FIX ID
TITAN-FRG-FIX-0001
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
CRITICAL
Public Blob Access
Disabled public blob access
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titanlabdata4336 |
| REGION | East US |
| CATEGORY | Public Blob Access |
■ SECTION 2 · ACTION TAKEN
Disabled public blob access
■ SECTION 3 · REGULATORY CONTEXT
HIPAA 164.312(a)(1) + PCI DSS 1.2.1 + CIS Azure 3.1
■ SECTION 4 · BEFORE STATE
{
"allowBlobPublicAccess": true
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"allowBlobPublicAccess": false
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az storage account update -n titanlabdata4336 -g titan-lab-20260412 --allow-blob-public-access false
ROLLBACK
az storage account update -n titanlabdata4336 -g titan-lab-20260412 --allow-blob-public-access true
FIX DURATION
920 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0001
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0002
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
HIGH
Weak TLS
■ SECTION 3 · REGULATORY CONTEXT
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titanlabdata4336 |
| REGION | East US |
| CATEGORY | Weak TLS |
■ SECTION 2 · ACTION TAKEN
Enforced HTTPS-only
■ SECTION 3 · REGULATORY CONTEXT
HIPAA 164.312(e)(1) + PCI DSS 4.1
■ SECTION 4 · BEFORE STATE
{
"supportsHttpsTrafficOnly": false
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"supportsHttpsTrafficOnly": true
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az storage account update -n titanlabdata4336 -g titan-lab-20260412 --https-only true
ROLLBACK
az storage account update -n titanlabdata4336 -g titan-lab-20260412 --https-only false
FIX DURATION
1040 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0002
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0003
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
HIGH
Weak TLS
■ SECTION 3 · REGULATORY CONTEXT
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titanlabdata4336 |
| REGION | East US |
| CATEGORY | Weak TLS |
■ SECTION 2 · ACTION TAKEN
Set TLS 1.2 minimum
■ SECTION 3 · REGULATORY CONTEXT
HIPAA 164.312(e)(1) + PCI DSS 4.1 + NIST SC-8
■ SECTION 4 · BEFORE STATE
{
"minimumTlsVersion": "TLS1_0"
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"minimumTlsVersion": "TLS1_2"
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az storage account update -n titanlabdata4336 -g titan-lab-20260412 --min-tls-version TLS1_2
ROLLBACK
az storage account update -n titanlabdata4336 -g titan-lab-20260412 --min-tls-version TLS1_0
FIX DURATION
1160 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0003
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0004
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
CRITICAL
Public Blob Access
Disabled public blob access
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titanlabphi4336 |
| REGION | East US |
| CATEGORY | Public Blob Access |
■ SECTION 2 · ACTION TAKEN
Disabled public blob access
■ SECTION 3 · REGULATORY CONTEXT
HIPAA 164.312(a)(1) + CIS Azure 3.1
■ SECTION 4 · BEFORE STATE
{
"allowBlobPublicAccess": true
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"allowBlobPublicAccess": false
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az storage account update -n titanlabphi4336 -g titan-lab-20260412 --allow-blob-public-access false
ROLLBACK
az storage account update -n titanlabphi4336 -g titan-lab-20260412 --allow-blob-public-access true
FIX DURATION
1280 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0004
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0005
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
HIGH
Weak TLS
■ SECTION 3 · REGULATORY CONTEXT
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titanlabphi4336 |
| REGION | East US |
| CATEGORY | Weak TLS |
■ SECTION 2 · ACTION TAKEN
Enforced HTTPS-only
■ SECTION 3 · REGULATORY CONTEXT
HIPAA 164.312(e)(1) + PCI DSS 4.1
■ SECTION 4 · BEFORE STATE
{
"supportsHttpsTrafficOnly": false
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"supportsHttpsTrafficOnly": true
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az storage account update -n titanlabphi4336 -g titan-lab-20260412 --https-only true
ROLLBACK
az storage account update -n titanlabphi4336 -g titan-lab-20260412 --https-only false
FIX DURATION
1400 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0005
