Assessment overview

QPen probes a target the way an adversary would, then scores how much of that activity the blue team actually saw. Findings carry the control identifiers that an assessor asks for and the ATT&CK technique that describes the behaviour.

6
Engagements
Across TLS, web, network and purple team
26
Total findings
Mapped to NIST 800-53 and CMMC
1
Purple exercises
Six red team actions in each run
67%
Avg blue score
Share of red team actions detected
2
Critical
10
High
7
Medium
6
Low
1
Info

Recent engagements

TargetScan typeSeverityFindingsStarted
payments.firstnationalbank.com
port 443
Full scan
C 1 H 3 M 2 L 1 I 0
7 4 d ago
2026-08-26 06:14 UTC
api.firstnationalbank.com
port 443
TLS scan
C 0 H 0 M 0 L 0 I 1
1 4 d ago
2026-08-26 05:48 UTC
admin.firstnationalbank.com
port 443
Web scan
C 0 H 1 M 2 L 2 I 0
5 4 d ago
2026-08-26 04:56 UTC
192.168.10.45
port 443
Network scan
C 0 H 1 M 1 L 1 I 0
3 4 d ago
2026-08-26 04:02 UTC
treasury.firstnationalbank.com
port 443
Purple team exercise
C 0 H 1 M 1 L 0 I 0
2 4 d ago
2026-08-26 03:00 UTC
branches.firstnationalbank.com
port 443
Full scan
C 1 H 4 M 1 L 2 I 0
8 4 d ago
2026-08-26 01:27 UTC