
Why Organizations Use VulnScan
Modern attack surfaces change every day: new subdomains, exposed admin panels, temporary APIs, outdated services, forgotten cloud buckets, weak TLS, and vulnerable third-party components. A one-time penetration test cannot provide continuous visibility, while raw scanner output is often too noisy for remediation teams. CyStack VulnScan is designed to close that gap:- Find more real risk by combining discovery, service fingerprinting, active vulnerability checks, version-to-CVE matching, vulnerability intelligence, and optional AI-assisted analysis.
- Reduce false positives by requiring concrete version evidence, exact/range CPE matching, verification signals, confidence scoring, deduplication, and optional AI review of noisy evidence.
- Prioritize remediation with severity, CVSS, EPSS, CISA KEV, public exploit indicators, confidence, and a 0-100 risk score.
- Support both Web UI and CLI so analysts can work interactively while automation pipelines still write scan history into the same database.
- Produce management-ready output through bilingual UI/reporting, PDF jobs, CSV/JSON export, and email notification.
- Support governed usage through visible license scope, target limits, activation status, and expiration information.
What VulnScan Can Assess
VulnScan is focused on Internet-facing assets and externally reachable services:Product Capabilities at a Glance
How a Scan Works
- Scope and license validation: VulnScan normalizes the target and validates it against the active license before work is queued.
- Discovery: The scanner discovers alive hosts, subdomains, open ports, server metadata, WAF/CDN signals, TLS certificates, and web/API endpoints.
- Fingerprinting: Services, technologies, CMS/frameworks, WordPress plugins/themes, protocol banners, TLS details, SSH/SMB/SNMP hints, and CPE candidates are identified.
- Detection: Built-in DAST checks, CyStack verification checks, unauthenticated-service checks, default-credential checks, optional AI-assisted analysis, and CPE-to-CVE matching run against the discovered surface.
- Enrichment: Findings are enriched with CVSS, EPSS, CISA KEV, CWE, OWASP Top 10, OWASP WSTG, remediation guidance, and exploitability signals.
- Deduplication and scoring: Duplicate findings are merged, the highest-confidence evidence is kept, and a risk score is calculated.
- Persistence: Standard Web UI, scheduled, and CLI scans are written to the same database with scan source metadata.
- Reporting: Users triage findings in the Web UI or export CSV, JSON, and PDF reports.
Scan to find, WAF to protect
VulnScan combines two complementary capabilities in the same workspace:- Vulnerability scanning helps you find risk: asset discovery, technology fingerprinting, active checks, CVE matching, and prioritization.
- CyStack WAF helps you actively prevent exploitation at the edge: point your domains through self-operated edge nodes, enable the managed OWASP ruleset, and add custom rules.
The word “WAF” is used in two senses in this documentation: WAF/CDN detection is the scan recognizing whether a target organization uses a WAF/CDN (for example Cloudflare); CyStack WAF is the firewall product your own organization deploys to protect its sites.
Deployment Model
CyStack VulnScan is distributed as a binary application compatible with Windows, macOS, and Linux. To obtain the binary and a matching license, contact CyStack Sales at sales@cystack.net. One binary supports two operating modes:- Web UI for interactive asset management, scanning, triage, reports, members, mail settings, and license management.
- CLI for automation, scheduled jobs, CI/security pipelines, offline preparation, and scripted report export.