Know which security issues to address first.

SeguriScan, IntruForce's platform, checks your websites and systems that can be accessed from the internet. It also looks for company data and work passwords exposed in leaks. It helps you decide what your IT team or provider should address first.

  • Nothing to install
  • No access to your internal network
  • You approve active testing separately

What needs attention now, and how serious each risk area is.

SeguriScan · my.intruforce.comDemo company, sample dataSample data

SeguriScan dashboard: assets, open services, findings by severity, data leaks and the threat level for each category

Dashboard

What needs attention now and how the calculated threat level is distributed across categories.

Services and ports24HTTPS 7HTTP 6SSH 5Mail 2Other 4

Threat level by category

compared with 25 Sep 2026

Lower is better

Current cycle since 1 Octas of 2 Oct 2026

6.6of 10
6.4
6.4−0.4
7.6
7.6−0.1
4.2
4.20.0
5.8
5.8+0.3
4.8
4.8−0.9
3.9
3.9−0.1

Needs attention 4 of 40

An issue: priority P1, critical severity, a deadline, a technical description and a fix recommendation

Prio.FindingAssetCVSSSev
P1lk.example.com9.8C
P1192.0.2.25—C
P2example.com—C
P2www.example.com9.4C
P1vpn.example.com9.8C
P2192.0.2.25—H
P2cdn.example.com8.1H
P2www.example.com7.5H
P3example.com—M

Dangerous exposure catalogSW-EXT-EXPOSURE-11

Dangerous exposure: MySQL database (3306)

192.0.2.25

PriorityP1Immediately
CriticalT1 · confidence

192.0.2.25

Age3 d.due by 6 Oct 2026
Exploitationnone
Detected29 Sep 2026

Description

The MySQL server answers on port 3306 from the internet. Anyone can try passwords against it, and any flaw in the server is reachable directly.

Recommendations

Close port 3306 on the perimeter. If remote access is needed, allow it only from known addresses or through the VPN.

A server card: risk score, open ports, linked domains and the first thing to fix

AssetRiskIssues
8.12112
lk.example.com
shop.example.com
www.example.com
9.112
9.611
—12
7.81
7.51

192.0.2.20 IPv4 Available Confirmed

www.example.com

Risk8.1High
Open portsUbuntu Linux 22.04Low (2)Medium (1)High (1)Critical (2)
Critical2open findings
SurfacePorts: 2elevated importance: 2
CertificatesTLS ok

What to close first Ports

Web login forms Elevated importance 80443

Public login forms — enable brute-force protection and MFA.

Domains 3

lk.example.comshop.example.comwww.example.com

The reports list: one report per check, downloadable as DOCX or XLSX

Ready perimeter reports — one per check. Each can be downloaded as DOCX or XLSX.

ReportCheck periodStatus
Perimeter report of 1 Oct 2026from 1 Oct 2026In progressEnglish
Perimeter report of 25 Sep 202624 Sep 2026 – 25 Sep 2026CompletedEnglish
Perimeter report of 18 Sep 202617 Sep 2026 – 18 Sep 2026CompletedEnglish

A known flaw in a VPN server, flagged as used by attackers, with the deadline to fix it

CVEProductAssetCVSSSev
KEVfortios7.2.5vpn.example.com9.8C
KEVjenkins2.426.1ci.example.com9.8C
KEVtomcat9.0.65api.example.com9.8C
fortios7.2.5vpn.example.com9.8C
http_server2.4.54www.example.com9.8C
http_server2.4.54www.example.com9.8C
openssh8.9p1www.example.com8.1H
openssh9.2p1192.0.2.258.1H

CVE-2024-21762

vpn.example.com

CVSS9.8Critical
CriticalT2 · confidenceKEV · ransomwareexploitation: confirmedEPSS 83.4%

vpn.example.com

CVSS9.8v3.1
ExploitationKEVEPSS 83.4%
Published9 Feb 2024

Product and asset

Product
fortios · fortinet
Version
7.2.5
Asset
vpn.example.com
Ports
443

CISA KEV ransomware

Used in ransomware campaigns. Active exploitation — must be resolved as soon as possible.

Resolve by
16 Feb 2024

External sources

NVD · CVE-2024-21762

Data leaks: leaked accounts of staff and customers, whether a password leaked too, and where it turned up

Data Leaks 17

access by grant

Passwords and hashes are shown masked. Access to full values is enabled for the organization on request.

