Vulnerability Scan
Weaknesses on the systems you expose to the internet, and how to act on them.
Loading documentation…
Vulnerability Scan checks the systems you expose to the internet for known weaknesses, so you can fix them before someone else finds them.
A scan runs every night against the targets on your account. It checks only the targets you have added. If you add a domain, for example, its subdomains are not included automatically. Subdomains are covered by Recon Scan.
The page follows the same layout as Dark Web Scan:
Below the graph, each vulnerability is listed with its CVSS level, so you can see at a glance which issues matter most. CVSS is a standard severity rating, running from Low to Critical.
Select a vulnerability to open a panel with a short description of the issue and the scanner logs that found it. This is available to subscribers only, not on free trials.
Each vulnerability also has a Detailed Remediation Advice button. It gives you a summary of the problem, the risks it may create and recommended steps to fix it. Only the description of the vulnerability is used to produce this advice. None of your own data is shared.
If you believe an issue is a false positive, or you do not consider it a real risk to you, select Acknowledge. The issue stays visible in HackRisk but no longer counts towards your HackRisk Score.
Below the main list, a second section shows vulnerabilities found by Recon Scan. It is there for convenience, so you can see everything in one place. Fuller detail on those issues is in the Recon Scan section.
The Scan Targets section lists every target currently set up for scanning. We add one target automatically: the domain you signed up with.
For each target you will see coloured counters, one per CVSS level.
Subscribers can add one extra scan target at no additional cost. Targets can be websites, IP addresses and other services that face the internet.
You can also scan internal devices by installing a scanning agent on them. Guidance for adding an internal target is available through the link in the portal.
Scans run automatically each night. As a subscriber, you can also start a scan of any target on demand.
The final section of Vulnerability Scan is Reports. These are monthly reports in a legacy format, with detailed information on the vulnerabilities found during each reporting period.