WebDefect
DETERMINISTIC CYBER POSTURE SPECIFICATION

The 17-Module Inspection & Scoring Methodology

WebDefect operates on a strictly non-destructive, read-only inspection protocol. Every reported finding is backed by cryptographic evidence, raw HTTP network traces, and secondary active verification re-probes — completely eliminating disputed third-party scoring.

100% NON-DESTRUCTIVE

Passive & RFC-Compliant

We never execute intrusive exploit payloads, brute-force credentials, or modify database states. Every request complies with standard HTTP/2, RFC 8446 TLS, and RFC 1035 DNS specifications.

ZERO ATTRIBUTION BIAS

Cryptographic Host Proof

Legacy rating tools penalize domains for shared AWS/Cloudflare IP addresses that belong to other tenants. We authenticate host identity directly via TLS SNI and SAN certificate chains.

ACTIVE 2-STAGE RE-PROBE

Near-Zero False Positives

Before any finding affects a domain's cyber rating, our engine conducts an automated secondary confirmation re-probe. Flaky connection timeouts and CDN edge hiccups are automatically discarded.

CYBER RATING ARCHITECTURE

The 0–100 Weighted Scoring Algorithm

Rather than arbitrary penalty drops, our algorithm evaluates domains from a baseline of 100 points, applying calibrated reductions based on the CVSS 4.0 base severity, exploitability vector, and scope of each verified issue.

A+95 – 100

Hardened Enterprise Defense

A85 – 94

Strong Perimeter Posture

B70 – 84

Acceptable, Minor Hardening Required

C55 – 69

Moderate Risk, Inadequate Headers / DMARC

D40 – 54

High Risk, Critical Exposure Identified

F< 40

Severe Vulnerability / Immediate Threat

MATHEMATICAL DEDUCTION FORMULADeterministic CVSS 4.0 Mapping

CRITICAL (CVSS 9.0–10.0): -25 pts deduction (e.g., exposed .git repo, unauthenticated database backup, active code injection)

HIGH (CVSS 7.0–8.9): -15 pts deduction (e.g., completely absent Content-Security-Policy, plaintext password post, TLS 1.0 active)

MEDIUM (CVSS 4.0–6.9): -7 pts deduction (e.g., DMARC p=none policy, missing SameSite on session cookies, HSTS < 6 months)

LOW (CVSS 0.1–3.9): -3 pts deduction (e.g., server version disclosure banner, missing Permissions-Policy)

COMPREHENSIVE SPECIFICATION

Detailed Inspection Phase Catalog

Every scan systematically executes the following phases in automated progression, verifying headers, cryptographic certificates, DNS records, and exposed endpoints.

PHASE 01Perimeter Mapping

External Exposure

45+ automated checksWeight: 10%

Maps subdomains, public IP ranges, open service ports, CDN edges, cloud asset buckets, and Certificate Transparency (CT) SAN entries. Every identified asset is corroborated across DNS and TLS handshake proofs — never expanding arbitrary wildcards.

Standards:RFC 8482Certificate Transparency LogsDNS Zone Records
PHASE 02Perimeter Mapping

Site Intelligence

35+ automated checksWeight: 5%

Passively traverses the target surface, following HTTP redirect chains, cataloging endpoints, embedded scripts, forms, API references, and external trust anchors without triggering rate limits or disruptive load.

Standards:RFC 9110W3C Resource DiscoveryRobots & Sitemap Parsing
PHASE 03Cryptographic & Protocol

Domain Infrastructure

38+ automated checksWeight: 15%

Inspects authoritative DNS servers for DNSSEC cryptographic chain validation (RRSIG, DNSKEY, DS), CAA record presence, RFC 7208 SPF lookup limits (<10 lookups), DKIM selector alignment, and strict DMARC enforcement (p=reject).

Standards:RFC 7208 (SPF)RFC 7489 (DMARC)RFC 4033-4035 (DNSSEC)RFC 8659 (CAA)
PHASE 04Cryptographic & Protocol

Connection Integrity

42+ automated checksWeight: 15%

Performs full cryptographic handshakes checking protocol version deprecation (TLS 1.0/1.1 denial), cipher suite strength (AEAD algorithms, ChaCha20/AES-GCM), Perfect Forward Secrecy (PFS), OCSP stapling, SAN validity, and HSTS preload eligibility.

Standards:RFC 8446 (TLS 1.3)NIST SP 800-52r2Mozilla Modern TLS Guidelines
PHASE 05Application Defense

Web Protection

36+ automated checksWeight: 15%

Evaluates mandatory security headers: Content-Security-Policy (CSP Level 3 strict-dynamic, script-src, object-src), Strict-Transport-Security (HSTS max-age >= 31536000 with includeSubDomains and preload), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.

Standards:W3C CSP Level 3RFC 6797 (HSTS)W3C Permissions Policy
PHASE 06Application Defense

Browser Controls

10+ automated checksWeight: 10%

Parses Set-Cookie directives to enforce Secure, HttpOnly, and SameSite=Strict/Lax flags on session identifiers. Inspects Cross-Origin Resource Sharing (CORS) policies to flag wildcard origin allowances with Access-Control-Allow-Credentials.

