New assessment
Point QPen at a hostname, an address or a CIDR block. The scanner negotiates a session, reads the certificate chain, sweeps the exposed service surface and maps every result to the controls an assessor will ask about.
What each assessment returns
| Type | Checks | Typical findings |
|---|---|---|
| TLS scan | Key exchange group, certificate signature algorithm, protocol version, harvest now decrypt later exposure | 1 to 5 |
| Web scan | Transport security, content policy, frame policy, banner disclosure, administrative paths, cross origin policy, cookie flags | 3 to 6 |
| Network scan | Open port inventory, remote access services, service banners, cleartext protocols | 2 to 4 |
| Full scan | Every check above, correlated into one report | 5 to 10 |
| Purple team | Six red team actions across crypto and web, scored against blue team detection | 0 to 6 |