dumping everything or guessing one pack. Every response reports strict P1→P2→P3→P4, worst finding first, and runs a bounded handful of fast skills per pass, offering the rest as follow-ups so it stays within Security Copilot's budget.

  3. [ WHAT IT RETURNS ] 03 / 03

    Findings come back as ranked lists — each with its risk level, the escalation path that makes it matter, and the specific reduction action — with the asset, permission scope, and access verb bolded, never buried in a truncated table. End-of-life software on a high-value asset is enriched with its known-CVE count, max CVSS, RCE potential, and public-exploit status; MFA gaps name the accounts actually signing in without it; non-admin app registrations are flagged as standing persistence footholds. Microsoft first-party service principals and built-in Tier-0 groups are auto-recognized and down-ranked, so findings stay high-signal. Configuration hygiene is read from Microsoft Secure Score and reported verbatim — complemented, never duplicated.

// end.report | sections: 3 | chars: 2,101 current build

Capabilities

LEX_AGENT.skills[]

61 exposure & identity-risk skills,
organized into 10 packs.

A built-in library of exposure and identity-risk skills, grouped into the packs below. Each pack is a set of named capabilities the agent invokes inline — analysts never write the underlying queries by hand. Findings come back ranked P1→P4, worst first.

cat 01
[ IDENTITY-BEHAVIOR ]

Identity Behavior & Escalation

Tier-0 access, server admin-access fan-in, lateral movement, service-account misuse, and stale privilege.

e.g.

Tier-0 exposure check

Shows which devices reach your most critical identity infrastructure outside sanctioned admin paths — a standing edge you can cut.

skills 09
cat 02
[ IDENTITY-HARDENING ]

Identity Hardening

Privileged interactive logons on endpoints, NTLM auth footprint, and synced/hybrid privileged accounts.

e.g.

Privileged auth footprint

Surfaces privileged accounts authenticating in risky ways — interactive logons and legacy NTLM you can retire before they're abused.

skills 03
cat 03
[ ENTRA-PATHS ]

Entra Attack Paths

Dangerous app-role grants, risky consent, service-principal credentials, and over-privileged dormant apps.

e.g.

App & service-principal hardening

Flags over-broad app permissions, risky consent grants, and standing service-principal credentials — the non-human escalation paths to right-size.

skills 10
cat 04
[ SIGNIN-CA ]

Sign-in Risk & Conditional Access

Privileged CA coverage gaps, legacy auth, device-code flows, and strong-MFA gaps.

e.g.

MFA usage vs. registration

Names privileged accounts actually signing in without MFA — real sign-in behavior, not just the registration number Secure Score reports.

skills 07
cat 05
[ DEFENDER-HEALTH ]

Defender Health

Disabled EDR/AV/ASR controls, sensor-health gaps, and weak-cipher / legacy-protocol config.

e.g.

Control-coverage gaps

Finds endpoints where protection is disabled or sensors are unhealthy — blind spots that quietly widen your attack surface.

skills 03
cat 06
[ EXTERNAL-EXPOSURE ]

External & High-Impact Exposure

Internet-facing exploitable RCE, edge web shells, remote-access exposure, and exposed data-plane resources.

e.g.

EOL software with CVE reality

Each end-of-life package on a high-value asset shows its known-CVE count, max CVSS, whether RCE is possible, and whether a public exploit exists.

skills 07
cat 07
[ SUPPLY-CHAIN ]

Endpoint Supply Chain

Malicious IDE-extension and browser-extension signals, plus blocklisted extension downloads.

e.g.

Developer supply-chain signals

Surfaces malicious IDE and browser extensions on endpoints — the quiet supply-chain foothold most posture tools miss.

skills 03
cat 08
[ STANDING-EXPOSURE ]

Standing Exposure (Crown-Jewel & Data-Plane)

Standing crown-jewel access, data-plane exposure, delegation, and privileged credential material at rest.

e.g.

Standing crown-jewel access

Names the exact standing access edge to cut — e.g. WRITE/OWNER access to a named crown-jewel asset — with full object IDs, never truncated.

skills 14
cat 09
[ AI-IDENTITY ]

AI / Agent Identity Risk

Privileged AI-agent identities, AI-agent attack surface, and shadow local AI activity.

e.g.

AI-agent identity governance

Inventories autonomous non-human identities and the privilege they hold — a distinct, fast-growing risk class most consoles don't track.

skills 04
cat 10
[ CONFIG-POSTURE ]

Configuration Posture (API)

Microsoft Secure Score summary — the authority for config hygiene, reported verbatim.

e.g.

Secure Score, not duplicated

Reads the official Secure Score, trend, and per-control status as the config-hygiene authority — complementing the hunting skills, never re-implementing them.

skills 01

Want the full skill list?

We walk through the complete catalog — every skill, live, against real telemetry — in a demo.

Book a demo
// catalog.summary categories: 10 total: 61 skills Full skill catalog available in a live demo.

Requirements

To deploy LEX Agent into your Microsoft Security Copilot workspace you'll need:

  • Microsoft Security Copilot license
  • Microsoft Defender XDR with Advanced Hunting access (identity, sign-in, audit, exposure-graph, and TVM tables)
  • Microsoft Entra ID with SecurityReader role (read-only)
  • Microsoft Graph access for the Microsoft Secure Score API (read-only)
  • Microsoft Defender for Identity (recommended)
  • Microsoft Intune (recommended — read-only enrichment)