Continuous perimeter intelligence.
Real evidence. Zero guesswork.
Replace stale rating delays and disputed algorithms. WebDefect runs an exhaustive multi-phase audit with hundreds of deterministic checks, real raw HTTP evidence, and turnkey remediation code.
- No Agent Installation Required
- Evidence-Backed Findings
- Safe, Read-Only Inspection
- Near-Zero False Positives
38
Subdomains
645
Checks Run
0
Critical CVEs
Active Autonomous Phase ChecksClick to inspect evidence
TLS_AES_256_GCM_SHA384 • 0-RTT • Perfect Forward SecrecyComprehensive Cyber Defense Built for Scale
From perimeter DNSSEC to client-side DOM vulnerabilities, WebDefect runs deterministic checks across every layer of your attack surface to give you total visibility.
External Attack Surface (EASM)
Autonomous mapping of exposed subdomains, DNS SAN records, open ports, cloud storage buckets, and orphaned shadow IT assets.
Cryptographic Cyber Ratings
Evidence-backed 0-100 security scoring and A-F grades. Built on raw HTTP proof and cryptographic certs — zero attribution disputes.
TLS 1.3 & Certificate Auditing
Deep handshake negotiation verifying AEAD ciphers, forward secrecy, OCSP stapling, CAA DNS authorization, and HSTS preloading.
DNSSEC & Anti-Spoofing (DMARC)
Strict DMARC policy validation, SPF syntax lookup limits under RFC 7208, DKIM alignment, and cryptographic DNSSEC validation.
Deep API & Leaked Secret Probing
Safely probes for exposed /.git directories, /.env secrets, Spring Actuator paths, Swagger docs, and GraphQL introspection endpoints.
Executive PDF & Board Dossiers
Instant download of board-ready security assessment reports with CVSS 4.0 scoring, compliance mappings (SOC 2, ISO 27001), and remediation.
How WebDefect Audits Your Perimeter
Unlike legacy crawlers that guess or make superficial requests, our engine executes an autonomous, multi-phase pipeline grounded in deterministic cryptographic verification and safe, read-only inspection.
Perimeter Recon & Asset Mapping
Maps the complete external footprint: subdomains, DNS records, open ports, CDNs, and technology stacks.
External Exposure
Subdomain enumeration, certificate SAN parsing, CDN & cloud asset correlation
Analyzes Certificate Transparency logs, DNS zone records, SAN expansions, and cloud infrastructure associations without brute-force disruption.
Site Intelligence
Visible surface mapping, endpoints, embedded forms, client scripts
Crawls HTML entry points, parses document dependencies, detects form actions, and discovers links to internal resources.
Application Assessment
CMS, web servers, backend frameworks, CDN edge proxies
Passively finger-prints headers, cookies, script hashes, and DOM signatures to identify WordPress, Next.js, Cloudflare, Nginx, and more.
Engineered to Replace Legacy Rating Monopolies
Traditional security rating firms rely on IP attribution heuristics and disputed algorithms. Bitsight refresh cycles can take up to 30 days; UpGuard blends active scanning with vendor questionnaires. WebDefect introduces deterministic, on-demand cyber posture backed by evidence-backed proof and instant remediation.
| Capability | WebDefect (WebDefect) | SecurityScorecard / Bitsight | UpGuard / Detectify | Intruder / Censys |
|---|---|---|---|---|
| Evidence Determinism | 100% Evidence-backed proof — raw HTTP response headers & cryptographic handshakes | Heuristic estimation & disputed IP attribution | Partially evidence-backed; blends active scanning with vendor questionnaires | Vulnerability signatures, limited raw evidence |
| Scan Execution Speed | On-demand execution — results available as soon as the pipeline completes | Near real-time (24–48h) for own scorecard; Bitsight can take up to 30 days | Active scanning with scheduled crawls; on-demand re-scan available | Queued penetration runs (several minutes) |
| False-Positive Rate | Near 0% (Automated 2-stage active verification re-probe) | Frequent disputes over shared cloud/CDN IP addresses | Manual dispute workflow required | Moderate false positive rate on complex APIs |
| Remediation Engineering | Turnkey copy-paste snippets (Nginx, Caddy, Cloudflare, AWS) | Vague high-level guidance & external help center links | Generic remediation guidelines | Standard advisory links |
| Deep API & Secret Probing | Probes Swagger, GraphQL, .git, .env, Actuator paths safely | Limited application-layer depth; focused on IP/network attribution & supply-chain vendor risk | Active web scanning with breach data feeds; limited depth on API/endpoint probing | Focuses on network CVEs, light secret detection |
| Pricing & Accessibility | Instant public scan + transparent pricing (free tier available) | Self-serve free tier available; enterprise contracts $15k–$50k+/yr | Self-serve plans from ~$1,599/mo; enterprise contracts $25k–$85k+/yr | Monthly paid plans from $149/mo (Essential) to $499/mo (Pro) |
| Continuous Baseline Diffing | Deterministic change tracking with exact configuration diffs | Score fluctuations without exact header diffs | Alerts on asset additions/removals | Alerts on new ports/services |
Evidence First. Ready-to-Deploy Code.
Security teams and developers love WebDefect because we don't just throw alert noise over the wall. Every issue includes the raw network proof and the exact configuration lines needed to fix it.
Exposed Git Version Control Repository (/.git/config)
The root or subdirectory exposed a readable Git repository metadata file. Attackers can reconstruct the complete source code, embedded API keys, and commit history.
HTTP/2 200 OK
content-type: text/plain
content-length: 312
[core]
repositoryformatversion = 0
filemode = true
bare = false
logallrefupdates = true
[remote "origin"]
url = git@github.com:target-corp/core-api.git# Block all hidden and dot-files from web root
location ~ /\.(?!well-known) {
deny all;
return 404;
}SIMPLIFIED ENTERPRISE WORKFLOW
From Target Entry to Board-Ready Audit — On Demand
No complex agent deployment, no invasive testing, and zero impact on your production availability.
Define Target Perimeter
Input your primary root domain, subdomains, or public CIDR blocks. Zero agent installation or credential access needed.
Autonomous 17-Module Execution
Our engine executes 645 safe, read-only checks across TLS 1.3, DNSSEC, DMARC, CSP, API discovery, and dependency CVE feeds — on demand, no scheduling required.
Deterministic Proof & Remediation
Inspect live findings with raw HTTP traces, download board-ready executive PDF dossiers, and copy-paste exact fix configurations.
BUILT FOR SECURITY-CONSCIOUS TEAMS
The Stack Your Infrastructure Already Trusts
WebDefect scans sites running on the same infrastructure and CDN providers your team relies on every day.
Distinct Automated Checks
Every scan runs 645 distinct security checks drawn from the same canonical inventory — each backed by captured HTTP, TLS, or DNS evidence. Nothing estimated, nothing attributed.
Inspection Modules
Replacing stale rating agency batch cycles with on-demand verification the moment engineers commit fixes — no scheduled windows, no waiting.
Compliance Frameworks
Every finding is automatically mapped to OWASP Top 10, PCI DSS v4, ISO 27001, and NIST CSF — with pass/fail evidence your auditors can download.
Eliminate Perimeter Blindspots on Demand
Verify your DNSSEC, TLS 1.3 ciphers, DMARC alignment, exposed APIs, and sensitive credentials today. No sales calls, no contracts, and zero credit card required.