Security Overview
Risk Trend (Last 30 Days)
Risk Distribution ⓘ
Recent Assessments
View All →| Assessment | Target | Status | Risk | Findings | Last Scan | |
|---|---|---|---|---|---|---|
| #1042 example.com |
example.comhttps://example.com |
Completed | High | 271812 | 18 Jun 2024 10:30 AM |
⋮ |
| #1043 shop.example.com |
shop.example.comhttps://shop.example.com |
Running | Medium | 0253 | 18 Jun 2024 09:15 AM |
⋮ |
| #1041 api.example.com |
api.example.comhttps://api.example.com |
Completed | High | 14126 | 17 Jun 2024 04:45 PM |
⋮ |
| #1040 test.example.com |
test.example.comhttps://test.example.com |
Completed | Low | 0128 | 16 Jun 2024 11:20 AM |
⋮ |
| #1039 dev.example.com |
dev.example.comhttps://dev.example.com |
Completed | Medium | 0364 | 15 Jun 2024 02:10 PM |
⋮ |
Quick Actions
New Assessment
Start a new security assessment
View Projects
Manage all your projects
View Findings
Browse all security findings
Generate Report
Create a new security report
Retest
Re-run assessment to verify fixes
Monitoring
View monitoring dashboard
| Project | Targets | Status | Risk ⓘ | Findings | Last Assessment | Actions |
|---|---|---|---|---|---|---|
| Loading projects... | ||||||
Assessment #1042
RunningScan Progress
42%Scan Statistics
View DetailsLive Activity
View All LogsScan Configuration
Attack Surface
Visualize and explore the discovered attack surface of the targetAttack Surface Graph ⓘ
Discovered Assets (428)
| Asset | Type | Status | Source | Risk | Discovered On | Actions |
|---|---|---|---|---|---|---|
| 3 https://www.example.com/ | Web Page | 200 OK | Crawler | Low | 19 May 2024, 10:15 AM | ⋮ |
| 2 https://api.example.com/v1/users | API Endpoint | 200 OK | Crawler | Medium | 19 May 2024, 10:16 AM | ⋮ |
| 3 https://login.example.com/ | Web Page | 200 OK | Passive | Medium | 19 May 2024, 10:16 AM | ⋮ |
| 3 https://www.example.com/search?q=test | Parameter | 200 OK | Crawler | High | 19 May 2024, 10:17 AM | ⋮ |
| 3 https://www.example.com/admin | Sensitive Path | 403 Forbidden | Crawler | High | 19 May 2024, 10:17 AM | ⋮ |
Attack Surface Summary
Asset Types
View AllTop Subdomains
View AllDiscovery Sources
View AllFindings
Review and manage the security findings discovered in this assessment.| Finding | Severity | Status | Confidence | Category | Affected Asset | Discovered On | Actions |
|---|---|---|---|---|---|---|---|
|
🛡️
SQL Injection (Union Based)
/search?q=test |
Critical | Open | ● High | Injection | https://example.com/search | 19 May 2024 10:17 AM |
⋮ |
|
🛡️
Authentication Bypass
/api/auth/login |
Critical | Open | ● High | Authentication | https://api.example.com | 19 May 2024 10:32 AM |
⋮ |
|
☣️
Broken Access Control
/api/user/123 |
High | Open | ● High | Access Control | https://api.example.com | 19 May 2024 10:40 AM |
⋮ |
|
☣️
Sensitive Data Exposure
/user/profile |
High | Open | ● Medium | Data Exposure | https://api.example.com | 19 May 2024 10:48 AM |
⋮ |
|
☣️
Cross-Site Scripting (Reflected)
/search?q=<script>alert(1)</script> |
High | Open | ● High | XSS | https://example.com/search | 19 May 2024 11:02 AM |
⋮ |
|
🔍
Security Misconfiguration
/ |
Medium | Open | ● Medium | Configuration | https://example.com | 19 May 2024 11:25 AM |
⋮ |
|
🔍
Missing Security Headers
/ |
Medium | Open | ● Medium | Best Practices | https://example.com | 19 May 2024 11:27 AM |
⋮ |
|
🎯
Information Disclosure
/server-status |
Low | Open | ● Low | Information Disclosure | https://example.com/server-status | 19 May 2024 11:32 AM |
⋮ |
|
🎯
Directory Listing Enabled
/assets/ |
Low | Open | ● Low | Configuration | https://example.com/assets | 19 May 2024 11:41 AM |
⋮ |
|
ℹ️
Outdated jQuery Library
/assets/js/jquery.min.js |
Informational | Open | ● Low | Best Practices | https://example.com | 19 May 2024 11:50 AM |
⋮ |
SQL Injection (Union Based)
CriticalThe application is vulnerable to SQL Injection via the "q" parameter in the /search endpoint. The application appears to be directly concatenating user-supplied input into SQL queries.
