Services
Understand veyrisk
PricingDemo consoleContact
EN
Sign inBuy now
■ Scope

What veyrisk checks.

veyrisk combines several testing methods. Some run daily without any action on your part, others only after your proof of ownership or your consent. Here you can see what is checked and when.

■ Principle

Passive and active

Passive checks behave like a normal visitor: they retrieve publicly available information such as DNS records, certificates or the response of a website. They run daily for every domain you enter.

Active checks go further. They look for open ports and test services for known vulnerabilities. These checks only run once you have proven via a DNS record that the domain belongs to you. veyrisk verifies this proof again before every run.

■ External attack surface

Web presence and domains

  • Subdomains from public certificate logs and DNS, so that forgotten systems show up too
  • TLS certificates: expired, expiring soon, untrusted, faulty encryption
  • Redirect from HTTP to HTTPS and security headers such as HSTS, Content Security Policy and clickjacking protection
  • Publicly reachable admin interfaces, development and test systems, disclosed software versions
  • Email protection via SPF and DMARC, so that your domain cannot be misused for forged emails
  • After proof of ownership: open ports with risky services such as remote maintenance, databases or file shares
■ Vulnerability management

Servers and services

After proof of ownership, veyrisk checks the public addresses of your systems with OpenVAS, a widely used vulnerability scanner with a daily updated database of known vulnerabilities. Depending on the plan, this scan runs monthly or weekly. Only findings the scanner detected with high confidence are included. Better a gap in the report than a false alarm your team has to chase.

■ Web app scanning

Web applications and APIs

  • Typical vulnerabilities from the OWASP Top 10, such as injection, cross-site scripting and broken access control
  • Passive checks always, active tests only with your explicit consent and on domains with proof of ownership
  • Sign-in with a test account, so that areas behind the login are checked as well
  • APIs based on an OpenAPI or Postman file, scans can also be started from your build pipeline
■ Cloud and identities

Cloud accounts and Microsoft 365

  • AWS, Microsoft Azure and Google Cloud: publicly reachable storage and services, overly broad permissions, missing logging
  • Microsoft 365 and Entra ID: accounts without multi-factor sign-in, too many global administrators, risky settings
  • Connection with read-only permissions only. veyrisk changes nothing in your configuration.
■ Frequency

How often checks run

CheckPrerequisiteFrequency
Passive check of all domainsDomain entereddaily
Port checkProof of ownershipweekly or daily, depending on plan
Vulnerability scan with OpenVASProof of ownershipmonthly or weekly, depending on plan
Web app scanningProof of ownership, your consent for active testsper plan and on demand
Cloud and Microsoft 365Read-only accessregularly and on demand
■ Free first scan

What does your attack surface look like?

We scan your external attack surface for free and walk you through the results in 30 minutes.