Services Methodology Why Us About Us Blog Get in Touch
← Back to Services
// SERVICE CONFIGURATION

Service Configuration
Reviews

Hardening assessment of the platform services that carry your data and expose your business — databases, web servers and mail systems — reviewed against security best practices including CIS benchmarks, vendor guidance, and the tradecraft our operators use to attack them.

DatabasesWeb ServersEmail ServersCIS benchmarksPrivilege ReviewTLS ConfigurationAudit LoggingData Exposure
Overview

Device configuration reviews harden the hosts. Service configuration reviews harden what runs on them — and it is almost always the service layer, not the operating system, that an attacker actually exploits once inside a network. A fully patched Windows Server hardened to CIS Level 2 provides no protection whatsoever if the SQL Server instance on it has xp_cmdshell enabled and an application account with sysadmin rights.

These services share a common failure pattern. They are deployed from vendor defaults under project pressure, configured by teams optimising for functionality rather than security, and then left untouched for years because they work. Privileges accumulate, legacy protocols stay enabled to support a system that was decommissioned two years ago, and no one holds a current picture of what the configuration actually permits.

We review each service against its applicable benchmark, then go considerably further — assessing the privilege model, the trust relationships with adjacent systems, and the specific configuration states our red team operators look for when they need to move from initial access to objective. Findings are prioritised by exploitability, not compliance severity.

Review Methodology
01

Scope Definition & Baseline Selection

Agreement on in-scope service instances, their role in the environment, and the applicable benchmark set. We tailor baselines to your operational constraints rather than applying them wholesale, so that recommendations remain implementable in a production estate.

02

Configuration Extraction

Secure capture of live service configuration — database instance and security settings, web server and virtual host definitions, mail transport and connector configuration — alongside version and patch level, loaded modules or extensions, and the service account security context.

03

Benchmark & Hardening Analysis

Systematic assessment against security best practices including CIS benchmarks, DISA STIGs and vendor hardening guidance, with each control marked pass, fail or not applicable and annotated for relevance to your specific deployment.

04

Privilege & Trust Model Review

Examination of accounts, roles, delegation and inter-service trust. This is where the highest-impact findings consistently emerge — service accounts with far more privilege than their function requires, delegation grants that survive their original purpose, and trust relationships that let a compromise in one service reach directly into another.

05

Exposure, Encryption & Data Handling

Assessment of network reachability, listener configuration, and transport encryption, together with how sensitive data is stored, encrypted and surfaced. We verify that services are not unnecessarily exposed, that TLS is enforced with current protocol versions and cipher suites, and that data at rest is protected appropriately.

06

Audit Logging & Detection Coverage

Review of what each service records, whether those records reach a monitored SIEM, and whether the events that indicate compromise would actually be visible. We identify the specific blind spots — privileged operations, bulk data access, configuration changes — through which an intrusion would currently pass unobserved.

07

Reporting & Remediation Guidance

A risk-rated technical report with platform-specific remediation. Executive summary and technical debrief included as standard.

// Services Covered

  • SQL databases (MSSQL, Oracle, PostgreSQL, MySQL)
  • NoSQL platforms (MongoDB, Redis, Elasticsearch)
  • Apache HTTP Server & Nginx
  • Microsoft IIS & Apache Tomcat
  • Microsoft Exchange & Exchange Online
  • Postfix, Exim & Zimbra
  • Managed cloud equivalents (RDS, Azure SQL, SES)

// Standards

  • CIS benchmarks (L1 & L2)
  • DISA STIGs
  • Vendor Hardening Guides
  • NCSC Guidance
  • PCI DSS & ISO 27001 Annex A.8

// Typical Duration

  • Single service instance: 2–3 days
  • Multi-service environment: 4–6 days
  • Enterprise estate review: 8–12 days

// Engage Us

Ready to scope an engagement? Get in touch for a no-obligation conversation.

Request Assessment
What Makes Levantis Different

Service configuration is a specialist discipline that most testing firms treat as a scanner run with a benchmark stapled to the front. Our assessors understand the internals and privilege models of each platform, and they assess configuration in the context of your wider environment — identifying how a weakness in one service combines with others to form a real attack path rather than an isolated finding.

Every recommendation is delivered as working configuration your engineers can apply, not prose describing what they should research. That difference is what turns a report into remediated infrastructure.

Harden what actually holds your data.

Patched hosts and hardened builds count for little if the services running on them are configured for convenience. Get a clear picture of your service layer.

Get in Touch