AccountPasswordSourceSevFieldsFound
a.m*****@example.comStealer log · 1 Oct 2026yesStealer logCemail, password, URL1 Oct 2026
j.r****@example.comStealer log · 1 Oct 2026yesStealer logCemail, password, URL1 Oct 2026
s.p*****@example.comCombolist 2026-08 · 23 Sep 2026yesCombolist 2026-08Hemail, password23 Sep 2026
d.l****@example.comStealer log · 16 Sep 2026yesStealer logHemail, password, URL16 Sep 2026
it-support@example.comtravelbook.example breach · 2 Sep 2026yestravelbook.example breachHemail, password hash2 Sep 2026
m.g*****@example.comStealer log · 19 Aug 2026yesStealer logHemail, password, URL19 Aug 2026
Open the SeguriScan demo full screen
Built by cybersecurity practitionersThe same team runs security assessments for clients
Checks from outside your companyWebsites, online systems and exposed data
Support in English and SpanishWork with the team in either language

Professional certifications

The people behind the checks.

Professional qualifications held by individual members of our team in security testing, network defence and auditing. These are personal certifications; IntruForce as a company is not certified against ISO/IEC 27001.

  • OSCP
  • OSWP
  • OSWA
  • HTB CPTS
  • C|EH Master
  • ISO/IEC 27001 Lead Auditor

Two ways to work with IntruForce.

Monitor your company's online systems with SeguriScan. For a closer look at a specific website or system, work with our security specialists.

Platform · Security monitoring

SeguriScan — security monitoring platform

Keep track of security issues in your websites, online systems and exposed company data.

For regular checks, clear priorities and a view of what still needs attention.

See how SeguriScan works →
Services · A specific assessment

Expert security testing

Have specialists test a website, application or system within an agreed scope.

Available separately, without a SeguriScan subscription.

View available assessments →

Problems that can go unnoticed.

A forgotten website, an open login page or a lookalike domain can create a problem for your business. Knowing about it gives your team a place to start.

01

An old website is still online.

A campaign has ended, but its website is still accessible from the internet. It may have security issues worth checking.

02

A login page is open to the internet.

Anyone who finds it can try passwords against it. Your team can decide whether it should be reachable at all.

03

Someone registers a domain similar to yours.

It could be used to impersonate your company. It is worth checking who uses it and for what purpose. See sample look-alike domains →

Understand the issue. Agree on the next step.

SeguriScan in practice

One issue, from found to fixed.

SeguriScan checks what your company exposes to the internet — its external attack surface — and looks for company passwords in data leaks. Here is one issue at a sample company, start to finish.

SeguriScan covers systems reachable from the internet; it does not assess your internal network.

  1. Found on a system nobody listed.

    The company entered its domain, and SeguriScan found lk.example.com, a client portal missing from its list. The company approved it for checking.

    Not on the list

    lk.example.com · 1 of 11 domains found

    See the systems found →
  2. Ranked first, and confirmed.

    An approved active check reproduced it, so it is real, not a scanner guess. P1 puts it at the top of the list.

    P1 · act now ✓ Confirmed by an active check

    See the issue →
  3. The IT team or provider fixes it.

    The company's IT team or provider makes the fix. An IntruForce analyst answers their questions on the issue, inside SeguriScan.

    Analyst reply

    Yes, as a stopgap: allow only the classes the portal needs, then update the framework.

    See a request →
  4. The next check confirms the fix.

    After the fix, the next automated check no longer reproduces it and moves the issue to Resolved.

    Resolved

    See a resolved issue →
Issue · Invented example companySample data

The real SeguriScan issue screen, simplified. Invented company, sample data.

See what would come first for your company.

Share your company website and a work email with our team.Walk through the sample company, up to the leadership summary →
Check My Company

External review only · Nothing to install · You approve active testing separately

Expert security testing

Need a closer look at a specific system?

IntruForce specialists carry out security testing within a scope agreed with your company. You can book these assessments separately, without subscribing to SeguriScan.

01

Penetration testing

Assess whether an attacker could exploit weaknesses in the systems included in the test.

02

Web application security testing

Review the security of your online store, customer portal or business application.

03

API security testing

Review how your systems exchange data and control access to it.

04

Phishing simulations

Assess how your team responds to messages designed to deceive them.

Each assessment starts with an agreed scope: the systems to test, the approach and the results to deliver. For example, you can combine SeguriScan monitoring with a separately scoped assessment of your customer portal.

Ask our team about an assessment →

Before you start

A few practical questions.

We already work with an IT provider. Can this help?
SeguriScan shows which issues need attention, so you can review them with your provider and follow progress.
What happens after I send the request?
Our team reads your request and replies to your work email to agree what the review will cover. Nothing is tested until you approve it.
Who fixes the issues?
Your IT team or provider makes the fixes. SeguriScan helps you identify priorities and follow the status of issues.

Your first step

Request an initial review of your company.

Share your company website and a work email. We'll send your request to the IntruForce team. Tell us if you want to discuss a specific assessment instead.

  • Nothing to install
  • No access to your internal network
  • You approve active testing separately
Only if you’d prefer us to reply there.

This form sends a review request to the IntruForce team. Sending it commits you to nothing; our team replies to the work email you provide.