SWR7
Home/Services/Service · Detect
Service · Detect

Detect: continuous, non-destructive vulnerability detection

Everything an attacker would learn about your surface in the first hour — found first, on production, without a single crafted exploit.

What Detect does

Detect is the first job of the swarm: establish what is exposed, misconfigured or already known-vulnerable on the targets you authorized, using non-destructive detection at safety levels S0–S1. It runs on production because it never has to break anything to prove a finding.

What it covers

  • TLS and certificates — expiry, weak protocols and ciphers, chain and configuration errors after a rotation.
  • HTTP security headers — HSTS, Content-Security-Policy, frame and MIME protections, and their disappearance after a deploy.
  • Authentication surfaces — login and session behavior observed from the outside: rate limiting, error signatures, exposed panels.
  • Injection and cross-site scripting — reflected inputs and error behavior detected with non-persistent, non-weaponized probes.
  • Dependencies and known CVEs — version fingerprints matched against public vulnerability databases.
  • Exposed files and paths — backups, .env and .git folders, source maps, admin panels, debug endpoints.
  • Subdomains — new, changed or forgotten hosts, the classic staging server nobody remembers.
  • Leaked credentials — accounts tied to your domain appearing in public breach corpora.

How a finding becomes a finding

Each agent owns one slice of the list above. Signals are triaged before they reach you — is it real, is it reachable, how severe — and scored. Unverified signals stay internal. What you see is a finding with evidence, severity and the remediation attached.

Where it runs, and where it stops

Detect runs at S0 (passive: DNS, certificates, headers, public corpora) and S1 (non-destructive active: lightweight requests that reveal configuration and behavior). Both are allowed on production under the Rules of Engagement. Anything that would need crafted inputs or exploitation belongs to the controlled and intrusive levels, on staging, and is a separate decision you take in writing — see the S0–S3 safety levels.

OutputA continuous exposure view in the client area, alerts for high-severity findings, and a PDF report per run — each finding with its fix.

Frequently asked questions

How often does Detect run?

Continuously, in cycles of minutes to hours depending on the check: uptime and TLS every few minutes, exposure and subdomain discovery a few times a day, breach-corpus checks daily. The cadence is set per site in the Rules of Engagement.

Will our WAF or bot protection block it?

Detect identifies itself with a stable user agent and stays within the request budget agreed in the RoE. If your edge blocks it, we see it as a finding about your edge, not as a failed test — and we tell you.

Does Detect replace a penetration test?

No. It replaces the year-long gap between two pentests, when the surface changes and nobody is looking. Depth (exploitation, chaining, business logic) is what the controlled and intrusive levels are for.

Want to know what your surface looks like from outside?

An intro call, no commitment. If it makes sense, you receive the Rules of Engagement — nothing is tested before you sign.

Book an intro call