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0006
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
HIGH
Weak TLS
■ SECTION 3 · REGULATORY CONTEXT
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titanlabphi4336 |
| REGION | East US |
| CATEGORY | Weak TLS |
■ SECTION 2 · ACTION TAKEN
Set TLS 1.2 minimum
■ SECTION 3 · REGULATORY CONTEXT
HIPAA 164.312(e)(1) + NIST SC-8
■ SECTION 4 · BEFORE STATE
{
"minimumTlsVersion": "TLS1_0"
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"minimumTlsVersion": "TLS1_2"
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az storage account update -n titanlabphi4336 -g titan-lab-20260412 --min-tls-version TLS1_2
ROLLBACK
az storage account update -n titanlabphi4336 -g titan-lab-20260412 --min-tls-version TLS1_0
FIX DURATION
1520 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0006
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0007
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
CRITICAL
Open SQL Firewall
Deleted open SQL firewall rule (0.0.0.0-255.255.255.255)
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | sql-titan-lab-4336 |
| REGION | East US |
| CATEGORY | Open SQL Firewall |
■ SECTION 2 · ACTION TAKEN
Deleted open SQL firewall rule (0.0.0.0-255.255.255.255)
■ SECTION 3 · REGULATORY CONTEXT
HIPAA 164.312(a)(1) + PCI DSS 1.3.1
■ SECTION 4 · BEFORE STATE
{
"rule": "AllowAllIPs",
"startIp": "0.0.0.0",
"endIp": "255.255.255.255"
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"rule": "removed"
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az sql server firewall-rule delete -s sql-titan-lab-4336 -g titan-lab-20260412 -n AllowAllIPs
ROLLBACK
az sql server firewall-rule create -s sql-titan-lab-4336 -g titan-lab-20260412 -n AllowAllIPs --start-ip 0.0.0.0 --end-ip 255.255.255.255
FIX DURATION
1640 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0007
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0008
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
HIGH
App Service HTTPS
Enforced HTTPS-only on App Service
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titan-lab-admin-4336 |
| REGION | East US |
| CATEGORY | App Service HTTPS |
■ SECTION 2 · ACTION TAKEN
Enforced HTTPS-only on App Service
■ SECTION 3 · REGULATORY CONTEXT
HIPAA 164.312(e)(1) + PCI DSS 4.1
■ SECTION 4 · BEFORE STATE
{
"httpsOnly": false
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"httpsOnly": true
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az webapp update -n titan-lab-admin-4336 -g titan-lab-20260412 --https-only true
ROLLBACK
az webapp update -n titan-lab-admin-4336 -g titan-lab-20260412 --https-only false
FIX DURATION
1760 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0008
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0009
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
HIGH
App Service HTTPS
Enforced HTTPS-only on App Service
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titan-lab-portal-4336 |
| REGION | East US |
| CATEGORY | App Service HTTPS |
■ SECTION 2 · ACTION TAKEN
Enforced HTTPS-only on App Service
■ SECTION 3 · REGULATORY CONTEXT
HIPAA 164.312(e)(1) + PCI DSS 4.1
■ SECTION 4 · BEFORE STATE
{
"httpsOnly": false
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"httpsOnly": true
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az webapp update -n titan-lab-portal-4336 -g titan-lab-20260412 --https-only true
ROLLBACK
az webapp update -n titan-lab-portal-4336 -g titan-lab-20260412 --https-only false
FIX DURATION
1880 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0009
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0010
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
HIGH
Function CORS Wildcard
Removed CORS wildcard (*) on Function App
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titanlabfunc4336 |
| REGION | East US |
| CATEGORY | Function CORS Wildcard |
■ SECTION 2 · ACTION TAKEN
Removed CORS wildcard (*) on Function App
■ SECTION 3 · REGULATORY CONTEXT
PCI DSS 6.5.8 + OWASP Broken Access Control
■ SECTION 4 · BEFORE STATE
{
"cors.allowedOrigins": [
"*"
]
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"cors.allowedOrigins": [
"https://portal.titan-lab.com"
]
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az functionapp cors remove -n titanlabfunc4336 -g titan-lab-20260412 --allowed-origins '*'
ROLLBACK
