SeguriScan
See how SeguriScan works, screen by screen
SeguriScan, IntruForce's platform, checks the websites and systems your company exposes to the internet and looks for company data and work passwords exposed in leaks. It shows your team what to fix first. Below, one sample company, from its domain to its report for leadership.
SeguriScan covers systems reachable from the internet. It does not assess your internal network.
External review only · Nothing to install · You approve active testing separately
1 / 9 · Adding systems
It starts with your domain.
You add a domain or an address range, accept the assessment rules and confirm you are authorized to have it checked. Local or internal addresses are rejected: the internet can't reach them.
- You confirm you're authorized
- Rejected: internal address
2 / 9 · Systems · Changes
Find systems you didn't know about.
From the lines entered, SeguriScan found the servers and websites behind them on its own, including some nobody entered; the company confirms them before they are scanned. Most get a risk score from 0 to 10, and changes since the last check are marked.
- Not on your list
- New since last check
Perimeter changes
Appeared 198.51.100.14
Opened 192.0.2.25 :3306/tcp
Closed 192.0.2.21 :8080/tcp
Perimeter changes
Assets
Appeared 1
198.51.100.14
Disappeared 1
192.0.2.30
Ports
Opened 1
192.0.2.25 :3306/tcp mysql
Closed 1
192.0.2.21 :8080/tcp http
Domains
Appeared 1
pay.example.com
Disappeared 1
old-shop.example.com
3 / 9 · Dashboard
See where the biggest risk sits: here, Web.
SeguriScan scores everything it found in six areas, from network to mail; here, Web scores highest. The center is one overall number, lower is better, and it is not a guarantee.
- Overall score (lower is better)
- Web: highest, and going down
Threat level by category
compared with 25 Sep 2026Lower is better
Current cycle since 1 Octas of 2 Oct 2026
for the current state as of 2 Oct 2026
Websites and web applications: login forms, exposed files, insecure handling of data.
Findings counted13
Critical2
High6
Medium3
Assets in the denominator6
Findings per asset2.2
4 / 9 · Outdated software
Find old software attackers already use.
Part of the Network and Web scores is old software: SeguriScan matches versions on the company's systems against publicly known vulnerabilities, most severe first. A KEV tag marks flaws on CISA's list of those used in real attacks, next to the system to update.
- Used in real attacks (CISA KEV)
- Which system to update
5 / 9 · Similar domains · Data leaks
Spot look-alike domains and leaked passwords.
Some of the risk sits outside the company's servers: SeguriScan lists registered domains that imitate it and whether they can receive email. Work accounts found in leaks sit in a separate view for people given access, masked, so the team knows whose passwords to change.
- Can receive email (MX)
Similar domains 11
| Similar domain | Type | Status | Risk | MX records |
|---|---|---|---|---|
| example.netdomain zone (TLD) substitution | domain zone (TLD) substitution | Active | High | mail.example.net |
| examp1e.examplehomoglyph (visually similar characters) | homoglyph (visually similar characters) | Active | High | mx1.examp1e.example |
| example-login.exampledictionary word addition | dictionary word addition | Active | High | mx.example-login.example |
| exarnple.examplehomoglyph (visually similar characters) | homoglyph (visually similar characters) | Active | High | — |
| pay-example.examplehyphen insertion | hyphen insertion | Active | Medium | mail.pay-example.example |
Only registered lookalike domains appear in the list. “MX records” are the domain’s mail servers (phishing risk).
6 / 9 · Issues
Know what to fix first, and how.
Across all areas, Needs attention puts one issue first: a P1 on the client portal, in Web, confirmed by an active check. Each issue shows where it was found, the date to fix it by and steps your IT team can follow.
- Confirmed: an active check reproduced it
- How to fix
Needs attention 4 of 40
Web application scannerSW-WEB-DESER-02
Insecure handling of serialized data in the web portal
https://lk.example.com
lk.example.com
Description
The client portal accepts a serialized object from the browser and restores it on the server without checking its type. A crafted object lets an attacker run code on the server.
How to fix
Stop deserializing data that comes from the browser, or restrict it to an allow-list of classes. Update the framework to a fixed version.
7 / 9 · My requests
Ask an analyst while you fix it.
Your IT team asks about that portal issue right on it, inside SeguriScan. An IntruForce analyst replies in the same thread.
- An IntruForce analyst replies
Web application scannerSW-WEB-DESER-02
Insecure handling of serialized data in the web portal
https://lk.example.com
My requests · 1
Question or comment In progress
We can’t remove deserialization from the portal before our next release. Is an allow-list of classes enough for now?
Yes, as a stopgap: allow only the classes the portal needs, and update the framework as soon as you can. The next check will show whether the fix holds.
8 / 9 · Issues · Resolved
See the fix confirmed by the next check.
Earlier, the team closed an admin console on api.example.com:8080. The next automated check no longer reached it and moved the issue to Resolved on its own.
- Resolved by the next check
Infrastructure scannerSW-EXT-EXPOSURE-17
API server admin console open to the internet (port 8080)Resolved
http://api.example.com:8080
Question or comment
We closed port 8080 on api.example.com. The console now answers only on our internal network.
Not reproduced: api.example.com:8080 no longer answers from the internet. Status: Resolved.
9 / 9 · Summary
Show leadership the progress on one page.
Fixes like these add up: the summary shows the score, open issues by priority and how fast the team fixes them, ready to print. Your IT team also gets a detailed report in Word or Excel after each check.
- Average days to fix (MTTR)
- Print / PDF
DEMO · Fintech — external perimeter
Executive summary · External perimeter assessment (EASM)
Observation period: from 17 Jul 2026 — 2 Oct 2026
Generated2 Oct 2026
EASM perimeter score
Medium▼ -0.3 · risk decreased
One number for how exposed the company is online, not a guarantee.
By response priority
P1 3P2 15P3 22P4 0
Remediation
Average days from detection to fix.
Share of issues the team has fixed.
Overdue: issues still open after the fix-by date for their priority.
Due soon: issues whose fix-by date is close.
Open findings — trend
17 Jul 202640 open2 Oct 2026
Top risks up to 10 priority open findings
| Prio. | Finding | Asset | Sev. |
|---|---|---|---|
| P1 | vpn.example.com | C | |
| P1 | lk.example.com | C | |
| P1 | 192.0.2.25 | C | |
| P2 | www.example.com | C | |
| P2 | example.com | C |
Questions, answered
FAQ
Will we hear about new issues without logging in?
SeguriScan can send notifications to email addresses or Telegram chats your admin sets up, each with its own minimum severity.
Need a deeper test of one system?
IntruForce also runs expert security assessments, such as a penetration test of a single system. See Expert Services →
What needs attention now, and how serious each risk area is.
SeguriScan dashboard: assets, open services, findings by severity, data leaks and the threat level for each category
An issue: priority P1, critical severity, a deadline, a technical description and a fix recommendation
A server card: risk score, open ports, linked domains and the first thing to fix
The reports list: one report per check, downloadable as DOCX or XLSX
A known flaw in a VPN server, flagged as used by attackers, with the deadline to fix it
Data leaks: leaked accounts of staff and customers, whether a password leaked too, and where it turned up
Your first step
See what SeguriScan finds for your company.
Share your company website and a work email. We'll send your request to the IntruForce team. Tell us if you want to discuss a specific assessment instead.
- Nothing to install
- No access to your internal network
- You approve active testing separately