Assessment workflow
Pentest-style workflow, graded to standard
Passive assessment runs safely on any domain. Active exploitation testing (XSS, SQLi, path traversal, SSRF) is authorized and non-destructive, and only runs on domains you have verified you own. Every finding is validated across multiple signals and scored to CVSS 3.1, CWE, and OWASP.
Scoping & Information Gathering
Normalize final origin, redirect path, public crawl boundary, and safe non-invasive test profile.
Reconnaissance & Intelligence
DNS, TLS, certificates, exposed services, robots, security.txt, email auth, IP reputation, and stack signals.
Vulnerability Assessment
Headers, cookies, CSP, CORS, SRI, mixed content, TLS downgrade, DNSSEC, DMARC, DKIM, MTA-STS, and port exposure.
Analysis & Validation
Findings are correlated across HTTP, DNS, TLS, crawler, content, and server-side recon evidence to reduce false positives.
Comprehensive Reporting
Executive score, technical checks, evidence cards, signal graph, limitations, and priority remediation actions.
Remediation Support
Fix guidance for web server headers, CDN policy, DNS/email records, exposed services, disclosure files, and retest targets.
Re-testing & Validation
Run the same deep profile again after fixes to compare scores, evidence, and remaining attack surface.
What gets checked
Live signals across nine security categories
TLS & Certificate
- Protocol grade (TLSv1.3 → TLSv1.0)
- Cipher suite: AEAD vs legacy
- Key bit strength (256–4096)
- Certificate chain depth
- Self-signed detection
- Days until expiry
- Signature algorithm (RSA/EC/PQC)
- HSTS preload eligibility
Security Headers
- Content-Security-Policy presence and eval/inline flags
- Strict-Transport-Security max-age and includeSubDomains
- X-Frame-Options (DENY / SAMEORIGIN)
- X-Content-Type-Options: nosniff
- Referrer-Policy value
- Permissions-Policy
- Cross-Origin-Opener-Policy
- Cross-Origin-Resource-Policy
Email Authentication
- SPF record presence and policy
- DKIM: scans 18 common selectors
- DKIM key type (RSA/Ed25519) and bit estimate
- DMARC policy (reject / quarantine / none)
- DMARC pct coverage
- MTA-STS mode (enforce / testing)
DNS Hardening
- CAA record count and issuers
- DNSSEC: RRSIG and DNSKEY detection
- Authenticated Data (AD) flag
- NS redundancy count
- IPv6 AAAA record presence
- Domain age proxy from SOA serial
Misconfigurations
- Server header version disclosure
- X-Powered-By header exposure
- phpinfo() output in page HTML
- Verbose stack trace in page HTML
- Clickjacking protection check
- Cache-Control directive presence
- Mixed content (HTTP refs on HTTPS pages)
Cookie Security
- Per-cookie Secure flag
- HttpOnly flag on each cookie
- SameSite attribute (Strict / Lax / None)
- Total cookie count
- Session vs persistent cookie ratio
CVE Intelligence
- Component + version fingerprinting from headers and markup
- Curated high-signal CVE knowledge base
- Live OSV.dev feed correlation (npm ecosystem)
- Real CVE ids with published CVSS scores
- Fixed-version remediation guidance
- CWE and OWASP mapping per finding
Attack Surface (passive)
- Weak cipher-suite enumeration
- Sensitive file exposure (.git, .env, backups, source maps)
- Secrets in served JavaScript bundles
- Certificate-transparency subdomain enumeration
- Dangling-CNAME subdomain-takeover detection
- DNS zone-transfer (AXFR) attempt
- WAF/CDN detection + risky HTTP methods
Active Testing (verified domains)
- Reflected XSS via safe reflection canaries (CWE-79)
- SQL injection, error-based (CWE-89)
- Path traversal / local file inclusion (CWE-22)
- Open redirect (CWE-601)
- Out-of-band blind SSRF via collaborator (CWE-918)
- JWT weakness: alg:none and empty signatures (CWE-347)
- Non-destructive payloads · Advanced plan only
Live scanner
Paste any domain to run the cyber-only scanner. Deep mode runs the full enterprise assessment and builds the security report.
Paste a URL above and hit Scan →
Cyber Security Scan · Deep scan crawls up to 16 pages