az functionapp cors add -n titanlabfunc4336 -g titan-lab-20260412 --allowed-origins '*'
FIX DURATION
2000 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0010
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0011
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
MEDIUM
FTP Enabled
Disabled FTP on Function App
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titanlabfunc4336 |
| REGION | East US |
| CATEGORY | FTP Enabled |
■ SECTION 2 · ACTION TAKEN
Disabled FTP on Function App
■ SECTION 3 · REGULATORY CONTEXT
PCI DSS 4.1 + NIST SC-8
■ SECTION 4 · BEFORE STATE
{
"ftpsState": "AllAllowed"
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"ftpsState": "Disabled"
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az functionapp config set -n titanlabfunc4336 -g titan-lab-20260412 --ftps-state Disabled
ROLLBACK
az functionapp config set -n titanlabfunc4336 -g titan-lab-20260412 --ftps-state AllAllowed
FIX DURATION
2120 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0011
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0012
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
HIGH
Weak TLS
Set TLS 1.2 minimum on Function App
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titanlabfunc4336 |
| REGION | East US |
| CATEGORY | Weak TLS |
■ SECTION 2 · ACTION TAKEN
Set TLS 1.2 minimum on Function App
■ SECTION 3 · REGULATORY CONTEXT
HIPAA 164.312(e)(1) + PCI DSS 4.1
■ SECTION 4 · BEFORE STATE
{
"minTlsVersion": "1.0"
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"minTlsVersion": "1.2"
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az functionapp config set -n titanlabfunc4336 -g titan-lab-20260412 --min-tls-version 1.2
ROLLBACK
az functionapp config set -n titanlabfunc4336 -g titan-lab-20260412 --min-tls-version 1.0
FIX DURATION
2240 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0012
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0013
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
HIGH
Redis Non-SSL
Disabled non-SSL port on Redis Cache
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titan-lab-redis-4336 |
| REGION | East US |
| CATEGORY | Redis Non-SSL |
■ SECTION 2 · ACTION TAKEN
Disabled non-SSL port on Redis Cache
■ SECTION 3 · REGULATORY CONTEXT
PCI DSS 4.1 + HIPAA 164.312(e)(1)
■ SECTION 4 · BEFORE STATE
{
"enableNonSslPort": true
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"enableNonSslPort": false
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az redis update -n titan-lab-redis-4336 -g titan-lab-20260412 --set enableNonSslPort=false
ROLLBACK
az redis update -n titan-lab-redis-4336 -g titan-lab-20260412 --set enableNonSslPort=true
FIX DURATION
2360 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0013
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0014
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
MEDIUM
Event Hub Network
Set Event Hub network rules to Deny default
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titan-lab-eh-4336 |
| REGION | East US |
| CATEGORY | Event Hub Network |
■ SECTION 2 · ACTION TAKEN
Set Event Hub network rules to Deny default
■ SECTION 3 · REGULATORY CONTEXT
HIPAA 164.312(a)(1) + NIST AC-3
■ SECTION 4 · BEFORE STATE
{
"defaultAction": "Allow"
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"defaultAction": "Deny"
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az eventhubs namespace network-rule update -n titan-lab-eh-4336 -g titan-lab-20260412 --default-action Deny
ROLLBACK
az eventhubs namespace network-rule update -n titan-lab-eh-4336 -g titan-lab-20260412 --default-action Allow
FIX DURATION
2480 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0014
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0015
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
MEDIUM
Service Bus Network
Set Service Bus network rules to Deny default
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titan-lab-sb-4336 |
| REGION | East US |
| CATEGORY | Service Bus Network |
■ SECTION 2 · ACTION TAKEN
Set Service Bus network rules to Deny default
■ SECTION 3 · REGULATORY CONTEXT
HIPAA 164.312(a)(1) + NIST AC-3
■ SECTION 4 · BEFORE STATE
{
"defaultAction": "Allow"
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"defaultAction": "Deny"
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az servicebus namespace network-rule-set update -n titan-lab-sb-4336 -g titan-lab-20260412 --default-action Deny