Reports
View, manage and download security assessment reports| Report | Target | Project | Scan Date | Findings | Risk Summary | Status | Actions |
|---|---|---|---|---|---|---|---|
|
📄
Assessment #1042
Full Security Assessment |
https://example.com 93.184.216.34 |
ABC Technologies | 19 May 2024 10:30 AM |
39 2 Critical |
2
7
18
10
2
CHMLInfo
|
Completed |
|
|
📄
Assessment #1041
Full Security Assessment |
https://api.example.com 93.184.216.35 |
ABC Technologies | 18 May 2024 04:15 PM |
28 1 Critical |
1
5
10
8
4
CHMLInfo
|
Completed |
|
|
📄
Assessment #1040
Vulnerability Assessment |
https://staging.example.com 93.184.216.36 |
ABC Technologies | 17 May 2024 09:05 AM |
17 0 Critical |
0
2
6
7
2
CHMLInfo
|
Completed |
|
|
📄
Assessment #1039
API Security Assessment |
https://api.example.com/v1 93.184.216.35 |
XYZ Company | 16 May 2024 11:20 AM |
31 2 Critical |
2
6
14
6
3
CHMLInfo
|
Completed |
|
|
📄
Assessment #1038
Full Security Assessment |
https://shop.xyz.com 93.184.216.37 |
XYZ Company | 15 May 2024 02:45 PM |
22 1 Critical |
1
4
9
6
2
CHMLInfo
|
Completed |
|
|
📄
Assessment #1037
Full Security Assessment |
https://blog.acme.com 93.184.216.38 |
Acme Corporation | 14 May 2024 10:10 AM |
12 0 Critical |
0
1
4
5
2
CHMLInfo
|
Completed |
|
|
📄
Assessment #1036
Vulnerability Assessment |
https://internal.globex.com 10.0.0.15 |
Globex Inc. | 13 May 2024 06:25 PM |
8 0 Critical |
0
0
3
4
1
CHMLInfo
|
Completed |
|
|
📄
Weekly Summary Report
Summary Report |
Multiple Targets 5 target(s) |
— | 12 May 2024 11:59 PM |
— | — | Completed |
|
Reports Overview
Top Risk by Reports
View AllRecent Downloads
View All| Target | Project | Status | Authorization | Scope | Last Scan | Actions |
|---|---|---|---|---|---|---|
|
🌐
example.com
https://example.com Primary |
ABC Technologies | ● Active | 🛡️ Authorized by Client | example.com *.example.com +2 more |
19 May 2024 10:30 AM |
⋮ |
|
🌐
api.example.com
https://api.example.com |
ABC Technologies | ● Active | 🛡️ Authorized by Client | api.example.com *.api.example.com |
18 May 2024 04:15 PM |
⋮ |
|
🌐
staging.example.com
https://staging.example.com |
ABC Technologies | ● In Progress | 🛡️ Authorized by Client | staging.example.com | 19 May 2024 09:05 AM |
⋮ |
|
🌐
shop.xyz.com
https://shop.xyz.com |
XYZ Company | ● Active | 🛡️ Authorized by Client | shop.xyz.com *.shop.xyz.com +1 more |
17 May 2024 11:20 AM |
⋮ |
|
🌐
blog.acme.com
https://blog.acme.com |
Acme Corporation | ● Expired | 🛡️ Expired on 10 May 2024 | blog.acme.com | 10 May 2024 02:45 PM |
⋮ |
|
🌐
internal.globex.com
https://internal.globex.com |
Globex Inc. | ● Paused | 🛡️ Authorized by Client | internal.globex.com | Never | ⋮ |
Target Details
*.example.com
static.example.com
+2 more
Main corporate website and all related subdomains in scope for security assessment.
🔄 Retest Engine & Fix Verification
1-Click automated re-verification of reported vulnerabilities to confirm fix compliance.
| Finding Code | Vulnerability | Target | Retest Status | Last Retest | Action |
|---|---|---|---|---|---|
| SEC-001 | Missing Strict-Transport-Security (HSTS) Header | https://bank.example.com/ | FIXED | Today 10:15 AM | |
| SEC-002 | Session Cookie Missing HttpOnly & SameSite Flags | https://bank.example.com/login | STILL PRESENT | Yesterday 04:20 PM |
👁️ 24/7 Continuous Monitoring Dashboard
Automated cron schedules monitoring attack surfaces and sending instant alerts on perimeter changes.
12 Domains
Every 24 Hours
100% Operational
👥 Team & Role Access Control (RBAC)
| User Name | Email Address | Role | Status |
|---|---|---|---|
| Himanshu | admin@securescope.io | Administrator | Active |
| Security Analyst | analyst@securescope.io | Security Analyst | Active |
| Rahul Sharma | dev@securescope.io | Developer | Active |
🔌 Integrations & Webhooks
Connect SecureScope to your issue tracker and alert channels.
Jira Software
Auto-create Jira tickets for P0/P1 findings.
Slack Alerts
Receive instant Slack webhooks on critical vulnerabilities.
Custom Webhook
HTTP POST payloads to your API endpoint.
🔑 Developer API & JWT Tokens
REST API token for CI/CD pipeline security integration.
📜 ScopeGuard Audit Trail & Activity Logs
⚙️ Platform Security Settings
💳 License & Enterprise Subscription
Current Plan: Enterprise SaaS Unlimited Plan
Active • Self-Hosted cPanel / VPS License