Q: Interested in top tier, but have few questions; 1.
Does it also scan the PII transactions and cookie content issues?
2. Do you have malware scanning and protection?
3. Do you scan Apps, Repo and codebase?
4. Does it scan the server roots, like AWS buckets and S3 containers?
5. In the report, does it only show the possible vulnerability, or does it also give information on how to fix it?
dada_
Jun 27, 2024A: Hello,
1. It does not, in the future we will also scan for Cookies;
2. It does scan for malwares but we do not offer a software solutions to protect against it, we are not a cybersecurity "tool" like an antivirus or EDR etc;
3. We scan webapp from external, we don't scan codebases and repos;
4. We do not :(;
5. We also give the remediations information on the "Improve" section of the platform that is bound with the reports
So what your does actually ?
Hi @SwapnilSays
- Scanning for known vulnerabilities
- Presence check and correct configuration of DKIM/SPF parameters in the email server
- Data breaches for email addresses
- SSL certificate validity check
- Checking the correct configuration of the SSL certificate
- Sensitive Directory Control Exposed
- Checking the existence of exposed sensitive subdomains
- Domain reputation check
- Controlling open and vulnerable ports
- Phishing look-alike domain existence check