Initial commit: establishing the cqre.net perimeter
This commit is contained in:
@@ -0,0 +1,10 @@
|
||||
---
|
||||
title: "Products"
|
||||
description: "Open-source and commercial tools for M365 governance, audit log retention, and configuration management."
|
||||
eyebrow: "Open Source & Commercial"
|
||||
lead: "Three tools that together give you complete visibility over your Microsoft 365 tenant — what happened, what your configuration looks like, and what it all means."
|
||||
---
|
||||
|
||||
PULSAR captures the signal. ASTRAL holds the baseline. AURORA makes sense of both.
|
||||
|
||||
All three tools are independently useful and progressively more powerful in combination.
|
||||
@@ -0,0 +1,104 @@
|
||||
---
|
||||
title: "ASTRAL"
|
||||
description: "Admin Security: Tenant Review, Automation & Lifecycle. Git-tracked M365 configuration snapshots with drift detection, PR-based review, and baseline restore."
|
||||
eyebrow: "Free & Open Source"
|
||||
lead: "ASTRAL answers the question your M365 tenant cannot: what does our configuration look like right now, what did it look like before, and what changed — and who approved that change?"
|
||||
icon: "🌌"
|
||||
badge:
|
||||
text: "Free & Open Source"
|
||||
color: "green"
|
||||
actions:
|
||||
- label: "View on GitHub"
|
||||
url: "https://github.com/cqrenet/astral"
|
||||
external: true
|
||||
primary: true
|
||||
- label: "Learn about AURORA →"
|
||||
url: "/products/aurora/"
|
||||
---
|
||||
|
||||
## What ASTRAL Does
|
||||
|
||||
ASTRAL takes regular snapshots of your Microsoft 365 configuration — Conditional Access policies, Intune compliance and configuration profiles, admin role assignments, authentication methods, cross-tenant access settings, privileged groups, and more — and stores them as versioned files in a Git repository.
|
||||
|
||||
<div class="feature-list">
|
||||
<div class="feature-item">
|
||||
<div class="feature-item-icon">📸</div>
|
||||
<div class="feature-item-body">
|
||||
<h4>Configuration Snapshots</h4>
|
||||
<p>Regular, automated snapshots of your entire M365 configuration stored as human-readable JSON files in Git. Coverage includes Conditional Access, Intune, Entra ID roles, PIM policies, authentication methods, cross-tenant access, identity protection policies, and more.</p>
|
||||
</div>
|
||||
</div>
|
||||
<div class="feature-item">
|
||||
<div class="feature-item-icon">🔀</div>
|
||||
<div class="feature-item-body">
|
||||
<h4>Drift Detection & Pull Requests</h4>
|
||||
<p>When configuration changes between snapshots, ASTRAL opens a Pull Request in Azure DevOps showing exactly what changed in a human-readable diff. If Azure OpenAI is configured, it adds a plain-English narrative explaining the change and its implications.</p>
|
||||
</div>
|
||||
</div>
|
||||
<div class="feature-item">
|
||||
<div class="feature-item-icon">✅</div>
|
||||
<div class="feature-item-body">
|
||||
<h4>Reviewable Approval Trail</h4>
|
||||
<p>PRs can be reviewed, commented on, and approved or rejected by the team. This is lightweight change management built on infrastructure you already use. Every decision is timestamped and reviewer-attributed — audit evidence ready without extra tooling.</p>
|
||||
</div>
|
||||
</div>
|
||||
<div class="feature-item">
|
||||
<div class="feature-item-icon">↩️</div>
|
||||
<div class="feature-item-body">
|
||||
<h4>Baseline Restore</h4>
|
||||
<p>If a drift PR is rejected, a pipeline can automatically restore the previous configuration. The Git baseline is the source of truth. "What do we restore to?" becomes a deterministic operation, not an emergency reconstruction exercise.</p>
|
||||
</div>
|
||||
</div>
|
||||
<div class="feature-item">
|
||||
<div class="feature-item-icon">🤖</div>
|
||||
<div class="feature-item-body">
|
||||
<h4>MCP Server</h4>
|
||||
<p>ASTRAL exposes its snapshot data via the Model Context Protocol, enabling AI assistants to query configuration history, compare policy states, and surface drift in natural language. AURORA uses this interface for cross-tool diagnostics.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
## Coverage
|
||||
|
||||
ASTRAL currently covers the following M365 workloads:
|
||||
|
||||
- **Entra ID** — Conditional Access policies, authentication methods, authorization policy, security defaults, cross-tenant access, external collaboration settings
|
||||
- **Entra Roles** — Permanent and PIM-eligible role assignments, PIM governance policies, privileged group membership with delta tracking
|
||||
- **Intune** — Compliance policies, device configuration profiles, enrollment restrictions
|
||||
- **Identity Protection** — Sign-in risk policy, user risk policy, MFA registration policy
|
||||
- **Reports** — Nightly generated Intune and Entra documentation, committed to the repository automatically
|
||||
|
||||
Phase 2 (planned): UTCM API integration covering Exchange Online, Teams, Defender, and Purview — 249 additional resource types via a single API surface.
