WebDefect
FULL-SPECTRUM ATTACK SURFACE DEFENSE

Comprehensive Cyber Defense Built for Enterprise Scale

From perimeter DNSSEC and TLS 1.3 negotiation to deep API endpoint discovery and client-side DOM vulnerabilities, WebDefect runs 645 distinct deterministic checks across 17 automated modules to give you total visibility with zero guesswork.

645
Automated Checks
17
Inspection Modules
<60s
Audit Duration
0%
Disputed Attribution
EASM IntelligencePhase 01 & 0245+ Asset Vectors

External Attack Surface Management (EASM)

Autonomous perimeter discovery with zero wildcard guesswork

Continuously discovers and catalogs every public-facing asset linked to your organization. Every subdomain, DNS record, IP address, and open port is corroborated with cryptographic certificate evidence and live DNS validation — eliminating disputed shadow assets.

Core Inspection Coverage

  • Subdomain Enumeration & SAN Parsing
  • Cloud Storage Bucket Discovery (S3, GCS, Azure)
  • Orphaned CNAME & DNS Takeover Detection
  • Public Service Port & Banner Fingerprinting
  • Shadow IT & Deprecated Staging Hostnames

Deterministic Methodologies

Certificate Transparency Logs
Correlates historic and current Subject Alternative Names (SANs) from all major CT logs.
DNS Zone & Record Enumeration
Inspects A, AAAA, CNAME, MX, TXT, SRV, and CAA records across authoritative nameservers.
Cloud Bucket Takeover Probing
Verifies whether dangling CNAMEs point to deprovisioned Amazon S3, Azure Blob, or Google Cloud buckets.
Deterministic RatingsMathematical Scoring645 Distinct Checks

Cryptographic Cyber Posture Ratings

0–100 security score backed by verifiable proof and CVSS 4.0

Replaces subjective questionnaire scores and disputed IP-attribution algorithms with concrete mathematical ratings. Every deduction is tied to raw cryptographic handshakes or captured HTTP headers with zero attribution uncertainty.

Core Inspection Coverage

  • CVSS 4.0 Base Scoring Deductions
  • A+ through F Categorical Letter Grades
  • Tamper-Evident SHA-256 Audit Records
  • Active 2-Stage Verification Re-Probing
  • Zero Shared IP False-Positive Disputes

Deterministic Methodologies

Deterministic Deductions
Scores start at 100; deductions calibrate directly to severity (-25 Critical, -15 High, -7 Medium, -3 Low).
Secondary Confirmation Stage
All flagged conditions undergo automated second-stage probing to eliminate transient network blips.
Historical Drift Tracking
Calculates exact delta scores between sequential scans to highlight newly introduced flaws.
Transport LayerPhase 04Grade A+ Verification

TLS 1.3 & Certificate Auditing

Exhaustive cryptographic handshakes and cipher suite evaluation

Performs deep SSL/TLS handshakes verifying AEAD cipher suites, Perfect Forward Secrecy (PFS), protocol deprecation (TLS 1.0/1.1 denial), OCSP stapling, CAA DNS authorization, and Chromium HSTS preloading compliance.

Core Inspection Coverage

  • TLS 1.3 & 1.2 Protocol Negotiation
  • AEAD Cipher Suites (AES-GCM, ChaCha20-Poly1305)
  • Certificate Chain of Trust & Revocation (OCSP/CRL)
  • HSTS Preload List Inclusion Verification
  • DNS Certification Authority Authorization (CAA)

Deterministic Methodologies

Deprecated Protocol Denial
Ensures SSLv2, SSLv3, TLS 1.0, and TLS 1.1 handshakes are immediately rejected.
Forward Secrecy Verification
Validates ECDHE and DHE key exchange parameters to protect historical traffic from future key compromises.
Certificate Expiry & SAN Integrity
Flags certificates expiring within 30 days, weak RSA key lengths (<2048-bit), or untrusted roots.
Identity DefensePhase 03Zero Brand Spoofing

DNSSEC & Anti-Spoofing (DMARC/SPF/DKIM)

Cryptographic domain trust and email spoofing prevention

Validates DNSSEC chains to prevent cache poisoning, while thoroughly inspecting email authentication policies under RFC 7208 SPF lookup limits, DKIM selector alignment, and strict DMARC rejection enforcement.

Core Inspection Coverage

  • DNSSEC Cryptographic Chain (RRSIG, DNSKEY, DS)
  • RFC 7208 SPF 10-Lookup Limit Validation
  • DMARC Policy Hardening (p=reject / p=quarantine)
  • DKIM Key Size & Signature Alignment
  • BIMI (Brand Indicators) & MTA-STS Strict Transport

Deterministic Methodologies

SPF Lookup Recursion Limit
Parses includes and redirects to guarantee lookup count remains under the RFC 7208 ceiling of 10.
DMARC Enforcement Audit
Detects weak p=none configurations that allow unauthorized threat actors to send forged domain emails.
DNSSEC Trust Anchor Verification
Traces DS records back to root zone trust anchors ensuring query responses cannot be spoofed.
API & ExposuresPhase 08 & 09Active Verification

Deep API & Sensitive Exposure Probing

Non-intrusive scanning for leaked keys, git repos, and internal endpoints

Safely audits public infrastructure for accidentally exposed developer artifacts, exposed environment files, Spring Actuator endpoints, Swagger UI documentation, and unprotected GraphQL schemas.

Core Inspection Coverage

  • Exposed Version Control (/.git, /.svn, .gitignore)
  • Environment Files & Private Keys (/.env, id_rsa)
  • Spring Boot Actuator & Diagnostic Paths (/health, /env)
  • OpenAPI / Swagger UI Spec Exposure
  • GraphQL Introspection Query Probing

Deterministic Methodologies

Git Metadata Leaks
Confirms whether HEAD and index files are accessible over HTTP, risking full source code reconstruction.
Introspection Detection
Verifies whether production GraphQL endpoints reveal their complete internal schema to unauthenticated users.
Backup & Dump Files
Tests for database dumps (.sql, .dump), archive files (.zip, .tar.gz), and editor swap files (.swp).
Executive ReportingExecutive ReadyInstant PDF Export

Executive PDF & Board Dossiers

Instant download of board-ready security audit dossiers

Generates comprehensive security assessment reports formatted for CISOs, board directors, and cyber insurance underwriters. Includes complete CVSS 4.0 scoring, compliance mappings, and turnkey developer remediation snippets.

Core Inspection Coverage

  • SOC 2 Type II & ISO 27001 Control Cross-Walks
  • PCI-DSS v4.0 & NIST CSF 2.0 Mapping
  • Turnkey Nginx, Caddy, Cloudflare Config Fixes
  • Cryptographic Hashes for Tamper-Evident Proof
  • Developer-Friendly CVSS 4.0 Vector Strings

Deterministic Methodologies

Compliance Cross-Walks
Maps every technical vulnerability directly to specific regulatory requirements (e.g. ISO 27001 Annex A.8.8).
Copy-Paste Remediation Snippets
Generates tested configuration directives ready to paste into web servers and CDN edge rules.
High-Resolution Visual Charts
Includes category radar diagrams, severity histograms, and trend trajectories for presentations.

Experience Deterministic Perimeter Intelligence

Audit your domain now. No agent software to install, no invasive penetration load, and zero long-term sales calls required.