Scanners
- Home
- Advanced Testing
- Scanners
Industry-standard scanners, packaged so small businesses and lean SaaS teams can actually run them
The scanners larger platforms offer, in a clear on-demand workflow you can start in minutes
PortWarden runs open-source and industry-standard scanners used across the industry, including OpenVAS, OWASP ZAP, Nmap, TLS analysis, web discovery, and targeted validation tools. Deeper recon and exploit validation options are available too. Each scanner is a clear on-demand job with normalized findings, evidence, and guidance, so small businesses and lean SaaS teams do not need an in-house security analyst to start.
Buy what you need. Run it against your authorized assets. Get back a finding report a real person can act on. Escalate to a human security professional when the situation calls for it.
Start FreeWhy a list of scanners matters
- Industry-standard tools, not a black-box secret scanner
- Every scan produces normalized, auditable evidence
- Our AI compares each result to known vulnerability databases
- Guided remediation walks your team through the fix
- Human security professionals are available when needed
Scanners are the starting point. AI analysis and human review make findings useful.
A raw scanner dump is noise. PortWarden turns each scan into a prioritized, plain-English finding with remediation steps, and a path to a human expert when you want a second look.
1. Run the right scanner
Pick a scanner that matches the question you need answered, such as surface mapping, port discovery, TLS posture, web vulnerability review, or targeted validation. Then run it against your authorized assets.
2. AI compares results to vulnerability databases
PortWarden's AI cross-references each result against known vulnerability databases and threat intelligence, cuts noise, prioritizes by real-world risk, and explains each finding in language your team can act on.
3. Guided remediation, step by step
For each finding, PortWarden explains what to change, why it matters, and how to verify the issue is closed after remediation.
4. Retest to confirm the fix
Rerun the same scanner against the same scope and confirm the issue is gone. Every retest is stored as evidence so you have a trail of what changed and when.
5. Human security professionals on call
When a finding needs deeper judgment, or something looks like an active issue, escalate to a qualified human security professional for targeted validation, deeper testing, or a quote-based penetration test.
6. Evidence and audit trail
Every scan stores its raw artifact, a normalized JSON report, and a client-facing finding summary. Auditable, exportable, and ready for security review conversations.
Scanner families, grouped by security program category
Six categories, one toolbox. Industry-standard tools are packaged into clear jobs with predictable scope and evidence-backed results. Scan depth and bundles are selected in the client portal.
Reconnaissance & surface mapping
Map the externally visible footprint of a domain and gather context before deeper testing.
Map the public footprint before deeper testing
Purpose. Reconnaissance answers the first question in external testing: what does this domain or business expose from the outside? It builds the target picture before port discovery, web testing, TLS review, vulnerability scanning, or human validation.
What it looks for
- Public subdomains, hostnames, and related internet-facing assets
- Resolved hosts, reachable web services, and basic technology fingerprints
- Forgotten applications, staging systems, shadow IT, and externally visible entry points
- Signals that help choose the next scan, such as web discovery, Nmap, TLS review, OWASP ZAP, or OpenVAS
Popular tools in this phase
- Subdomain and asset discovery: Amass, Subfinder, Assetfinder, Findomain
- DNS and host validation: dnsx, shuffledns, MassDNS
- Web probing and fingerprinting: httpx, WhatWeb, Wappalyzer, WafW00f
- Crawling and URL discovery: Katana, gau, waybackurls
Port, service & web content discovery
Find reachable ports, visible services, and exposed web paths so the next scan starts with the right scope.
Find reachable ports and exposed services
Purpose. Port discovery shows which services are reachable from the public internet. Teams get a clean exposure map before service enumeration, TLS review, vulnerability scanning, or remediation.
What it looks for
- Open TCP ports and internet-facing services on authorized assets
- Unexpected listeners after firewall, DNS, hosting, or deployment changes
- Service signals that help choose follow-up Nmap, TLS, OWASP ZAP, or OpenVAS checks
- Quick exposure confirmation or wider port coverage depending on the target and urgency
Popular tools in this phase
- Masscan, Nmap, Naabu, RustScan
Find exposed web paths, files, and application entry points
Purpose. Web discovery maps visible content and routes so teams can spot forgotten paths, risky files, admin areas, and targets for deeper web testing.