ROLLBACK
az servicebus namespace network-rule-set update -n titan-lab-sb-4336 -g titan-lab-20260412 --default-action Allow
FIX DURATION
2600 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0015
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0016
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
HIGH
NSG Open Port
Removed NSG Elasticsearch 9200 rule
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titan-db-nsg |
| REGION | East US |
| CATEGORY | NSG Open Port |
■ SECTION 2 · ACTION TAKEN
Removed NSG Elasticsearch 9200 rule
■ SECTION 3 · REGULATORY CONTEXT
PCI DSS 1.3.1 + CIS Azure 6.3
■ SECTION 4 · BEFORE STATE
{
"port": 9200,
"source": "Internet",
"destination": "VirtualNetwork"
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"rule": "removed"
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az network nsg rule delete -g titan-lab-20260412 --nsg-name titan-db-nsg -n AllowElasticsearch9200
ROLLBACK
az network nsg rule create -g titan-lab-20260412 --nsg-name titan-db-nsg -n AllowElasticsearch9200 --priority 100 --source-address-prefixes Internet --destination-port-ranges 9200
FIX DURATION
2720 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0016
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0017
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
CRITICAL
Public Blob Access
Disabled public blob access
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titanlabnosftdl4336 |
| REGION | East US |
| CATEGORY | Public Blob Access |
■ SECTION 2 · ACTION TAKEN
Disabled public blob access
■ SECTION 3 · REGULATORY CONTEXT
HIPAA 164.312(a)(1) + CIS Azure 3.1
■ SECTION 4 · BEFORE STATE
{
"allowBlobPublicAccess": true
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"allowBlobPublicAccess": false
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az storage account update -n titanlabnosftdl4336 -g titan-lab-20260412 --allow-blob-public-access false
ROLLBACK
az storage account update -n titanlabnosftdl4336 -g titan-lab-20260412 --allow-blob-public-access true
FIX DURATION
2840 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0017
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0018
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
HIGH
Weak TLS
■ SECTION 3 · REGULATORY CONTEXT
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titanlabnosftdl4336 |
| REGION | East US |
| CATEGORY | Weak TLS |
■ SECTION 2 · ACTION TAKEN
Set TLS 1.2 minimum
■ SECTION 3 · REGULATORY CONTEXT
HIPAA 164.312(e)(1) + NIST SC-8
■ SECTION 4 · BEFORE STATE
{
"minimumTlsVersion": "TLS1_0"
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"minimumTlsVersion": "TLS1_2"
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az storage account update -n titanlabnosftdl4336 -g titan-lab-20260412 --min-tls-version TLS1_2
ROLLBACK
az storage account update -n titanlabnosftdl4336 -g titan-lab-20260412 --min-tls-version TLS1_0
FIX DURATION
2960 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0018
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0019
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
HIGH
AKS Azure AD
Enabled Azure AD integration on AKS
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titan-lab-aks-4336 |
| REGION | East US |
| CATEGORY | AKS Azure AD |
■ SECTION 2 · ACTION TAKEN
Enabled Azure AD integration on AKS
■ SECTION 3 · REGULATORY CONTEXT
HIPAA 164.308(a)(4) + NIST IA-2
■ SECTION 4 · BEFORE STATE
{
"aadProfile": null
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"aadProfile": {
"managed": true,
"enableAzureRBAC": true
}
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az aks update -n titan-lab-aks-4336 -g titan-lab-20260412 --enable-aad --enable-azure-rbac
ROLLBACK
(Azure AD integration is one-way once enabled — cluster recreation required to revert)
FIX DURATION
3080 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0019
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0020
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
MEDIUM
AKS Network Policy
Enabled Calico network policy on AKS
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titan-lab-aks-4336 |
| REGION | East US |
| CATEGORY | AKS Network Policy |
■ SECTION 2 · ACTION TAKEN
Enabled Calico network policy on AKS
■ SECTION 3 · REGULATORY CONTEXT
NIST SC-7 + CIS AKS 5.3.2
■ SECTION 4 · BEFORE STATE
{
"networkPolicy": "none"
