New assessment

Point QPen at a hostname, an address or a CIDR block. The scanner negotiates a session, reads the certificate chain, sweeps the exposed service surface and maps every result to the controls an assessor will ask about.

Hostname, address or CIDR block. Results are reproducible: the same target always returns the same report.
Session port for the TLS stages.
TLS reads key exchange, certificate algorithm and protocol version. Web checks headers, cookies, exposed paths and cross origin policy. Network sweeps ports and grabs banners. Full runs all three. Purple team fires six red team actions and scores what the blue team caught.
Past engagements

What each assessment returns

TypeChecksTypical findings
TLS scanKey exchange group, certificate signature algorithm, protocol version, harvest now decrypt later exposure1 to 5
Web scanTransport security, content policy, frame policy, banner disclosure, administrative paths, cross origin policy, cookie flags3 to 6
Network scanOpen port inventory, remote access services, service banners, cleartext protocols2 to 4
Full scanEvery check above, correlated into one report5 to 10
Purple teamSix red team actions across crypto and web, scored against blue team detection0 to 6