A dated, validated picture of your exposure
Authenticated scanning with the false positives removed and findings ranked by what actually matters in your environment.
The challenge
Raw scanner output is unusable. Hundreds of findings, most of them noise, none of them prioritised for your business.
Scope — included and not included
Included
- Authenticated and unauthenticated scanning
- Manual validation of findings
- False positive removal
- Prioritisation by exploitability and exposure
- Remediation guidance
Not included
- Exploitation of findings, that is a pentest
- Remediation work
- Continuous rescanning, that is vulnerability management
- Application logic testing
How it works
01
Scope and credentials
Target list, scan credentials, maintenance window if needed.
02
Scan
Authenticated and unauthenticated passes across the agreed scope.
03
Validate and rank
Manual validation, noise removed, ranked for your environment.
04
Report and walkthrough
Findings presented live, with remediation guidance per finding.
What you receive
- →Validated findings list
- →Prioritisation matrix
- →Remediation guidance per finding
- →Executive summary
- →Raw scan data
What we need from you
- ·Target list
- ·Scan credentials
- ·A maintenance window if required
- ·A named contact
Timeline and engagement
3 to 5 days. Fixed scope.
Standards, methods and tooling
OpenVASNessusDefectDojoCVSS 4.0Portal hosted in Canada
Frequently asked questions