|
||||
|
||||
## Bring Your Own AI
|
||||
|
||||
AI PR narratives use any OpenAI-compatible endpoint — Azure OpenAI, Ollama (local), Groq, or others. ASTRAL is fully functional without AI. The narratives are an enhancement, not a dependency.
|
||||
|
||||
## What This Gives You Strategically
|
||||
|
||||
**Configuration decoupled from Microsoft's control plane.** Once M365 configuration lives in Git, it is data you own. The history, the review workflow, the approval trail — none of it depends on Microsoft's tools. Gitea, GitHub, GitLab, or a self-hosted instance are all valid targets.
|
||||
|
||||
**Disaster recovery baseline.** The Git history is not just evidence — it is a rebuild blueprint. If a CA policy is catastrophically misconfigured or bulk changes are made by a compromised account, the previous known-good state is in Git and the restore pipeline applies it deterministically.
|
||||
|
||||
**Compliance evidence.** ASTRAL's Git trail maps directly onto NIS2 Article 21 (configuration management), DORA Article 11 (ICT change management), GDPR Article 5(2) (accountability principle), and ISO 27001 A.8.9 (configuration management). External auditors receive timestamped, reviewer-attributed evidence — not manual screenshots.
|
||||
|
||||
**Institutional knowledge capture.** Every PR comment, AI narrative, and approval decision is a searchable, permanent record of why a configuration choice was made. Teams without this lose institutional knowledge every time personnel changes.
|
||||
|
||||
## Deployment Model
|
||||
|
||||
ASTRAL runs entirely within your Azure DevOps organisation and Microsoft tenant:
|
||||
- One ADO project
|
||||
- Three pipelines (backup, review sync, restore)
|
||||
- One Entra app registration (read-only Graph permissions + targeted Intune read)
|
||||
- One variable group
|
||||
|
||||
No data leaves your environment. No CQRE infrastructure is involved. No ongoing licensing.
|
||||
|
||||
<div class="cta-strip">
|
||||
<h2>Ready to deploy ASTRAL?</h2>
|
||||
<p>Full deployment guide, bootstrap scripts, and pipeline YAML are on GitHub.</p>
|
||||
<div class="actions">
|
||||
<a href="https://github.com/cqrenet/astral" class="btn btn-primary" target="_blank" rel="noopener">View on GitHub</a>
|
||||
<a href="/products/aurora/" class="btn btn-outline">Explore AURORA →</a>
|
||||
</div>
|
||||
</div>
|
||||
@@ -0,0 +1,105 @@
|
||||
---
|
||||
title: "AURORA"
|
||||
description: "Audit, Unified Review, Observability & Remediation for Administrators. The paid AI-assisted operations layer that connects PULSAR and ASTRAL."
|
||||
eyebrow: "Commercial"
|
||||
lead: "AURORA sits in front of PULSAR and ASTRAL, connecting them into a single unified interface with AI-assisted cross-tool diagnostics, multi-scope orchestration, and enriched SIEM forwarding."
