Know which security issues to address first.

SeguriScan, IntruForce's platform, checks your websites and systems that can be accessed from the internet. It also looks for company data and work passwords exposed in leaks. It helps you decide what your IT team or provider should address first.

  • Nothing to install
  • No access to your internal network
  • You approve active testing separately

What needs attention now, and how serious each risk area is.

SeguriScan · my.intruforce.comDemo company, sample dataSample data

SeguriScan dashboard: assets, open services, findings by severity, data leaks and the threat level for each category

Dashboard

What needs attention now and how the calculated threat level is distributed across categories.

Services and ports24HTTPS 7HTTP 6SSH 5Mail 2Other 4
Data leaks17unprocessedEmployees 9Customers 4External 3Unclassified 1

Threat level by category

  1. 01Network6.4
  2. 02Web7.6
  3. 03Info4.2
  4. 04Data leaks5.8
  5. 05Mail—
  6. 06ASM3.9

Needs attention 4 of 40

An issue: priority P1, critical severity, a deadline, a technical description and a fix recommendation

Prio.FindingAssetCVSSSev
P1lk.example.com9.8C
P1192.0.2.25—C
P1example.com—C
P1www.example.com9.4C
P1vpn.example.com9.8C
P2192.0.2.25—H
P2cdn.example.com8.1H
P2www.example.com7.5H
P3example.com—M

Web application scannerSW-WEB-DESER-02

Insecure handling of serialized data in the web portal

https://lk.example.com

PriorityP1Immediately
CriticalT1 · confidence

lk.example.com

Age2 d.due by 6 Oct 2026
Exploitationlikely
Detected29 Sep 2026

Description

The client portal accepts a serialized object from the browser and restores it on the server without checking its type. A crafted object lets an attacker run code on the server.

Recommendations

Stop deserializing data that comes from the browser, or restrict it to an allow-list of classes. Update the framework to a fixed version.

A server card: risk score, open ports, linked domains and the first thing to fix

AssetRiskIssues
8.12112
lk.example.com
shop.example.com
www.example.com
9.112
9.611
—12
7.81
7.51

192.0.2.20 IPv4 Available Confirmed

www.example.com

Risk8.1High
Open portsUbuntu Linux 22.04Low (2)Medium (1)High (1)Critical (2)
Critical2open findings
SurfacePorts: 2elevated importance: 2
CertificatesTLS ok

What to close first Ports

Web login forms Elevated importance 80443

Public login forms — enable brute-force protection and MFA.

Domains 3

lk.example.comshop.example.comwww.example.com

The reports list: one report per check, downloadable as DOCX or XLSX

Ready perimeter reports — one per check. Each can be downloaded as DOCX or XLSX.

ReportCheck periodStatus
Perimeter report of 30 Sep 2026from 30 Sep 2026In progressEnglish
Perimeter report of 12 Aug 20264 Aug 2026 – 12 Aug 2026CompletedEnglish
Perimeter report of 14 May 20266 May 2026 – 14 May 2026CompletedEnglish

A known flaw in a VPN server, flagged as used by attackers, with the deadline to fix it

CVEProductAssetCVSSSev
KEVfortios7.2.5vpn.example.com9.8C
KEVjenkins2.426.1ci.example.com9.8C
KEVtomcat9.0.65api.example.com9.8C
fortios7.2.5vpn.example.com9.8C
http_server2.4.54www.example.com9.8C
http_server2.4.54www.example.com9.8C
openssh8.9p1www.example.com8.1H
openssh9.2p1192.0.2.258.1H

CVE-2024-21762

vpn.example.com

CVSS9.8Critical
CriticalT2 · confidenceKEV · ransomwareexploitation: confirmedEPSS 83.4%

vpn.example.com

CVSS9.8v3.1
ExploitationKEVEPSS 83.4%
Published9 Feb 2024

Product and asset

Product
fortios · fortinet
Version
7.2.5
Asset
vpn.example.com
Ports
443

CISA KEV ransomware

Used in ransomware campaigns. Active exploitation — must be resolved as soon as possible.

