SeguriScan

See how SeguriScan works, screen by screen

SeguriScan, IntruForce's platform, checks the websites and systems your company exposes to the internet and looks for company data and work passwords exposed in leaks. It shows your team what to fix first. Below, one sample company, from its domain to its report for leadership.

SeguriScan covers systems reachable from the internet. It does not assess your internal network.

Check My Company

External review only · Nothing to install · You approve active testing separately

1 / 9 · Adding systems

It starts with your domain.

You add a domain or an address range, accept the assessment rules and confirm you are authorized to have it checked. Local or internal addresses are rejected: the internet can't reach them.

  1. You confirm you're authorized
  2. Rejected: internal address
Inside SeguriScan, when you add systemsSample data

2 / 9 · Systems · Changes

Find systems you didn't know about.

From the lines entered, SeguriScan found the servers and websites behind them on its own, including some nobody entered; the company confirms them before they are scanned. Most get a risk score from 0 to 10, and changes since the last check are marked.

  1. Not on your list
  2. New since last check
Sample data
AssetRiskIssues
8.12112
lk.example.com
shop.example.com
www.example.com
9.112
9.611
—12
7.81
7.51

192.0.2.21 IPv4 Available Confirmed

api.example.com

Risk7.5High
Open portsUbuntu Linux 22.04High (1)
Critical0open findings
SurfacePorts: 1elevated importance: 1
CertificatesTLS ok

What to close first Ports

Web services on the perimeter Elevated importance 443

API on the perimeter — retire old.example.com if nothing uses it.

Domains 3

api.example.comci.example.comold.example.com

Perimeter changes

Appeared 198.51.100.14

Opened 192.0.2.25 :3306/tcp

Closed 192.0.2.21 :8080/tcp

3 / 9 · Dashboard

See where the biggest risk sits: here, Web.

SeguriScan scores everything it found in six areas, from network to mail; here, Web scores highest. The center is one overall number, lower is better, and it is not a guarantee.

  1. Overall score (lower is better)
  2. Web: highest, and going down
Sample data

Threat level by category

compared with 25 Sep 2026

Lower is better

Current cycle since 1 Octas of 2 Oct 2026

6.6of 10
6.4
6.4−0.4
7.6
7.6−0.1

for the current state as of 2 Oct 2026

Websites and web applications: login forms, exposed files, insecure handling of data.

Findings counted13

Critical2

High6

Medium3

Assets in the denominator6

Findings per asset2.2

4.2
4.20.0
5.8
5.8+0.3
4.8
4.8−0.9
3.9
3.9−0.1

4 / 9 · Outdated software

Find old software attackers already use.

Part of the Network and Web scores is old software: SeguriScan matches versions on the company's systems against publicly known vulnerabilities, most severe first. A KEV tag marks flaws on CISA's list of those used in real attacks, next to the system to update.

  1. Used in real attacks (CISA KEV)
  2. Which system to update
Sample data
CVEProductAssetCVSSSev
KEVfortios7.2.5vpn.example.com9.8C
KEVjenkins2.426.1ci.example.com9.8C
KEVtomcat9.0.65api.example.com9.8C
fortios7.2.5vpn.example.com9.8C
http_server2.4.54www.example.com9.8C
http_server2.4.54www.example.com9.8C
openssh8.9p1www.example.com8.1H
openssh9.2p1192.0.2.258.1H

CVE-2025-24813

api.example.com

CVSS9.8Critical
CriticalT2 · confidenceKEVexploitation: confirmedEPSS >99.9%

api.example.com

CVSS9.8v3.1
ExploitationKEVEPSS >99.9%
Published10 Mar 2025

Product and asset

Product
tomcat · apache
Version
9.0.65
Asset
api.example.com
Ports
443

CISA KEV

Active exploitation — must be resolved as soon as possible.

Resolve by
22 Apr 2025

External sources

NVD · CVE-2025-24813

5 / 9 · Similar domains · Data leaks

Spot look-alike domains and leaked passwords.

Some of the risk sits outside the company's servers: SeguriScan lists registered domains that imitate it and whether they can receive email. Work accounts found in leaks sit in a separate view for people given access, masked, so the team knows whose passwords to change.

  1. Can receive email (MX)
Sample data

Similar domains 11

Similar domainTypeStatusRiskMX records
example.netdomain zone (TLD) substitutiondomain zone (TLD) substitutionActiveHighmail.example.net
examp1e.examplehomoglyph (visually similar characters)homoglyph (visually similar characters)ActiveHighmx1.examp1e.example
example-login.exampledictionary word additiondictionary word additionActiveHighmx.example-login.example
exarnple.examplehomoglyph (visually similar characters)homoglyph (visually similar characters)ActiveHigh—
pay-example.examplehyphen insertionhyphen insertionActiveMediummail.pay-example.example

Only registered lookalike domains appear in the list. “MX records” are the domain’s mail servers (phishing risk).

