SeguriScan — security monitoring platform
Keep track of security issues in your websites, online systems and exposed company data.
For regular checks, clear priorities and a view of what still needs attention.
See how SeguriScan works →SeguriScan, IntruForce's platform, checks your websites and systems that can be accessed from the internet. It also looks for company data and work passwords exposed in leaks. It helps you decide what your IT team or provider should address first.
What needs attention now, and how serious each risk area is.
SeguriScan dashboard: assets, open services, findings by severity, data leaks and the threat level for each category
Dashboard
What needs attention now and how the calculated threat level is distributed across categories.
Threat level by category
Needs attention 4 of 40
An issue: priority P1, critical severity, a deadline, a technical description and a fix recommendation
| Prio. | Finding | Asset | CVSS | Sev |
|---|---|---|---|---|
| P1 | lk.example.com | 9.8 | C | |
| P1 | 192.0.2.25 | — | C | |
| P1 | example.com | — | C | |
| P1 | www.example.com | 9.4 | C | |
| P1 | vpn.example.com | 9.8 | C | |
| P2 | 192.0.2.25 | — | H | |
| P2 | cdn.example.com | 8.1 | H | |
| P2 | www.example.com | 7.5 | H | |
| P3 | example.com | — | M |
Web application scannerSW-WEB-DESER-02
Insecure handling of serialized data in the web portal
https://lk.example.com
lk.example.com
Description
The client portal accepts a serialized object from the browser and restores it on the server without checking its type. A crafted object lets an attacker run code on the server.
Recommendations
Stop deserializing data that comes from the browser, or restrict it to an allow-list of classes. Update the framework to a fixed version.
A server card: risk score, open ports, linked domains and the first thing to fix
Search by asset
| Asset | Risk | Issues | |
|---|---|---|---|
| 8.1 | 2112 | ||
| lk.example.com | |||
| shop.example.com | |||
| www.example.com | |||
| 9.1 | 12 | ||
| 9.6 | 11 | ||
| — | 12 | ||
| 7.8 | 1 | ||
| 7.5 | 1 | ||
192.0.2.20 IPv4 Available Confirmed
www.example.com
What to close first Ports
Web login forms Elevated importance 80443
Public login forms — enable brute-force protection and MFA.
Domains 3
The reports list: one report per check, downloadable as DOCX or XLSX
Ready perimeter reports — one per check. Each can be downloaded as DOCX or XLSX.
| Report | Check period | Status | |
|---|---|---|---|
| Perimeter report of 30 Sep 2026 | from 30 Sep 2026 | In progress | English |
| Perimeter report of 12 Aug 2026 | 4 Aug 2026 – 12 Aug 2026 | Completed | English |
| Perimeter report of 14 May 2026 | 6 May 2026 – 14 May 2026 | Completed | English |
A known flaw in a VPN server, flagged as used by attackers, with the deadline to fix it
| CVE | Product | Asset | CVSS | Sev |
|---|---|---|---|---|
| KEV | fortios7.2.5 | vpn.example.com | 9.8 | C |
| KEV | jenkins2.426.1 | ci.example.com | 9.8 | C |
| KEV | tomcat9.0.65 | api.example.com | 9.8 | C |
| fortios7.2.5 | vpn.example.com | 9.8 | C | |
| http_server2.4.54 | www.example.com | 9.8 | C | |
| http_server2.4.54 | www.example.com | 9.8 | C | |
| openssh8.9p1 | www.example.com | 8.1 | H | |
| openssh9.2p1 | 192.0.2.25 | 8.1 | H |
CVE-2024-21762
vpn.example.com
vpn.example.com
Product and asset
CISA KEV ransomware
Used in ransomware campaigns. Active exploitation — must be resolved as soon as possible.
External sources
NVD · CVE-2024-21762
Professional certifications
Professional qualifications held by individual members of our team in security testing, network defence and auditing. These are personal certifications; IntruForce as a company is not certified against ISO/IEC 27001.
Monitor your company's online systems with SeguriScan. For a closer look at a specific website or system, work with our security specialists.
Keep track of security issues in your websites, online systems and exposed company data.
For regular checks, clear priorities and a view of what still needs attention.
See how SeguriScan works →Have specialists test a website, application or system within an agreed scope.
Available separately, without a SeguriScan subscription.
View available assessments →A forgotten website, an open login page or a lookalike domain can create a problem for your business. Knowing about it gives your team a place to start.
A campaign has ended, but its website is still accessible from the internet. It may have security issues worth checking.
Anyone who finds it can try passwords against it. Your team can decide whether it should be reachable at all.
It could be used to impersonate your company. It is worth checking who uses it and for what purpose.
Understand the issue. Agree on the next step.
Working with SeguriScan
See the issues detected, agree on priorities with your IT team and follow what happens next. Your team or provider makes the fixes.
See issues detected in systems accessible from the internet, along with company data found in leaks.
Use the information about each issue to decide what to review first with your team or provider.
Follow the status of issues and the changes detected in SeguriScan checks.
SeguriScan identifies systems associated with your company, checks for security issues and brings the results together in one platform.
Together these checks cover what your company exposes to the internet — its external attack surface — and company accounts found in data leaks. SeguriScan covers systems reachable from the internet; it does not assess your internal network.
Start with a request for an initial review.
Share your company website and a work email with our team.Expert security testing
IntruForce specialists carry out security testing within a scope agreed with your company. You can book these assessments separately, without subscribing to SeguriScan.
Assess whether an attacker could exploit weaknesses in the systems included in the test.
Review the security of your online store, customer portal or business application.
Review how your systems exchange data and control access to it.
Assess how your team responds to messages designed to deceive them.
Each assessment starts with an agreed scope: the systems to test, the approach and the results to deliver. For example, you can combine SeguriScan monitoring with a separately scoped assessment of your customer portal.
Before you start
Your first step
Share your company website and a work email. We'll send your request to the IntruForce team. Tell us if you want to discuss a specific assessment instead.