SeguriScan — security monitoring platform
Keep track of security issues in your websites, online systems and exposed company data.
For regular checks, clear priorities and a view of what still needs attention.
See how SeguriScan works →SeguriScan, IntruForce's platform, checks your websites and systems that can be accessed from the internet. It also looks for company data and work passwords exposed in leaks. It helps you decide what your IT team or provider should address first.
What needs attention now, and how serious each risk area is.
SeguriScan dashboard: assets, open services, findings by severity, data leaks and the threat level for each category
Dashboard
What needs attention now and how the calculated threat level is distributed across categories.
Threat level by category
compared with 25 Sep 2026Lower is better
Current cycle since 1 Octas of 2 Oct 2026
Needs attention 4 of 40
An issue: priority P1, critical severity, a deadline, a technical description and a fix recommendation
| Prio. | Finding | Asset | CVSS | Sev |
|---|---|---|---|---|
| P1 | lk.example.com | 9.8 | C | |
| P1 | 192.0.2.25 | — | C | |
| P2 | example.com | — | C | |
| P2 | www.example.com | 9.4 | C | |
| P1 | vpn.example.com | 9.8 | C | |
| P2 | 192.0.2.25 | — | H | |
| P2 | cdn.example.com | 8.1 | H | |
| P2 | www.example.com | 7.5 | H | |
| P3 | example.com | — | M |
Dangerous exposure catalogSW-EXT-EXPOSURE-11
Dangerous exposure: MySQL database (3306)
192.0.2.25
192.0.2.25
Description
The MySQL server answers on port 3306 from the internet. Anyone can try passwords against it, and any flaw in the server is reachable directly.
Recommendations
Close port 3306 on the perimeter. If remote access is needed, allow it only from known addresses or through the VPN.
A server card: risk score, open ports, linked domains and the first thing to fix
Search by asset
| Asset | Risk | Issues | |
|---|---|---|---|
| 8.1 | 2112 | ||
| lk.example.com | |||
| shop.example.com | |||
| www.example.com | |||
| 9.1 | 12 | ||
| 9.6 | 11 | ||
| — | 12 | ||
| 7.8 | 1 | ||
| 7.5 | 1 | ||
192.0.2.20 IPv4 Available Confirmed
www.example.com
What to close first Ports
Web login forms Elevated importance 80443
Public login forms — enable brute-force protection and MFA.
Domains 3
The reports list: one report per check, downloadable as DOCX or XLSX
Ready perimeter reports — one per check. Each can be downloaded as DOCX or XLSX.
| Report | Check period | Status | |
|---|---|---|---|
| Perimeter report of 1 Oct 2026 | from 1 Oct 2026 | In progress | English |
| Perimeter report of 25 Sep 2026 | 24 Sep 2026 – 25 Sep 2026 | Completed | English |
| Perimeter report of 18 Sep 2026 | 17 Sep 2026 – 18 Sep 2026 | Completed | English |
A known flaw in a VPN server, flagged as used by attackers, with the deadline to fix it
| CVE | Product | Asset | CVSS | Sev |
|---|---|---|---|---|
| KEV | fortios7.2.5 | vpn.example.com | 9.8 | C |
| KEV | jenkins2.426.1 | ci.example.com | 9.8 | C |
| KEV | tomcat9.0.65 | api.example.com | 9.8 | C |
| fortios7.2.5 | vpn.example.com | 9.8 | C | |
| http_server2.4.54 | www.example.com | 9.8 | C | |
| http_server2.4.54 | www.example.com | 9.8 | C | |
| openssh8.9p1 | www.example.com | 8.1 | H | |
| openssh9.2p1 | 192.0.2.25 | 8.1 | H |
CVE-2024-21762
vpn.example.com
vpn.example.com
Product and asset
CISA KEV ransomware
Used in ransomware campaigns. Active exploitation — must be resolved as soon as possible.