Resolve by
16 Feb 2024

External sources

NVD · CVE-2024-21762

Open the SeguriScan demo full screen
Built by cybersecurity practitionersThe same team runs security assessments for clients
Checks from outside your companyWebsites, online systems and exposed data
Support in English and SpanishWork with the team in either language

Professional certifications

The people behind the checks.

Professional qualifications held by individual members of our team in security testing, network defence and auditing. These are personal certifications; IntruForce as a company is not certified against ISO/IEC 27001.

  • OSCP
  • OSWP
  • OSWA
  • HTB CPTS
  • C|EH Master
  • ISO/IEC 27001 Lead Auditor

Two ways to work with IntruForce.

Monitor your company's online systems with SeguriScan. For a closer look at a specific website or system, work with our security specialists.

Platform · Security monitoring

SeguriScan — security monitoring platform

Keep track of security issues in your websites, online systems and exposed company data.

For regular checks, clear priorities and a view of what still needs attention.

See how SeguriScan works →
Services · A specific assessment

Expert security testing

Have specialists test a website, application or system within an agreed scope.

Available separately, without a SeguriScan subscription.

View available assessments →

Problems that can go unnoticed.

A forgotten website, an open login page or a lookalike domain can create a problem for your business. Knowing about it gives your team a place to start.

01

An old website is still online.

A campaign has ended, but its website is still accessible from the internet. It may have security issues worth checking.

02

A login page is open to the internet.

Anyone who finds it can try passwords against it. Your team can decide whether it should be reachable at all.

03

Someone registers a domain similar to yours.

It could be used to impersonate your company. It is worth checking who uses it and for what purpose.

Understand the issue. Agree on the next step.

Working with SeguriScan

Information to make decisions and track progress.

See the issues detected, agree on priorities with your IT team and follow what happens next. Your team or provider makes the fixes.

Know what needs attention.

See issues detected in systems accessible from the internet, along with company data found in leaks.

Agree on priorities with your IT team.

Use the information about each issue to decide what to review first with your team or provider.

See what is still open.

Follow the status of issues and the changes detected in SeguriScan checks.

How it works

SeguriScan identifies systems associated with your company, checks for security issues and brings the results together in one platform.

Together these checks cover what your company exposes to the internet — its external attack surface — and company accounts found in data leaks. SeguriScan covers systems reachable from the internet; it does not assess your internal network.

Start with a request for an initial review.

Share your company website and a work email with our team.
Check My Company

Expert security testing

Need a closer look at a specific system?

IntruForce specialists carry out security testing within a scope agreed with your company. You can book these assessments separately, without subscribing to SeguriScan.

01

Penetration testing

Assess whether an attacker could exploit weaknesses in the systems included in the test.

02

Web application security testing

Review the security of your online store, customer portal or business application.

03

API security testing

Review how your systems exchange data and control access to it.

04

Phishing simulations

Assess how your team responds to messages designed to deceive them.

Each assessment starts with an agreed scope: the systems to test, the approach and the results to deliver. For example, you can combine SeguriScan monitoring with a separately scoped assessment of your customer portal.

Ask our team about an assessment →

Before you start

A few practical questions.

We already work with an IT provider. Can this help?
SeguriScan shows which issues need attention, so you can review them with your provider and follow progress.
What happens after I send the request?
Our team reads your request and replies to your work email to agree what the review will cover. Nothing is tested until you approve it.
Who fixes the issues?
Your IT team or provider makes the fixes. SeguriScan helps you identify priorities and follow the status of issues.

Your first step

Request an initial review of your company.

Share your company website and a work email. We'll send your request to the IntruForce team. Tell us if you want to discuss a specific assessment instead.

  • Nothing to install
  • No access to your internal network
  • You approve active testing separately
Only if you’d prefer us to reply there.

This form sends a review request to the IntruForce team. Sending it commits you to nothing; our team replies to the work email you provide.