Monthly Vulnerability Scan

A credentialed scan of one host, every month, against the public record of known vulnerabilities: what is installed, which versions, and which of those versions have published advisories against them. You get a ranked list of what is out of date or misconfigured, with the fix named. Because it repeats monthly, you can also see whether the list from last month actually got shorter.

What you get

  • One host scanned monthly with credentials, so the report covers installed packages and not only what answers from outside
  • Findings ranked by severity, each with the fix named rather than an advisory number left for you to look up
  • A comparison against last month: what was fixed, what is still open, what is new
  • Findings that do not apply to you marked as such, so nobody spends a day chasing a vulnerability in a service you do not run

What this does not cover

  • Everything a scanner cannot know: access control that is simply wrong, business logic that can be abused, a password somebody can guess, two small weaknesses that only matter together
  • Fixing what it finds — the report says what to do; the doing is Server Security Hardening Baseline, a Dependency Patch Run, or your own team
  • Hosts beyond the one in scope; the subscription covers a single host
  • Compliance of any kind. This is not an approved-scanning-vendor PCI scan, and the report is not an attestation that can be handed to an auditor, an insurer or a card network
  • Testing a custom web application beyond what a scanner recognises, which needs a person — that is External Penetration Test

Who it fits

A production host you want to stop quietly rotting, since unpatched software is how most servers are actually lost. A scan is not a pen test: it finds what is already published, not what somebody clever could do with your particular setup, and anyone buying it as proof of being secure is buying the wrong thing.