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"networkPolicy": "calico"
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az aks update -n titan-lab-aks-4336 -g titan-lab-20260412 --network-policy calico
ROLLBACK
(Network policy change requires cluster recreation to revert)
FIX DURATION
3200 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0020
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0021
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
HIGH
AKS API Server
Restricted AKS API server to authorized IP ranges
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titan-lab-aks-4336 |
| REGION | East US |
| CATEGORY | AKS API Server |
■ SECTION 2 · ACTION TAKEN
Restricted AKS API server to authorized IP ranges
■ SECTION 3 · REGULATORY CONTEXT
HIPAA 164.312(a)(1) + PCI DSS 1.3.1
■ SECTION 4 · BEFORE STATE
{
"authorizedIpRanges": [
"0.0.0.0/0"
]
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"authorizedIpRanges": [
"10.0.0.0/8",
"40.112.x.x/32"
]
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az aks update -n titan-lab-aks-4336 -g titan-lab-20260412 --api-server-authorized-ip-ranges 10.0.0.0/8,40.112.x.x/32
ROLLBACK
az aks update -n titan-lab-aks-4336 -g titan-lab-20260412 --api-server-authorized-ip-ranges 0.0.0.0/0
FIX DURATION
3320 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0021
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0022
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
MEDIUM
LB SKU Upgrade
Upgraded Load Balancer to Standard SKU
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titan-lab-lb-4336 |
| REGION | East US |
| CATEGORY | LB SKU Upgrade |
■ SECTION 2 · ACTION TAKEN
Upgraded Load Balancer to Standard SKU
■ SECTION 3 · REGULATORY CONTEXT
NIST CP-10 + Azure Well-Architected Framework
■ SECTION 4 · BEFORE STATE
{
"sku": "Basic"
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"sku": "Standard"
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az network lb update -n titan-lab-lb-4336 -g titan-lab-20260412 --sku Standard
ROLLBACK
(Basic SKU deprecated Sep 2025 — downgrade not supported)
FIX DURATION
3440 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0022
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0023
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
HIGH
Key Vault Purge
Enabled Key Vault purge protection
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titan-lab-kv-4336 |
| REGION | East US |
| CATEGORY | Key Vault Purge |
■ SECTION 2 · ACTION TAKEN
Enabled Key Vault purge protection
■ SECTION 3 · REGULATORY CONTEXT
HIPAA 164.308(a)(7) + SOC 2 CC6.1
■ SECTION 4 · BEFORE STATE
{
"enablePurgeProtection": false
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"enablePurgeProtection": true
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az keyvault update -n titan-lab-kv-4336 -g titan-lab-20260412 --enable-purge-protection true
ROLLBACK
(Purge protection is one-way — cannot be disabled once enabled)
FIX DURATION
3560 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0023
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0024
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
MEDIUM
ACR Admin Account
Disabled Container Registry admin account
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titanlabacr4336 |
| REGION | East US |
| CATEGORY | ACR Admin Account |
■ SECTION 2 · ACTION TAKEN
Disabled Container Registry admin account
■ SECTION 3 · REGULATORY CONTEXT
HIPAA 164.308(a)(4) + CIS Azure 9.1
■ SECTION 4 · BEFORE STATE
{
"adminUserEnabled": true
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"adminUserEnabled": false
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az acr update -n titanlabacr4336 -g titan-lab-20260412 --admin-enabled false
ROLLBACK
az acr update -n titanlabacr4336 -g titan-lab-20260412 --admin-enabled true
FIX DURATION
3680 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0024
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0025
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
LOW
Orphan Disk
Deleted unattached disk (32GB) saved Custom/mo
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titan-orphan-disk |
| REGION | East US |
| CATEGORY | Orphan Disk |
■ SECTION 2 · ACTION TAKEN
Deleted unattached disk (32GB) saved Custom/mo
■ SECTION 3 · REGULATORY CONTEXT
Cost Optimization + FinOps
■ SECTION 4 · BEFORE STATE
{
"diskSizeGB": 32,
"attachedTo": null,
