Optional categories are off until you choose. You can change or withdraw your choice using Cookie settings in the footer.

Sample report · fictional data

All results, scores, addresses and dates on this page are illustrative. They do not describe a real organization, and opening this sample does not run a scan.

example.test

Illustrative snapshot

External security score

Grade: A
82 / 100
Score from completed checks

NIS2

Technical indicator
70 / 100
External checks only. Not a compliance audit.

Findings & Vulnerabilities

Items: 4
4 findings
check
Subdomains: 3 • Leak Risk: Low
Detailed analysis

Overview of 8 OSINT Security Modules.

How to read this assessment

The score describes measured external configuration. Higher scores indicate fewer issues in the checks performed; they do not guarantee that a system is secure.

The overall score is a weighted average of assessed modules: DNS and TLS 20% each; Microsoft 365, web headers, exposed services and reputation 15% each. Modules without a score are excluded and the remaining weights are rescaled. Subdomain inventory and credential exposure are reported separately and are not included in this average.

Coverage and risk are separate. A confirmed absent service receives neither a penalty nor a bonus. A failed check cannot establish absence or successful remediation. A missing protection on an existing service can still be a finding.

The NIS2 indicator uses the overall score minus 12 points for each Critical or High finding, with a minimum of zero. This is an external technical indicator, not a compliance audit.

TLS and header grades are local XRENN™ assessments. No Qualys SSL Labs or Mozilla Observatory assessment is performed. They describe only the checks listed in each module.

Up to three next steps are selected from the severity and evidence of related findings. Findings with the same cause are grouped. A scan without actionable findings does not receive invented priorities.

Three priorities in this example

These steps relate only to the fictional findings below. Your own scan will use its actual findings.

1. Review certificate and TLS findings

Confirm the affected hostname, repair the certificate or renewal process and repeat the verified connection.

2. E-mail Security Hardening (SPF, DMARC, DKIM)

Inventory senders, back up DNS, configure the applicable policies, verify delivery and repeat the scan.

3. HTTP Security Headers

Back up configuration, test CSP in report-only mode, verify key user journeys and repeat the same checks.

DNS & E-mail

85/100
Public IP addresses (DNS) 192.0.2.10 (A)

DoH Status: Healthy

SPF Policy: Valid

DMARC: none

DNSSEC: Active

How we measure and assess: DNS & E-mail

Method We query public DNS for MX, SPF, DMARC, DNSKEY, MTA-STS and eight common DKIM selectors, using an independent resolver after a resolver failure.

What the result means Missing or permissive mail policies can weaken protection against domain impersonation. Legitimate senders must be inventoried before tightening a policy.

Scope and limitations DNSKEY and MTA-STS checks confirm record presence only. DKIM discovery covers common selectors, not every possible selector. DNS responses are recursive observations, not an authoritative zone audit.

Verification after remediation Repeat the DNS checks after propagation and verify delivery from every legitimate mail sender.

Measurement coverage (9/9)
  • Cloudflare DoH: Measured
  • DNS MX: Measured
  • DNS SPF: Measured
  • DNS DMARC: Measured
  • DNSKEY: Measured
  • MTA-STS: Measured
  • DKIM: Measured
  • DNS A: Measured
  • DNS AAAA: Measured
Weak DMARC Policy (p=none)

Review the observed mail-policy gaps and verify legitimate senders before changing DNS.

Remediation Inventory senders, back up DNS, configure the applicable policies, verify delivery and repeat the scan.

Evidence and priority

Why it matters Missing or permissive mail policies can weaken protection against domain impersonation. Legitimate senders must be inventoried before tightening a policy.

Priority Medium. Findings are ordered by severity, then by evidence basis. Direct observations precede provider observations at the same severity. Business criticality is not assumed.

Evidence basis Direct observation

Verification after remediation Repeat the DNS checks after propagation and verify delivery from every legitimate mail sender.

Rule and methodology version dmarc.monitoring · v1

Source
DNS DMARC
Observation
Measured
Checked at (UTC)
09/14/2026 10 a.m. UTC
Measured target
example.test
SPF record
v=spf1 mx -all
SPF Policy
Valid
DMARC record
v=DMARC1; p=none
DMARC
none
DKIM
Detected

Microsoft 365

Not Configured

M365 Tenant: Not Configured

Autodiscover: Not Configured

Azure Subdomains: 0

How we measure and assess: Microsoft 365

Method We compare public Microsoft realm and OpenID responses, Autodiscover DNS and selected Azure DNS links.

What the result means Public tenant metadata identifies the service footprint. It does not prove a weakness in tenant access controls.

Scope and limitations No tenant login, MFA, Conditional Access or internal Azure configuration is tested. A confirmed absent tenant is excluded from scoring.

Verification after remediation Verify tenant ownership and internal controls with the administrator; repeat public discovery after DNS changes.