6 / 9 · Issues

Know what to fix first, and how.

Across all areas, Needs attention puts one issue first: a P1 on the client portal, in Web, confirmed by an active check. Each issue shows where it was found, the date to fix it by and steps your IT team can follow.

  1. Confirmed: an active check reproduced it
  2. How to fix
Sample data

Needs attention 4 of 40

Web application scannerSW-WEB-DESER-02

Insecure handling of serialized data in the web portal

https://lk.example.com

PriorityP1Immediately
CriticalConfirmedT1 · confidence

lk.example.com

Age2 d.due by 7 Oct 2026
Exploitationlikely
Detected30 Sep 2026

Description

The client portal accepts a serialized object from the browser and restores it on the server without checking its type. A crafted object lets an attacker run code on the server.

How to fix

Stop deserializing data that comes from the browser, or restrict it to an allow-list of classes. Update the framework to a fixed version.

7 / 9 · My requests

Ask an analyst while you fix it.

Your IT team asks about that portal issue right on it, inside SeguriScan. An IntruForce analyst replies in the same thread.

  1. An IntruForce analyst replies
Sample data

Web application scannerSW-WEB-DESER-02

Insecure handling of serialized data in the web portal

https://lk.example.com

My requests · 1

Question or comment In progress

IT team

We can’t remove deserialization from the portal before our next release. Is an allow-list of classes enough for now?

In progress · IntruForce analyst

Analyst reply · IntruForce analyst

Yes, as a stopgap: allow only the classes the portal needs, and update the framework as soon as you can. The next check will show whether the fix holds.

8 / 9 · Issues · Resolved

See the fix confirmed by the next check.

Earlier, the team closed an admin console on api.example.com:8080. The next automated check no longer reached it and moved the issue to Resolved on its own.

  1. Resolved by the next check
Sample data

Infrastructure scannerSW-EXT-EXPOSURE-17

API server admin console open to the internet (port 8080)Resolved

http://api.example.com:8080

Question or comment

IT team

We closed port 8080 on api.example.com. The console now answers only on our internal network.

SeguriScan check

Not reproduced: api.example.com:8080 no longer answers from the internet. Status: Resolved.

9 / 9 · Summary

Show leadership the progress on one page.

Fixes like these add up: the summary shows the score, open issues by priority and how fast the team fixes them, ready to print. Your IT team also gets a detailed report in Word or Excel after each check.

  1. Average days to fix (MTTR)
  2. Print / PDF
Sample data

DEMO · Fintech — external perimeter

Executive summary · External perimeter assessment (EASM)

Observation period: from 17 Jul 2026 — 2 Oct 2026

Generated2 Oct 2026

EASM perimeter score

C6.6/10
Medium
▼ -0.3 · risk decreased

One number for how exposed the company is online, not a guarantee.

By response priority

P1 3P2 15P3 22P4 0

Remediation

MTTR9.4 d.mean time to remediate

Average days from detection to fix.

Resolved78%share of closed findings

Share of issues the team has fixed.

Overdue1SLA deadline missed

Overdue: issues still open after the fix-by date for their priority.

Due soon3deadline is approaching

Due soon: issues whose fix-by date is close.

Open findings — trend

17 Jul 202640 open2 Oct 2026

Top risks up to 10 priority open findings

Prio.FindingAssetSev.
P1vpn.example.comC
P1lk.example.comC
P1192.0.2.25C
P2www.example.comC
P2example.comC

Questions, answered

FAQ

Will we hear about new issues without logging in?

SeguriScan can send notifications to email addresses or Telegram chats your admin sets up, each with its own minimum severity.

Need a deeper test of one system?

IntruForce also runs expert security assessments, such as a penetration test of a single system. See Expert Services →

What needs attention now, and how serious each risk area is.

SeguriScan · my.intruforce.comDemo company, sample dataSample data

SeguriScan dashboard: assets, open services, findings by severity, data leaks and the threat level for each category

An issue: priority P1, critical severity, a deadline, a technical description and a fix recommendation

A server card: risk score, open ports, linked domains and the first thing to fix

The reports list: one report per check, downloadable as DOCX or XLSX

A known flaw in a VPN server, flagged as used by attackers, with the deadline to fix it

Data leaks: leaked accounts of staff and customers, whether a password leaked too, and where it turned up

Open the SeguriScan demo full screen

Your first step

See what SeguriScan finds for your company.

Share your company website and a work email. We'll send your request to the IntruForce team. Tell us if you want to discuss a specific assessment instead.

  • Nothing to install
  • No access to your internal network
  • You approve active testing separately
Only if you’d prefer us to reply there.

This form sends a review request to the IntruForce team. Sending it commits you to nothing; our team replies to the work email you provide.