Complete web and network security assessment: WAF, open ports, subdomains, CORS policy, OWASP headers, DMARC, and DORA / NIS2 compliance.
Auditing HTTP headers, SSL certificate, network ports, WAF filters, and NIS2 / DORA compliance.
Key security indicators, OWASP-calculated score, WAF posture, SSL, and threat reputation.
Risk classification aligned with OWASP Top 10 standards.
Evaluation of perimeter and local attack filters against automated SQLi, XSS, and botnets.
TLS certificate validity, issuer CA, and port 80 to HTTPS enforcement.
Browser security barriers mitigating Clickjacking, XSS, and MIME sniffing.
Controlling cross-origin API data sharing and mitigating credential theft.
Inspection of HttpOnly, Secure, and SameSite flags protecting session tokens.
Preventing CEO Fraud and Business Email Compromise through domain authentication.
Direct probing of active service ports on public IP (Web, SSH, DB, RDP).
Discovery of exposed subdomains, mail infrastructure, and dev/staging environments.
Security assessment of disclosed runtime versions and CVE signature catalogs.
Maps confirmed technical findings to verifiable auditor evidence.
Detection of REST API endpoints, user enumeration risks, and XML-RPC.
Probing for configuration leaks (.env, .git) and security.txt.
Real-time multi-threaded lookup across 5 global reputation blocklists.
Ready-to-use hardening snippets for Apache .htaccess, Nginx, PHP, and DNS records.
The full security report and remediation checklist will be delivered to:
@domeniu.ro