DEFAULT INSTALL
Open / listening Closed / disabled Scanned — exploitable Scanned — clean
⚠ Couldn't load the 3D engineThree.js failed to load from the CDN. Check your connection and reload.

OS Hardening: Attack Surface Reduction Simulator

A default operating-system install typically ships with far more listening services than any single deployment actually needs — legacy protocol handlers, convenience daemons, unused file-sharing services. Every one of those open ports is a separate door an attacker or a vulnerability scanner can reach. Hardening closes the doors the system's role doesn't require, without needing to know in advance which of them happen to hide an exploitable flaw. This simulator runs the identical vulnerability scanner, against the identical underlying set of vulnerabilities, against a default install and a hardened one — toggle the mode, run the scan, and watch how many exploitable entry points are actually reachable in each case.