โกNuclei
9,000+ community templates โ CVE exploitation, exposed admin panels, default credentials, takeovers, misconfigurations.
NEW9k templates
๐ท๏ธOWASP ZAP DAST
Active web-app testing โ spider + active scan, XSS, SQLi, CSRF, parameter fuzzing against running apps.
NEWDAST
๐OpenVAS / Greenbone
50,000+ network NVT checks โ CVE detection, service version fingerprinting, authenticated deep scans.
NEW50k NVTs
๐ก๏ธVulnerability Assessment
Multi-engine vuln scan: agent + Nuclei + ZAP + OpenVAS + CVE matching with EPSS prioritisation.
VAPT
๐Network Discovery
Internal port scanning, service detection, banner grabbing, risky-port alerting.
Network
๐SSL/TLS Analysis
Certificate chain validation, weak ciphers, Heartbleed/ROBOT, expiry alerts at 30/14/7 days.
TLS
๐งEmail Security
SPF, DKIM, DMARC verification. Header analysis, open relay detection, domain hardening.
Email
๐API Security
REST endpoint scanning, auth-bypass testing, rate-limit checks, sensitive data leak detection.
API
๐DNS Security
Subdomain enumeration via crt.sh, takeover detection (Heroku, S3, GitHub Pages), DNSSEC, glue records.
DNS
๐WordPress Scanner
8 WordPress checks โ XML-RPC, REST user enum, version disclosure, config backups, debug logs, plugin detection.
NEWCMS
๐ปCode & SAST
Static analysis across Python, JS, Java, Go, PHP โ SQLi, XSS, hardcoded secrets, insecure deserialisation.
SAST
๐๏ธDatabase Security
MySQL, Postgres, MongoDB, MSSQL, Oracle, Redis โ auth, encryption, version, backup verification.
DB
๐ง AI SOC
Autonomous threat triage, MITRE ATT&CK mapping, playbook suggestions, false-positive learning.
AI
๐กThreat Intel Feeds
109,000+ live IOCs from abuse.ch (Feodo, URLhaus, MalwareBazaar). EDR event correlation hourly.
109K IOCs
๐Dark Web Monitoring
HIBP k-anonymity credential checks, domain breach exposure (HIBP Enterprise), automatic SOC case creation.
NEWHIBP
๐Domain & Brand Monitor
Typosquat variants, DNS resolution checks, CT-log lookalike detection, real-time phishing alerts.
NEWBrand
๐Certificate Lifecycle
Cert inventory across scope domains, expiry alerts at 30/14/7/1 days, weak-cipher detection.
NEWTLS
๐EPSS Scoring
Live FIRST.org EPSS feed โ vulnerabilities ranked by exploit probability, not just CVSS.
NEWEPSS
๐Risk Register
Likelihood ร impact scoring, treatment plans, owner assignment, review dates. Auditor-ready PDF export.
NEWISO 27001
๐Cyber Maturity (NIST CSF 2.0)
25-question assessment, 6-domain scoring (govern + identify + protect + detect + respond + recover), 90-day roadmap.
NEWNIST CSF
๐คVendor Risk Assessment
12-question vendor questionnaire, automated risk scoring, SOC 2 CC9.2 evidence, overdue review alerts.
NEWCC9.2
๐ฃPhishing Simulation
3 templates (IT alert, password expiry, invoice). Click tracking, awareness landing, department reports.
NEWCC2.2
๐Security Awareness Training
6 modules: phishing, password hygiene, DPDP basics, IR 101, device security, OWASP secure coding.
NEWTraining
๐Executive Dashboard
CISO-level view in plain English. Posture, risk in rupees, top 5 risks, compliance per framework, 6-month trend.
NEWCISO
๐Trust Portal
Vanta-style public compliance page. Live scores from continuous monitoring. Share with customers + auditors.
NEWPublic
๐ชOutbound Webhooks
HMAC-signed webhooks for 7 event types โ vuln.created, sla.breached, dark_web.new, scan.complete, etc.
NEWIntegrations
๐Public REST API v1
Bearer-token auth, /me /vulnerabilities /assets /incidents /dashboard endpoints. Per-key revocation + scopes.
NEWAPI
๐๏ธAsset Inventory + CMDB
Asset metadata (owner, criticality, environment, EOL date) + per-asset scan scheduling on hourly/daily/weekly cadence.
NEWCMDB
๐ฅExternal VAPT Import
Import pen-test findings via JSON. Track remediation, generate evidence that the VAPT was conducted and addressed.
NEWImport
๐ท๏ธWhite-label MSP Reporting
Custom brand name, logo, primary color, footer text on all PDF reports. Per-customer white-label settings.
NEWMSP