|
||||
icon: "🌅"
|
||||
badge:
|
||||
text: "Commercial"
|
||||
color: "orange"
|
||||
actions:
|
||||
- label: "Contact Us"
|
||||
url: "/about/#contact"
|
||||
primary: true
|
||||
- label: "← Back to Products"
|
||||
url: "/products/"
|
||||
---
|
||||
|
||||
## What AURORA Does
|
||||
|
||||
PULSAR captures the signal. ASTRAL holds the baseline. AURORA makes sense of both.
|
||||
|
||||
AURORA is a unified operations platform that connects to PULSAR and ASTRAL via their MCP servers, exposes a single unified interface to your AI tool, and provides cross-tool diagnostics that neither product can answer alone. **AURORA stores no data** — all data lives in PULSAR (MongoDB) and ASTRAL (Git). AURORA is purely a query, orchestration, and intelligence layer.
|
||||
|
||||
## Cross-Tool Diagnostic Tools
|
||||
|
||||
<div class="feature-list">
|
||||
<div class="feature-item">
|
||||
<div class="feature-item-icon">🔗</div>
|
||||
<div class="feature-item-body">
|
||||
<h4>Correlate Drift with Audit</h4>
|
||||
<p><em>Who in the portal triggered this drift commit?</em> — Gets recent Git commits from ASTRAL and PULSAR audit events in the same window, matches by timestamp and resource name. Directly satisfies DORA Article 11's requirement to demonstrate who changed what and why.</p>
|
||||
</div>
|
||||
</div>
|
||||
<div class="feature-item">
|
||||
<div class="feature-item-icon">🏥</div>
|
||||
<div class="feature-item-body">
|
||||
<h4>Diagnose Policy Errors</h4>
|
||||
<p><em>Why is this compliance policy erroring on some devices?</em> — Fetches policy config and assignments from ASTRAL, queries PULSAR for audit events touching that policy, synthesises a narrative answer. Turns a 2-hour investigation into 2 minutes.</p>
|
||||
</div>
|
||||
</div>
|
||||
<div class="feature-item">
|
||||
<div class="feature-item-icon">📱</div>
|
||||
<div class="feature-item-body">
|
||||
<h4>Explain Device Compliance</h4>
|
||||
<p><em>Why did this device suddenly become non-compliant?</em> — Pulls assigned policies from ASTRAL, fetches all PULSAR audit events for the device, synthesises a compliance timeline with AI-generated narrative.</p>
|
||||
</div>
|
||||
</div>
|
||||
<div class="feature-item">
|
||||
<div class="feature-item-icon">📊</div>
|
||||
<div class="feature-item-body">
|
||||
<h4>Tenant Security Summary</h4>
|
||||
<p><em>What happened in my tenant this week that I should know about?</em> — Combines ASTRAL open drift PRs with PULSAR event summary, generates an executive briefing. Weekly security digest without manual work.</p>
|
||||
</div>
|
||||
</div>
|
||||
<div class="feature-item">
|
||||
<div class="feature-item-icon">⚖️</div>
|
||||
<div class="feature-item-body">
|
||||
<h4>Compare Scopes</h4>
|
||||
<p><em>What's different between my production and development Conditional Access policies?</em> — Compares configuration state across AURORA's configured named scopes (production, staging, test tenants).</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
## Multi-Scope Orchestration
|
||||
|
||||
AURORA connects to multiple named ASTRAL instances within one organisation — production read-only alongside development read-write, with direct configuration comparison between scopes. This is a distinct capability from what ASTRAL or PULSAR can deliver independently.
|
||||
|
||||
## Enriched SIEM Forwarding
|
||||
|
||||
PULSAR forwards raw audit events to a SIEM. AURORA forwards *enriched* events — audit events correlated with ASTRAL configuration state at the time of the event. Each forwarded event carries:
|
||||
|
||||
- The current ASTRAL snapshot state of the affected resource
|
||||
- Whether a matching Git commit exists in ASTRAL within the same time window
|
||||
- Risk signals: whether the affected policy is tagged high-sensitivity, whether the actor holds a privileged role
|
||||
|
||||
This produces qualitatively higher-quality SIEM data than any direct Microsoft integration delivers.
