Vulnerability scan
An automated check for known weakness signatures; it is quick and cheap, but it can raise false alarms and does not see flaws in business logic.
- 01
Why it matters
Vulnerability scanning is the cheapest way to look for known weaknesses quickly and regularly across a wide surface: it catches outdated software, wrong settings and exposed services. In systems that change all the time, regular scans show early whether a newly published flaw affects you. Findings still need manual confirmation before they are taken as certain.
- 02
Example
A monthly scan reports that an administration interface on a server is reachable from the internet and runs a version with a known flaw. The team first restricts the interface to the company network, then updates the version.
- 03
Common mistake
Presenting a scan report as a “security test” as it is. Scans produce false alarms and do not see business logic flaws; they complement a penetration test rather than replace it.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.