"monthlyCost": 1.6
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"state": "deleted"
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az disk delete -n titan-orphan-disk -g titan-lab-20260412 --yes
ROLLBACK
(Disk deletion is irreversible — snapshot required before deletion for rollback)
FIX DURATION
3800 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0025
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0026
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
LOW
Orphan Disk
Deleted unattached disk (64GB) saved Custom/mo
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titan-orphan-disk2 |
| REGION | East US |
| CATEGORY | Orphan Disk |
■ SECTION 2 · ACTION TAKEN
Deleted unattached disk (64GB) saved Custom/mo
■ SECTION 3 · REGULATORY CONTEXT
Cost Optimization + FinOps
■ SECTION 4 · BEFORE STATE
{
"diskSizeGB": 64,
"attachedTo": null,
"monthlyCost": 3.2
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"state": "deleted"
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az disk delete -n titan-orphan-disk2 -g titan-lab-20260412 --yes
ROLLBACK
(Disk deletion is irreversible — snapshot required before deletion for rollback)
FIX DURATION
3920 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0026
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0027
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
LOW
Orphan Public IP
Deleted orphaned Public IP saved Custom/mo
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titan-orphan-pip1 |
| REGION | East US |
| CATEGORY | Orphan Public IP |
■ SECTION 2 · ACTION TAKEN
Deleted orphaned Public IP saved Custom/mo
■ SECTION 3 · REGULATORY CONTEXT
Cost Optimization + FinOps
■ SECTION 4 · BEFORE STATE
{
"attachedTo": null,
"monthlyCost": 3.65
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"state": "deleted"
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az network public-ip delete -n titan-orphan-pip1 -g titan-lab-20260412
ROLLBACK
az network public-ip create -n titan-orphan-pip1 -g titan-lab-20260412 --sku Standard
FIX DURATION
4040 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0027
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0028
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
LOW
Orphan Public IP
Deleted orphaned Public IP saved Custom/mo
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titan-orphan-pip2 |
| REGION | East US |
| CATEGORY | Orphan Public IP |
■ SECTION 2 · ACTION TAKEN
Deleted orphaned Public IP saved Custom/mo
■ SECTION 3 · REGULATORY CONTEXT
Cost Optimization + FinOps
■ SECTION 4 · BEFORE STATE
{
"attachedTo": null,
"monthlyCost": 3.65
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"state": "deleted"
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az network public-ip delete -n titan-orphan-pip2 -g titan-lab-20260412
ROLLBACK
az network public-ip create -n titan-orphan-pip2 -g titan-lab-20260412 --sku Standard
FIX DURATION
4160 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0028
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE
FIX ID
TITAN-FRG-FIX-0029
✔ FIXED + VERIFIED ON PROD
Azure
TITAN FORGE
MEDIUM
Log Retention
Extended Log Analytics retention from 30 to 90 days
CLICK TO EXPAND ▾
■ SECTION 1 · RESOURCE IDENTIFICATION
| SUBSCRIPTION | 4f29d094-1079-44c9-acb0-4d73a7a2dd34 |
| RESOURCE GROUP | titan-lab-20260412 |
| RESOURCE NAME | titan-lab-logs |
| REGION | East US |
| CATEGORY | Log Retention |
■ SECTION 2 · ACTION TAKEN
Extended Log Analytics retention from 30 to 90 days
■ SECTION 3 · REGULATORY CONTEXT
HIPAA 164.312(b) + PCI DSS 10.7 + SOC 2 CC7.2
■ SECTION 4 · BEFORE STATE
{
"retentionInDays": 30
}
■ SECTION 5 · AFTER STATE (VERIFIED)
{
"retentionInDays": 90
}
■ SECTION 6 · AUTOMATED REMEDIATION
FIX COMMAND EXECUTED
az monitor log-analytics workspace update -n titan-lab-logs -g titan-lab-20260412 --retention-time 90
ROLLBACK
az monitor log-analytics workspace update -n titan-lab-logs -g titan-lab-20260412 --retention-time 30
FIX DURATION
4280 ms · exit 0
■ SECTION 7 · AUDIT TRAIL
Fix ID: TITAN-FRG-FIX-0029
Applied by: TITAN FORGE
Approved by: operator consent
Applied at: April 12, 2026
Verified: ✔ re-scan confirms compliant
✔ SECTION 8 · VERIFIED: Re-scan at 2026-04-12 13:46 UTC confirmed this fix resolved the finding. Resource is now compliant.
■ SECTION 9 · EXCEPTION RECORDING & APPROVER
NO EXCEPTION ON RECORD — RISK IS ACTIVE