|
||||
|
||||
## Pricing
|
||||
|
||||
AURORA is priced per-tenant, not per-user. Self-hosted customers bring their own Azure OpenAI endpoint (BYOAI). Hosted includes fully managed infrastructure and AI.
|
||||
|
||||
| Tier | Self-Hosted | Hosted |
|
||||
|------|-------------|--------|
|
||||
| Single tenant | €259/mo (€2,590/yr) | €389/mo (€3,890/yr) |
|
||||
| Up to 5 scopes | €429/mo (€4,290/yr) | €599/mo (€5,990/yr) |
|
||||
| Enterprise | Custom | Custom |
|
||||
|
||||
Annual billing includes ~15% discount.
|
||||
|
||||
**Support** is included with all AURORA tiers (email, 2-business-day SLA). Enterprise includes a dedicated Slack channel and same-day response.
|
||||
|
||||
## EU Compliance Notes
|
||||
|
||||
- **Self-hosted**: runs entirely on your Azure infrastructure, EU data residency preserved, no data processing agreement required with CQRE for the core product.
|
||||
- **Hosted**: CQRE manages the stack. EU data is stored and processed within the EU/EEA. A GDPR data processing agreement (DPA) is required before onboarding.
|
||||
- **BYOAI self-hosted**: pointing `LLM_BASE_URL` at your own Azure OpenAI EU endpoint ensures no tenant data leaves your region.
|
||||
|
||||
<div class="cta-strip">
|
||||
<h2>Interested in AURORA?</h2>
|
||||
<p>AURORA is in active development. Contact us to discuss your requirements, join the early access program, or get help sizing the right tier.</p>
|
||||
<div class="actions">
|
||||
<a href="/about/#contact" class="btn btn-primary">Get in Touch</a>
|
||||
<a href="/products/pulsar/" class="btn btn-outline">Start with PULSAR (Free)</a>
|
||||
</div>
|
||||
</div>
|
||||
@@ -0,0 +1,97 @@
|
||||
---
|
||||
title: "PULSAR"
|
||||
description: "Platform for Unified Log Search, Alerting & Review. Free, open-source M365 audit log ingestion with indefinite retention and AI-ready query interface."
|
||||
eyebrow: "Free & Open Source"
|
||||
lead: "PULSAR continuously ingests Microsoft 365 admin audit events and stores them in a database you own. Search, alert, forward to your SIEM, and query via AI — with no retention expiry."
|
||||
icon: "📡"
|
||||
badge:
|
||||
text: "Free & Open Source"
|
||||
color: "green"
|
||||
actions:
|
||||
- label: "View on GitHub"
|
||||
url: "https://github.com/cqrenet/pulsar"
|
||||
external: true
|
||||
primary: true
|
||||
- label: "Learn about ASTRAL →"
|
||||
url: "/products/astral/"
|
||||
---
|
||||
|
||||
## The Problem PULSAR Solves
|
||||
|
||||
Microsoft 365 E3 provides 90 days of audit log retention, accessible only through the Microsoft Purview portal. Events older than 90 days are permanently gone. There is no alerting on admin actions, no forwarding, and no integration surface beyond Microsoft's API.
|
||||
|
||||
PULSAR solves this entirely. Once deployed, audit events are continuously pulled and stored in your own MongoDB instance. Retention is indefinite. The data is yours.
