What is it all about?
The External Footprint Scan is a core component of our security suite, designed to continuously monitor your organization’s online presence and identify potential security risks. It provides visibility across your internet-facing assets, helping you proactively manage vulnerabilities before they can be exploited.
Your primary / associated domains:
Guardz typically scans your primary domain, as well as any domains designated as associated. If you wish to add or modify vendor domains for inclusion in the scans, these domains must first be verified through the respective vendors. The following resources are provided to assist you with this process:
Microsoft: Add custom domains to your tenant using the Microsoft Entra Custom Domain Instructions
Google: To add secondary domains in Google Workspace, refer to Google Workspace Custom Domain Instructions
What is being scanned under each domain?
The External Footprint Scan includes monitoring for:
Publicly Accessible IP Addresses: Detecting IPs associated with your organization to identify potential exposures
Domains and Subdomains: Scanning for misconfigurations, open ports, and security risks across your registered domains
SSL Certificates: Ensuring the security and validity of SSL certificates to protect data integrity
Threat Intelligence Sources: Leveraging multiple data sources to detect emerging threats and risks across the internet
The scan also checks over HTTP, enhancing detection capabilities across several technologies: Apache, Microsoft IIS and PHP
Activating the service
The external footprint scan is initiated automatically upon the addition of a new customer, once their Google or Microsoft domain has been submitted
The scan runs on a weekly basis
It may take up to 2 hours to complete a scan
Issues and Remediations
Upon completing a scan, Guardz identifies and reports any issues found across your assets, providing details such as affected IPs, domains, and any missing security measures.
You can take action directly on these issues to address and remediate them
You may initiate a scan manually after remediating an issue by following these steps:
Open the relevant issue
Click on 'Remediation'
Select the ‘Mark as processed’ option - this will trigger a new scan
Specific issues handling:
If a DMARC record is present but set to a 'none' policy (p=none), it is considered insufficiently configured. Adjusting the policy is recommended based on your organization's needs
If an asset is listed as inactive, it indicates that the asset's IP is no longer active, which could mean it is not responding or has been decommissioned