Dexfense

Know your attack surface.Build your defense.

Map your system architecture to MITRE ATT&CK® and get a prioritised, exportable security defense plan — in minutes.

MITRE ATT&CK® mapped 70+ components covered NIST CSF 2.0 Gap Analysis Exportable PDF reports
70+ Security Components
200+ ATT&CK® Techniques
NIST CSF 2.0 Aligned
Free to Use
HomeCommunity LibraryHybrid Office Network

Hybrid Office Network

Dexfense Reviewed

On-premises and cloud-connected corporate network with Active Directory, VPN, EDR/XDR, firewalls and managed Windows workstations.

EnterpriseSmall Business
14 components·By Dexfense·v1.0 · July 2026

Overview

Represents a typical corporate environment combining on-premises Windows infrastructure with cloud-connected services. Includes Active Directory domain controllers, Windows workstations and servers, a VPN gateway for remote access, network firewalls, DNS services, endpoint detection and response (EDR/XDR), mobile device management, network file servers and email. Mobile and BYOD devices connect through conditional access policies.

Intended for

IT administrators, network security engineers and MSPs managing corporate Windows environments.

Architecture Assumptions

This template assumes the following conditions. If your environment differs, use Remix to adapt the component selection.

  • Workstations are domain-joined Windows devices managed via Group Policy
  • Remote access is via a corporate-managed VPN with MFA
  • Firewall rules restrict both inbound and outbound traffic
  • EDR/XDR is deployed and actively monitored on all corporate devices
  • Backups are stored off-site and restored periodically to verify integrity

Out of Scope

  • OT/ICS environments and factory floor networks are not included
  • Assumes no datacenter co-location; not suitable for large enterprise with co-lo racks
  • Guest and visitor Wi-Fi is not separately modelled

Architecture Components14 components selected

Endpoints

Windows Clients

Windows-based end-user devices

EDR/XDR

Endpoint Detection and Response systems

Mobile Devices

Smartphones and tablets (iOS, Android)

Servers

Windows Servers

Windows-based servers

Domain Controllers

Active Directory domain controllers

Mail Servers

Email servers and services

Auth & IAM

Active Directory

Directory service for user and resource management

Multi-Factor Auth

Additional authentication verification layer

Network

VPN Services

Virtual Private Network services

Firewalls

Network and application firewalls

DNS Services

Domain name resolution services

Monitoring

Logging Systems

Centralized log collection and management

Storage

Backup Systems

Data backup and recovery systems

File Servers

Network attached storage for file sharing

Security Preview

Based on this architecture's component selection

Indicative Risk Score

43/100

25 techniques identified

3 Critical · 2 High

Top Attack Techniques

  • CriticalT1068Exploitation for Privilege Escalation
  • CriticalT1003OS Credential Dumping
  • CriticalT1486Data Encrypted for Impact
  • HighT1133External Remote Services
  • HighT1574Hijack Execution Flow

Top Recommended Controls

  • 1Implement privileged access management and monitor for suspicious directory queries
  • 2Focus on Attack Surface Reduction as your highest priority security initiative

The full defense plan — mitigations, detection methods, NIST CSF 2.0 mapping and exportable report — is available when you use this architecture in the planner.

Use This ArchitectureRemix This Architecture

Remix copies the components so you can add or remove items before generating your assessment.

Dexfense does not scan your systems. This template identifies threats and controls relevant to this architecture. Product and version validation is still required.

Back to Community Library