Standards:RFC 6265bis (Cookies)W3C Cross-Origin Resource Sharing
PHASE 07Application Defense

Delivery Layer

7+ automated checksWeight: 5%

Analyzes Cache-Control, Surrogate-Control, and Pragma directives to ensure sensitive data, authenticated sessions, and private API responses cannot be stored on shared intermediary CDN edge caches.

Standards:RFC 9111 (HTTP Caching)Cloudflare/Fastly/Akamai Best Practices
PHASE 08Exposures & Vulnerabilities

Resource Exposure

64+ automated checksWeight: 20%

Safely probes for exposed version control directories (/.git/config), environment variable files (/.env), database backups, Spring Boot Actuator health endpoints, public Swagger/OpenAPI docs, and GraphQL introspection endpoints.

Standards:OWASP API Security Top 10OWASP ASVS v4.0CWE-200 / CWE-538
PHASE 09Exposures & Vulnerabilities

Code Integrity

40+ automated checksWeight: 10%

Scans client-side script bundles for exposed source maps, embedded developer tokens, hardcoded API secrets, and extracts frontend library versions to cross-reference against real-time NIST NVD and OSV vulnerability feeds.

Standards:NIST National Vulnerability DatabaseOpen Source Vulnerabilities (OSV)
PHASE 10Application Defense

Access & Sessions

24+ automated checksWeight: 5%

Assesses client authentication forms for plaintext submission risk over insecure channels, missing CSRF tokens, unvalidated redirect targets, and client-side password handling policies without submitting actual credentials.

Standards:OWASP Top 10 A07 (Auth Failures)RFC 6749 (OAuth 2.0 Security BCP)
PHASE 11Information Disclosure

Application Assessment

26+ automated checksWeight: 5%

Audits response banners (Server, X-Powered-By, X-AspNet-Version), stack trace leakage in 404/500 handlers, internal IP disclosure in headers, and debug comments embedded within client HTML markup.

Standards:OWASP WSTG-INFO-02CWE-209 (Generation of Error Message with Sensitive Info)
PHASE 12Discoverability & Reach

SEO, GEO, AOE

20+ automated checksWeight: 5%

Validates sitemap structure, canonical tag consistency, hreflang declarations, structured data markup, robots.txt directives, and social media card meta tags to ensure accurate discoverability across search, AI-generated content surfaces, and answer engines.

Standards:Google Search CentralSchema.org Structured DataOpen Graph Protocol
PHASE 13Performance & Sustainability

Performance Health

18+ automated checksWeight: 5%

Measures Core Web Vitals indicators, HTTP Archive performance benchmarks, image format optimization (WebP/AVIF), CDN delivery efficiency, and green hosting signals to evaluate load-time posture and environmental footprint.

Standards:W3C Web PerformanceHTTP Archive AlmanacGreen Web Foundation
PHASE 14Privacy & Intelligence

Privacy Posture

22+ automated checksWeight: 5%

Detects GDPR/CCPA consent mechanisms, AI-generated content signals, typosquatting domain registrations, and brand impersonation patterns to evaluate compliance posture and brand protection coverage.

Standards:GDPR Article 7CCPA / CPRAICANN UDRP
PHASE 15Continuous Posture

Security Changes

14+ delta checksWeight: Telemetry

Compares current cryptographic fingerprints against the organization's historic baseline to identify new asset additions, modified TLS certificates, removed headers, or reappeared vulnerabilities.

Standards:Continuous Posture Monitoring (CPM)SOC 2 CC8.1 / CC6.8
PHASE 16Deterministic Proof

Finding Confidence

2-Stage Active Re-ProbeWeight: Verification

Every identified condition is subjected to a secondary active verification re-probe. Any intermittent or uncorroborated anomaly is purged, guaranteeing 100% reproducible evidence with raw HTTP response traces.

Standards:Deterministic Evidence StandardISO 27001 A.12.6
PHASE 17Deterministic Proof

Risk Intelligence

Algorithmic AggregationWeight: Unified

Correlates disparate findings into root-cause clusters, normalizes severity using CVSS 4.0 exploitability vectors, and applies our mathematical grading formula to compute the final 0–100 cyber rating.

Standards:FIRST CVSS v4.0 SpecificationNIST Risk Management Framework

Assessment Scope & Explicit Operational Boundaries

WebDefect is engineered specifically for External Attack Surface Management (EASM) and non-destructive perimeter cyber posture evaluation. To preserve target safety and maintain legal standards, the following explicit boundaries apply:

  • Public Surface Only: The engine audits assets reachable over the public Internet. Private VPCs, internal company intranets, and authenticated sessions requiring customer logins are strictly excluded.
  • No Exploit Delivery: We identify exposed vulnerabilities (such as publicly readable .env files or missing CSP policies) by observing standard HTTP response codes and headers, without executing intrusive injection attacks or modifying server state.
  • Point-in-Time Assurance: External scan results represent the deterministic state at the precise moment of execution. Continuous automated scheduled scanning is recommended to capture configuration drift and certificate renewal events.
Have questions regarding custom enterprise vulnerability scoring?Run Live Perimeter Audit →