External sources
NVD · CVE-2024-21762
Data leaks: leaked accounts of staff and customers, whether a password leaked too, and where it turned up
Data Leaks 17
access by grantPasswords and hashes are shown masked. Access to full values is enabled for the organization on request.
| Account | Password | Source | Sev | Fields | Found |
|---|---|---|---|---|---|
| a.m*****@example.comStealer log · 1 Oct 2026 | yes | Stealer log | C | email, password, URL | 1 Oct 2026 |
| j.r****@example.comStealer log · 1 Oct 2026 | yes | Stealer log | C | email, password, URL | 1 Oct 2026 |
| s.p*****@example.comCombolist 2026-08 · 23 Sep 2026 | yes | Combolist 2026-08 | H | email, password | 23 Sep 2026 |
| d.l****@example.comStealer log · 16 Sep 2026 | yes | Stealer log | H | email, password, URL | 16 Sep 2026 |
| it-support@example.comtravelbook.example breach · 2 Sep 2026 | yes | travelbook.example breach | H | email, password hash | 2 Sep 2026 |
| m.g*****@example.comStealer log · 19 Aug 2026 | yes | Stealer log | H | email, password, URL | 19 Aug 2026 |
Professional certifications
Professional qualifications held by individual members of our team in security testing, network defence and auditing. These are personal certifications; IntruForce as a company is not certified against ISO/IEC 27001.
Monitor your company's online systems with SeguriScan. For a closer look at a specific website or system, work with our security specialists.
Keep track of security issues in your websites, online systems and exposed company data.
For regular checks, clear priorities and a view of what still needs attention.
See how SeguriScan works →Have specialists test a website, application or system within an agreed scope.
Available separately, without a SeguriScan subscription.
View available assessments →A forgotten website, an open login page or a lookalike domain can create a problem for your business. Knowing about it gives your team a place to start.
A campaign has ended, but its website is still accessible from the internet. It may have security issues worth checking.
Anyone who finds it can try passwords against it. Your team can decide whether it should be reachable at all.
It could be used to impersonate your company. It is worth checking who uses it and for what purpose. See sample look-alike domains →
Understand the issue. Agree on the next step.
SeguriScan in practice
SeguriScan checks what your company exposes to the internet — its external attack surface — and looks for company passwords in data leaks. Here is one issue at a sample company, start to finish.
SeguriScan covers systems reachable from the internet; it does not assess your internal network.
The company entered its domain, and SeguriScan found lk.example.com, a client portal missing from its list. The company approved it for checking.
Not on the list
See the systems found →An approved active check reproduced it, so it is real, not a scanner guess. P1 puts it at the top of the list.
P1 · act now ✓ Confirmed by an active check
See the issue →The company's IT team or provider makes the fix. An IntruForce analyst answers their questions on the issue, inside SeguriScan.
Yes, as a stopgap: allow only the classes the portal needs, then update the framework.
After the fix, the next automated check no longer reproduces it and moves the issue to Resolved.
Resolved
See a resolved issue →The real SeguriScan issue screen, simplified. Invented company, sample data.
See what would come first for your company.
Share your company website and a work email with our team.Walk through the sample company, up to the leadership summary →External review only · Nothing to install · You approve active testing separately
Expert security testing
IntruForce specialists carry out security testing within a scope agreed with your company. You can book these assessments separately, without subscribing to SeguriScan.
Assess whether an attacker could exploit weaknesses in the systems included in the test.
Review the security of your online store, customer portal or business application.
Review how your systems exchange data and control access to it.
Assess how your team responds to messages designed to deceive them.
Each assessment starts with an agreed scope: the systems to test, the approach and the results to deliver. For example, you can combine SeguriScan monitoring with a separately scoped assessment of your customer portal.
Before you start
Your first step
Share your company website and a work email. We'll send your request to the IntruForce team. Tell us if you want to discuss a specific assessment instead.