The firewall manager, the mail gateway, the identity appliance, the backup plugin, the remote-access console — the tools you bought to protect and manage the estate are assets too, and almost nobody puts them on the inventory. Between September 1 and 18, 2026, CISA added 28 CVEs to its Known Exploited Vulnerabilities catalog: twenty drew a three-day remediation deadline and eight drew fourteen. All ten security and remote-management products in that window landed in the three-day pile. This is the afternoon that lists your stack, tags what each tool can reach, cross-checks it against a free public catalog by product name, and puts a named human on every row.What you get. One file: the whole kit as a single portable Windows app (.exe) with its own icon — the guidance, the worksheets, the print layout, the exports and the license, all inside it. Double-click to open; nothing to unzip, nothing to install. Windows 10/11, 64-bit.The worksheets export to CSV and to an Excel workbook with the dropdowns already set up from inside the kit, so your data is never trapped in our format.How it runs. No install, no account, no license key, no internet connection. What you type saves to the app's own local storage on your own machine. The app is built with no network permission at all — no analytics, no trackers, nothing that can send anything anywhere; the few links inside the kit open in your own browser. It is unsigned: Windows SmartScreen warns on first launch; verify the SHA-256 below against your download, then choose Run anyway. Print or export to keep a durable copy.Built for MSPs and IT teams whose RMM, EDR and backup consoles appear on no asset inventory vCISOs and consultants who need a dated, owned list of the tools that hold privilege over a client estate Anyone who patches servers in days and security appliances in quarters and has never written that down Not built for A vulnerability scanner, a patch-deployment tool, or an attack-surface-management product A compliance verdict, and not a claim that CISA directives apply to private organizations A severity-scoring exercise — the catalog it uses publishes no CVSS score at all License. Free to use inside your organization and with your clients, including in paid engagements. You may not resell it or republish it as your own. The full license is inside the kit, under About this kit.This kit supports compliance documentation and audit-preparation workflows. It is a practical starting point — review and adapt it for your organization. It is not legal, compliance, or audit advice, and using it does not establish or certify any compliance or security outcome. The Security Gator LLC is not affiliated with or endorsed by NIST or any other standards body.SHA-256 (Gatorbyte-014-security-stack-kit.exe)2dd53ab06089040ed6289383e76a315e14221358ca98e1223aa053a1ee2b03b0