|
||||
|
||||
## What PULSAR Does
|
||||
|
||||
<div class="feature-list">
|
||||
<div class="feature-item">
|
||||
<div class="feature-item-icon">📥</div>
|
||||
<div class="feature-item-body">
|
||||
<h4>Continuous Ingestion</h4>
|
||||
<p>Polls Microsoft audit APIs on a configurable interval and stores all events incrementally. Watermarks ensure nothing is missed. Sources: Entra directory audit logs, Intune audit logs, Exchange / SharePoint / Teams via Office 365 Management Activity API.</p>
|
||||
</div>
|
||||
</div>
|
||||
<div class="feature-item">
|
||||
<div class="feature-item-icon">🔍</div>
|
||||
<div class="feature-item-body">
|
||||
<h4>Search & Filter UI</h4>
|
||||
<p>A web interface for searching events by workload, operation type, user, resource, and time range. Designed for the kind of investigation that is otherwise done by manually clicking through the Purview portal.</p>
|
||||
</div>
|
||||
</div>
|
||||
<div class="feature-item">
|
||||
<div class="feature-item-icon">🔔</div>
|
||||
<div class="feature-item-body">
|
||||
<h4>Alerting</h4>
|
||||
<p>Rules-based alerting with webhook delivery. Trigger on new permanent Global Admin assignments, CA policy changes outside business hours, guest invitations in sensitive groups, and more.</p>
|
||||
</div>
|
||||
</div>
|
||||
<div class="feature-item">
|
||||
<div class="feature-item-icon">📤</div>
|
||||
<div class="feature-item-body">
|
||||
<h4>SIEM Forwarding</h4>
|
||||
<p>Forward audit events to an external SIEM. Events are normalised and enriched before forwarding — higher-quality data than a direct Microsoft API integration delivers.</p>
|
||||
</div>
|
||||
</div>
|
||||
<div class="feature-item">
|
||||
<div class="feature-item-icon">🤖</div>
|
||||
<div class="feature-item-body">
|
||||
<h4>MCP Server</h4>
|
||||
<p>PULSAR exposes <code>search_events</code>, <code>get_event</code>, and <code>get_summary</code> via the Model Context Protocol, so an AI assistant (Claude, Copilot, or any MCP-compatible client) can query your audit log in natural language.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
## Why This Matters
|
||||
|
||||
**For compliance (NIS2 / GDPR Article 33):** The 90-day M365 portal window does not satisfy requirements for ongoing, reliable audit log retention. PULSAR's indefinite retention, independently controlled, satisfies supervisory authority expectations and enables the 72-hour breach notification window under GDPR.
|
||||
|
||||
**For incident investigation:** Without PULSAR, a breach investigation depends on whatever events are still within the portal window. With PULSAR, the full history is always available — even if detection was slow.
|
||||
|
||||
**For governance evidence:** Every admin action, searchable and permanent. Useful for internal reporting, audit preparation, and the team's own situational awareness.
|
||||
|
||||
## Architecture
|
||||
|
||||
PULSAR runs as a container on Azure Container Apps alongside ASTRAL. The recommended database backend for production is **Azure Cosmos DB for MongoDB (vCore)** — fully managed, wire-compatible, and available within your Azure region (EU data residency preserved).
|
||||
|
||||
Secrets are stored in Azure Key Vault and surfaced via managed identity — no credentials in environment variables.
|
||||
|
||||
## PULSAR + ASTRAL Together
|
||||
|
||||
| | PULSAR | ASTRAL |
|
||||
|---|---|---|
|
||||
| **Question answered** | What happened? | What does the config look like, and what changed? |
|
||||
| **Data stored** | Audit events | Configuration snapshots |
|
||||
| **Storage** | MongoDB | Git repository |
|
||||
| **History** | From deployment date | From deployment date |
|
||||
|
||||
Deployed together, they give the complete picture: every admin action in the audit log, and every configuration state at any point in time.
|
||||
|
||||
<div class="cta-strip">
|
||||
<h2>Ready to deploy PULSAR?</h2>
|
||||
<p>Full deployment documentation and Docker images are available on GitHub.</p>
|
||||
<div class="actions">
|
||||
<a href="https://github.com/cqrenet/pulsar" class="btn btn-primary" target="_blank" rel="noopener">View on GitHub</a>
|
||||
<a href="/products/astral/" class="btn btn-outline">Explore ASTRAL →</a>
|
||||
</div>
|
||||
</div>
|
||||
Reference in New Issue
Block a user