Measurement coverage (4/4)
  • Microsoft Realm: Absence observed
  • Microsoft OpenID: Absence observed
  • Autodiscover: Absence observed
  • Azure DNS: Absence observed

TLS & SSL Encryption

Local grade C

Certificate Issuer: Example CA

Certificate Validity: 10 days

TLS 1.3 Support: Yes

How we measure and assess: TLS & SSL Encryption

Method We connect on port 443 with SNI and certificate verification, record the negotiated protocol and certificate expiry, and try www when the apex connection is unavailable.

What the result means Certificate validation failures or approaching expiry can disrupt trusted HTTPS access. Renewal findings use thresholds below 14 and 30 days.

Scope and limitations One negotiated connection does not enumerate all supported protocols or weak ciphers. HSTS preload and the complete TLS configuration are not tested.

Verification after remediation Repeat the verified connection to the same hostname after renewal or configuration changes.

Measurement coverage (1/1)
  • TLS / SNI: Measured
SSL/TLS Certificate Expiring Soon

Check certificate validity and renewal on the observed endpoint.

Remediation Confirm the affected hostname, repair the certificate or renewal process and repeat the verified connection.

Evidence and priority

Why it matters Certificate validation failures or approaching expiry can disrupt trusted HTTPS access. Renewal findings use thresholds below 14 and 30 days.

Priority Critical. Findings are ordered by severity, then by evidence basis. Direct observations precede provider observations at the same severity. Business criticality is not assumed.

Evidence basis Direct observation

Verification after remediation Repeat the verified connection to the same hostname after renewal or configuration changes.

Rule and methodology version tls.expiry · v1

Source
TLS / SNI
Observation
Measured
Checked at (UTC)
09/14/2026 10 a.m. UTC
Measured target
example.test
Measured target
example.test
Certificate Issuer
Example CA
Certificate validity (days)
10
Protocol
TLSv1.3
Certificate expiry
09/24/2026 10 a.m. UTC

Web Security Headers

Local grade B

Local score: 80/100

Server: Not disclosed

Missing Headers: 2 items

How we measure and assess: Web Security Headers

Method We inspect six security headers on the final successful HTTP response, trying HTTPS, www and HTTP as needed. CSP frame-ancestors can satisfy the framing protection check.

What the result means Missing headers remove browser protections but do not by themselves demonstrate an exploitable application vulnerability.

Scope and limitations Results describe the measured response, not every page or authenticated flow. Restricted responses do not establish missing-header findings. Header presence is not a full policy audit.

Verification after remediation Deploy CSP in report-only mode first, test forms and integrations, then enforce the policy and repeat the same URL check.

Measurement coverage (1/1)
  • HTTP: Measured
Missing Content-Security-Policy Security Header

Configure the missing protections on the measured HTTP response.

Remediation Back up configuration, test CSP in report-only mode, verify key user journeys and repeat the same checks.

Evidence and priority

Why it matters Missing headers remove browser protections but do not by themselves demonstrate an exploitable application vulnerability.

Priority Medium. Findings are ordered by severity, then by evidence basis. Direct observations precede provider observations at the same severity. Business criticality is not assumed.

Evidence basis Direct observation

Verification after remediation Deploy CSP in report-only mode first, test forms and integrations, then enforce the policy and repeat the same URL check.

Rule and methodology version http.missing · v1

Source
HTTP
Observation
Measured
Checked at (UTC)
09/14/2026 10 a.m. UTC
Measured target
example.test
Measured target
https://example.test
Strict-Transport-Security
max-age=31536000
X-Frame-Options
DENY
X-Content-Type-Options
nosniff
Referrer-Policy
strict-origin-when-cross-origin
Missing Headers
Content-Security-Policy
Missing Headers
Permissions-Policy
HTTP status
200
Missing Permissions-Policy Security Header

Configure the missing protections on the measured HTTP response.

Remediation Back up configuration, test CSP in report-only mode, verify key user journeys and repeat the same checks.

Evidence and priority

Why it matters Missing headers remove browser protections but do not by themselves demonstrate an exploitable application vulnerability.

Priority Low. Findings are ordered by severity, then by evidence basis. Direct observations precede provider observations at the same severity. Business criticality is not assumed.

Evidence basis Direct observation

Verification after remediation Deploy CSP in report-only mode first, test forms and integrations, then enforce the policy and repeat the same URL check.

