The Attack Surface and Vulnerability Scanner is part of the Plus and Premium packages. You can compare packages on our pricing page.
Add what you want scanned
- Open the Threat Intelligence Portal and go to Attack Surface in the menu.
- Add the assets you want to keep an eye on, such as a domain or a public IP address.
- Save your target so it appears in your list.
To make sure people only scan assets they own, new targets may need to be approved before scanning. If a target stays pending, ask your Q-Feeds administrator to approve it.
Start a scan
Select a target and start a scan. You can run a scan on demand, or schedule recurring scans so your attack surface is checked regularly without you having to remember.
Understand the findings
When the scan finishes you get a list of findings. For each one you can see:
- The asset it affects.
- A severity rating so you know what to fix first.
- A short description of the issue and guidance on how to resolve it.
What next
Work through the findings from the highest severity down. Re-run the scan after you make changes to confirm the issue is resolved.