1. Help centre
  2. Your services
  3. Vulnerability Scan
  • Welcome to HackRisk
  • Getting started
  • Reading your dashboard
  • Sophia, your AI assistant
  • Dark Web Scan
  • Vulnerability Scan
  • Recon Scan
  • Supply Chain Risk
  • Security Awareness & Phishing
  • Managing your account

Vulnerability Scan

Weaknesses on the systems you expose to the internet, and how to act on them.

Loading documentation…

Dark Web Scan< PreviousRecon ScanNext >

Powered by heyo

On this page

OverviewVulnerabilitiesVulnerabilities from Recon ScanScan targetsAdding scan targetsReports

Vulnerability Scan checks the systems you expose to the internet for known weaknesses, so you can fix them before someone else finds them.

Overview

A scan runs every night against the targets on your account. It checks only the targets you have added. If you add a domain, for example, its subdomains are not included automatically. Subdomains are covered by Recon Scan.

The page follows the same layout as Dark Web Scan:

  • A score for the module.
  • Your top five risks.
  • A graph showing how your vulnerabilities change over time.

Vulnerabilities

Below the graph, each vulnerability is listed with its CVSS level, so you can see at a glance which issues matter most. CVSS is a standard severity rating, running from Low to Critical.

Select a vulnerability to open a panel with a short description of the issue and the scanner logs that found it. This is available to subscribers only, not on free trials.

Each vulnerability also has a Detailed Remediation Advice button. It gives you a summary of the problem, the risks it may create and recommended steps to fix it. Only the description of the vulnerability is used to produce this advice. None of your own data is shared.

If you believe an issue is a false positive, or you do not consider it a real risk to you, select Acknowledge. The issue stays visible in HackRisk but no longer counts towards your HackRisk Score.

Vulnerabilities from Recon Scan

Below the main list, a second section shows vulnerabilities found by Recon Scan. It is there for convenience, so you can see everything in one place. Fuller detail on those issues is in the Recon Scan section.

Scan targets

The Scan Targets section lists every target currently set up for scanning. We add one target automatically: the domain you signed up with.

For each target you will see coloured counters, one per CVSS level.

  • Select a counter to see every vulnerability at that level for the target.
  • If there are no issues at that level, selecting the counter does nothing.
  • From this view, you can send an issue to Slack or Teams using the icon in the top-right corner.

Adding scan targets

Subscribers can add one extra scan target at no additional cost. Targets can be websites, IP addresses and other services that face the internet.

You can also scan internal devices by installing a scanning agent on them. Guidance for adding an internal target is available through the link in the portal.

Scans run automatically each night. As a subscriber, you can also start a scan of any target on demand.

Reports

The final section of Vulnerability Scan is Reports. These are monthly reports in a legacy format, with detailed information on the vulnerabilities found during each reporting period.