← Help

IP Scans

Watch public IPv4 addresses you own: score, risk ratings, findings, recommended fixes, and Pro CISA correlation.

Where it lives

Open IP Scans in the sidebar, between Domains and Findings. This is a separate inventory from domains. Findings from an IP stay on this page; they are not mixed into the domain Findings list. Hosts start collapsed; use Expand all / Collapse all or a host chevron to show insights and recommended fixes.

What you can add

Public IPv4 only. Private, loopback, link-local, multicast, and IPv6 addresses are rejected. Add only IPs you own or are authorized to monitor. No CIDR ranges.

What a scan reports

  • PTR reverse DNS and whether it is forward-confirmed
  • RDAP network, organization, country, ASN, CIDR allocation, and abuse contact
  • Open risky and inventory ports, including Windows RPC / NetBIOS / WinRM / Web Deploy / LDAPS (TCP connect only)
  • TLS on 443/8443/9443: handshake success, expiry, issuer, self-signed, IP SAN mismatch, legacy TLS
  • HTTP status and page title, security headers (including HTTP-only hosts), HTTPS redirect, security.txt, Server / X-Powered-By / ASP.NET / WWW-Authenticate / CORS / cookie flags
  • SSH exposure and outdated OpenSSH banners
  • DNS blocklists: Spamhaus ZEN (zen.spamhaus.org) and SpamCop (bl.spamcop.net). A listing becomes a finding. A rejected or timed-out query is shown as unavailable and is not treated as a listing, and it does not clear a listing from an earlier scan.

Profile and context

Expand a host to see its Profile: the service role inferred from ports that answered (web, mail, DNS, remote access, database, directory), plus the network and hostname from the last scan. If one of your monitored domains has an A record for this address, the profile names that domain.

Context is what you add: a purpose, a criticality, and notes. That stays on the host until you change it. A failed or missing scan does not erase it.

Free vs Pro

Free can store 2 IPs and run one scan per IP every 24 hours. A daily schedule is allowed, but it uses that same 24-hour window. Pro can store 25 IPs, scan on demand, keep the daily schedule, and download CSV/PDF reports branded cyberenforced.io.

Both plans show a host security score (averaged per IP). Pro also packages Critical / High / Medium counts and host risk ratings, and correlates open findings with the CISA Known Exploited Vulnerabilities catalog so matching items move up in priority. This is a catalog match plus the CISA required action — not a CVE exploit scan.

See the Billing guide for the rest of the plan comparison.

IP Scans | CyberEnforced