What it looks for
- Common directories, admin panels, backup files, config files, and test paths
- Application URLs, crawled routes, linked resources, and historical paths
- Potentially sensitive content that should be reviewed or removed
- Better scope for follow-up OWASP ZAP, XSStrike, sqlmap, or human web review
Popular tools in this phase
- ffuf, Feroxbuster, Gobuster, Dirsearch, Katana, gau, waybackurls, Hakrawler
Service, version & TLS enumeration
Service, version, and protocol detail so you know what is behind each exposed port.
Identify what is running behind open ports
Purpose. Nmap-based enumeration adds service-level context to open ports. Teams see software, versions, protocols, and safe evidence signals before deciding what to patch, harden, or test deeper.
What it looks for
- Service names, versions, banners, and protocol behavior on confirmed open ports
- Operating system and device hints where they can be collected safely
- Safe script output that gives richer remediation evidence without destructive testing
- Exposure signals that help prioritize TLS review, OpenVAS checks, web testing, or human validation
Popular tools in this phase
- Nmap, NSE safe scripts, service/version detection, OS fingerprinting where appropriate
Review certificates, protocols, and encryption settings
Purpose. TLS review checks whether public HTTPS and TLS-enabled services use safe protocol versions, strong cipher suites, valid certificates, and consistent configuration across the exposed estate.
What it looks for
- Supported TLS protocols, cipher suites, certificate details, and trust-chain signals
- Expired, mismatched, weak, or inconsistently deployed certificates
- Common TLS misconfigurations that can weaken encrypted services
- Endpoint-level differences across a domain or public service estate
Popular tools in this phase
- testssl.sh, SSLyze, OpenSSL, Nmap ssl-enum-ciphers
Automated vulnerability assessment
Automated checks for known weaknesses and risky configurations using industry-standard tools, including OpenVAS and OWASP ZAP.
Find known weaknesses on exposed hosts and web applications
Purpose. Vulnerability scanning checks exposed services, web apps, and known software fingerprints for weaknesses you can prioritize, fix, and retest. It combines network vulnerability assessment, web application review, and targeted validation into one remediation-focused phase.
What it looks for
- Known CVEs, risky service versions, exposed software, and insecure configurations
- Web application weaknesses such as missing security headers, exposed files, injection indicators, XSS indicators, and common OWASP issues
- Vulnerability evidence that can be normalized, deduplicated, prioritized, and tied to a practical fix
- Findings that may need no-harm validation or human review before remediation decisions
Popular tools in this phase
- OpenVAS, OWASP ZAP, Nuclei, Nikto, Nessus, Nexpose, Metasploit
- XSStrike, sqlmap, Nmap NSE vulnerability scripts, testssl.sh, SSLyze
Exploitation validation
Tightly scoped, no-harm checks for practical exploitability. They cut false positives and produce evidence a developer or auditor can act on.
Confirm suspected issues without turning testing into a free-for-all
Purpose. Validation checks whether a suspected weakness looks real, reproducible, and worth fixing first. Use it after discovery or vulnerability scanning to cut false positives, collect clearer evidence, and support remediation without broad exploitation.
What it looks for
- Evidence that suspected XSS, SQL injection, command injection, file inclusion, SSRF, authentication, or exposed-service findings are valid
- Controlled proof signals that help developers reproduce and fix the issue
- False positives from vulnerability scanners that should be downgraded or dismissed
- Cases where no-harm validation or human security review is the safer next step
Popular tools in this phase
- Metasploit, XSStrike, sqlmap, Nuclei, Burp Suite, OWASP ZAP
- Dalfox, Commix, ffuf, Feroxbuster, Nikto, Nmap NSE scripts, custom no-harm validation checks
Package bundles for common scenarios
When one scanner is not enough, PortWarden offers pre-built bundles that combine the right tools for common situations.
Per-IP deep dive
A full picture of a single IP: broad port sweep, service and version detection, standard vulnerability assessment, and TLS posture where applicable. A fast way to characterize one host.
Priority host emergency
When something looks wrong on a critical host and you need answers fast: deeper port and service analysis, deep vulnerability assessment, TLS review, and a priority report.
Web application deep dive
A focused review of one web application: expanded content discovery and deeper web vulnerability checks in one bundle, with normalized findings ready for developer remediation.
You should not need an in-house security analyst to run industry-standard scanners
PortWarden packages open-source and industry-standard tools into clear on-demand scans with predictable scope, normalized evidence, AI-driven analysis, and guided remediation.
You decide what you need. We run it, compare results against known vulnerability databases, and walk your team through the fix. Human security professionals are available when you want a deeper second look.