New here? Start with Getting started. Reviewing us for a security questionnaire? How scanning works and Data sources answer most of it, and the privacy policy covers data handling.

Start here

What we check

Checks reference

Every finding Attack Surface Scan can raise, grouped by area: the finding ID, default severity, what it means and how to fix it.

Vulnerability matching

How Attack Surface Scan matches detected software versions to CVEs and prioritises them with CISA KEV and EPSS, plus potential matches, JavaScript library advisories and end-of-life software.

Exposed services and ports

The full list of TCP ports Attack Surface Scan checks on each host, the default severity of each, how CDN edge IPs are handled, and how service greetings are read.

Asset inventory and discovery

How Attack Surface Scan builds the asset inventory: hosts, IPs, third-party dependencies and related domains, discovery sources, asset states, pruning and network context.

Certificates and certificate transparency

Attack Surface Scan's certificate monitoring: CT logs read every 15 minutes, the authorized-CA list, the unknown-certificate queue, served-certificate probes, stalled renewals and extra ports.

Email security

Attack Surface Scan's email authentication checks: SPF, DMARC, MTA-STS, TLS-RPT and CAA, plus lookalike domain monitoring and change alerts when records weaken.

Domain registration hygiene

Attack Surface Scan's registration checks: registrar transfer, update and delete locks via RDAP, DNSSEC status, security.txt, weak certificate signatures, registration expiry and registrar sprawl.

Web page and privacy checks

Attack Surface Scan's page crawl: login and personal-data forms without encryption, mixed content, third-party scripts without SRI, tracking cookies before consent, and the third-party script inventory.

Reputation monitoring

How Attack Surface Scan checks your hosts and their IP addresses against free public abuse feeds, what a listing means, and how to get delisted.

Reporting

Connect

Reference