Network exposure, hardening checklists, and weaponization context. Identify weak configurations that threat actors exploit.
Analyze HTTP headers, TLS configuration, certificates. Enter a domain or HTTPS URL.
Common weak defaults in web apps, databases, services. Check if your environment has these.
Kerberos, delegation, permissions. Source: CISA AA24-008A, NIST SP 800-53 IA-2/IA-4.
IAM, storage, secrets management. Audit your S3/Azure/GCP for these conditions.
Configuration weaknesses exploited by active threat campaigns. Sourced from CISA KEV + MITRE ATT&CK.