Skip to main content

External Footprint Scan

Updated yesterday

What is it all about?

The External Footprint Scan is a core component of our security suite, designed to continuously monitor your organization’s online presence and identify potential security risks. It provides visibility across your internet-facing assets, helping you proactively manage vulnerabilities before they can be exploited.

Your primary / associated domains:

Guardz typically scans your primary domain, as well as any domains designated as associated. If you wish to add or modify vendor domains for inclusion in the scans, these domains must first be verified through the respective vendors. The following resources are provided to assist you with this process:

What is being scanned under each domain?

The External Footprint Scan includes monitoring for:

  • Publicly Accessible IP Addresses: Detecting IPs associated with your organization to identify potential exposures

  • Domains and Subdomains: Scanning for misconfigurations, open ports, and security risks across your registered domains

  • SSL Certificates: Ensuring the security and validity of SSL certificates to protect data integrity

  • Threat Intelligence Sources: Leveraging multiple data sources to detect emerging threats and risks across the internet

  • The scan also checks over HTTP, enhancing detection capabilities across several technologies: Apache, Microsoft IIS and PHP


Activating the service

  • The external footprint scan is initiated automatically upon the addition of a new customer, once their Google or Microsoft domain has been submitted

  • The scan runs on a weekly basis

  • It may take up to 2 hours to complete a scan


Issues and Remediations

  • Upon completing a scan, Guardz identifies and reports any issues found across your assets, providing details such as affected IPs, domains, and any missing security measures.

  • You can take action directly on these issues to address and remediate them

  • You may initiate a scan manually after remediating an issue by following these steps:

    • Open the relevant issue

    • Click on 'Remediation'

    • Select the ‘Mark as processed’ option - this will trigger a new scan

Specific issues handling:

  • If a DMARC record is present but set to a 'none' policy (p=none), it is considered insufficiently configured. Adjusting the policy is recommended based on your organization's needs

  • If an asset is listed as inactive, it indicates that the asset's IP is no longer active, which could mean it is not responding or has been decommissioned

Did this answer your question?