Rule and methodology version http.missing · v1

Source
HTTP
Observation
Measured
Checked at (UTC)
09/14/2026 10 a.m. UTC
Measured target
example.test
Measured target
https://example.test
Strict-Transport-Security
max-age=31536000
X-Frame-Options
DENY
X-Content-Type-Options
nosniff
Referrer-Policy
strict-origin-when-cross-origin
Missing Headers
Content-Security-Policy
Missing Headers
Permissions-Policy
HTTP status
200

Exposed Services

TCP / OSINT
Open Perimeter Ports: 80, 443
Scan scope: 5 TCP ports · 1 public IPs
Observed endpoints
  • 192.0.2.10 · 80/tcp
  • 192.0.2.10 · 443/tcp
Shodan CVE records: Not detected
How we measure and assess: Exposed Services

Method We attempt TCP connections to 37 ports on up to four public DNS addresses and combine these observations with available Shodan records. Banners are read passively and are bounded.

What the result means Public database or administration ports deserve access-control review. An open SSH port alone is informational. A CVE from a provider requires asset and patch verification.

Scope and limitations No passwords, exploits, UDP sweep or full port scan are used. DNS addresses may belong to a CDN or shared host. Provider observation time can precede this scan.

Verification after remediation Confirm asset ownership, restrict unnecessary exposure, verify vendor patch applicability and repeat the same endpoint checks.

Measurement coverage (3/3)
  • Shodan: Measured
  • TCP: Measured
  • DNS: Measured

Subdomains & CT Logs

CT / DNS

Discovered Subdomains: 3 subdomains

  • mail.example.test
  • portal.example.test
  • www.example.test

Wildcard Certificates: 0

Shadow IT Alerts: 0

How we measure and assess: Subdomains & CT Logs

Method We combine certificate transparency sources, public host records and a bounded set of DNS prefixes. The displayed inventory is limited to 100 names.

What the result means A larger public inventory calls for ownership and lifecycle review; it does not prove that a subdomain is compromised.

Scope and limitations Certificate names can be historical. A listed name does not establish a live service or an exhaustive asset inventory.

Verification after remediation Confirm ownership and current DNS and service status before retiring any asset.

Measurement coverage (4/4)
  • CertSpotter: Measured
  • HackerTarget: Measured
  • crt.sh: Measured
  • DNS: Measured

Darkweb & Breaches

LeakRadar
Credential exposure: Not detected
Compromised Corporate Emails: 0
How we measure and assess: Darkweb & Breaches

Method We query the provider for domain-related credential exposure, keeping employee, customer and third-party groups and approximate counts separate.

What the result means Reported account exposure requires investigation, credential revocation where applicable and review of authentication controls.

Scope and limitations Coverage is limited to the provider database. A negative response means no records were detected in that checked source, not a guarantee that no leak exists. Passwords are not retrieved.

Verification after remediation Verify affected account groups with the owner, revoke exposed credentials and confirm MFA and session controls.

Measurement coverage (1/1)
  • LeakRadar: Measured

Reputation & Malware

Threat checks
Malware & phishing indicators: Not detected
Cloudflare Security DNS: Not detected
VirusTotal AV Engines: Not detected
URLhaus Threat Database: Not detected
How we measure and assess: Reputation & Malware

Method We query configured VirusTotal and URLhaus sources and compare Cloudflare malware-filtered DNS with unfiltered DNS.

What the result means Threat classifications can affect access and reputation. They are investigation signals, not proof of a successful compromise.

Scope and limitations Results apply to checked sources at the recorded time. DNS filtering is not a content scan. An unavailable source cannot confirm a clean result.

Verification after remediation Investigate the affected site and DNS, address confirmed issues and request a provider review if the classification is incorrect.

Measurement coverage (3/3)
  • URLhaus: Measured
  • VirusTotal: Measured
  • Cloudflare Security DNS: Measured
Expert guarantor

Cybersecurity, NIS2 & AI with Guarantor.

Direct contact with the expert guarantor for ISO 27001 ISMS, new Czech Cyber Security Act (ZKB 264/2025 Sb.) / NIS2 compliance, penetration testing, and world-class AI security.

Whether you are addressing the requirements of the new Czech Cyber Security Act (ZKB 264/2025 Sb.), the European NIS2 directive, ISO/IEC 27001 certification, or securely deploying frontier AI models and offline EdgeGuardian appliances, send your project inquiry to schedule an expert consultation.

Expertise & Diplomas

ISO/IEC 27001:2023 Lead Auditor

Information Security Management (ISMS), audit certification, and security policy implementation.

MBA Cybersecurity Academic Degree

Master of Business Administration – strategic and technical cybersecurity governance.

NIS2 & ZKB 264/2025 Sb. Compliance

Guarantor of compliance with the new Cyber Security Act and EU NIS2 directive.

AI & LLM Security Frontier AI

World-class frontier LLM model security, AI Red Teaming, and EdgeAI defense.

newsletter-shape newsletter-top-glow-shape newsletter-bottom-glow-shape

Secure Your Organization with XRENN™

From NIS2 and ZKB compliance to penetration testing and offline EdgeAI appliances, protect your critical infrastructure today.