Skip to content

Product documentation

How EightScope monitors your website, DNS, email and infrastructure

EightScope examines the internet-facing systems connected to a domain you control. It works from the public internet, without internal network access or customer credentials, to identify exposed services, weak configurations, unexpected assets and changes over time.

EightScope is designed to provide a clear view of externally observable risk. It combines attack-surface discovery, security checks, prioritised findings and repeatable monitoring in one place.

Authorisation and safety

Domain ownership

Before a production scan can run, the domain must be added to the customer’s organisation and ownership must be verified using a DNS TXT record.

Scanning is restricted to:

  • the verified root domain
  • subdomains belonging to that verified domain
  • public internet-facing services associated with those hostnames

EightScope does not allow customers to use the platform as a general-purpose scanner for unrelated third-party targets.

Safe target validation

Before contacting a hostname, EightScope resolves its DNS records and checks the returned addresses.

Scanning is blocked when a hostname resolves to:

  • private network addresses
  • loopback addresses
  • link-local addresses
  • reserved or otherwise non-public addresses
  • a mixture of public and non-public addresses

This helps prevent the scanner from being used to reach internal services, cloud metadata endpoints or other unsafe destinations.

If a redirect leaves the verified domain’s scope, EightScope does not continue assessing the external destination as though it belonged to the customer.

Non-destructive scanning

EightScope focuses on externally observable configuration and exposure. It does not attempt to damage systems, bypass authentication, brute-force passwords or exploit discovered vulnerabilities.

Some deeper checks, particularly full TCP port scanning, can still trigger firewall, hosting or security-monitoring alerts. Customers should run these checks only against systems they are authorised to assess.

How a scan works

  1. 1

    Verify the domain

    The customer adds a domain and proves control using a DNS TXT record. This establishes the permitted scan boundary.

  2. 2

    Discover internet-facing assets

    Depending on the selected scan type, EightScope uses public certificate data, DNS-based discovery and other external signals to identify hostnames connected to the verified domain. Discovery is not the same as a completed security assessment. A hostname can be discovered without being selected for every scan module.

  3. 3

    Build the asset inventory

    Each in-scope hostname receives its own asset record. EightScope records information such as hostname, resolved public IP addresses, discovery source, HTTP and HTTPS reachability, CDN indicators, TLS assessment status, HTTP-header assessment status, and reasons a check was skipped or blocked.

  4. 4

    Select assets for applicable checks

    Some checks can run against every relevant result, while other checks are limited to a selected set of hosts so scans remain safe, timely and predictable. Selection is deterministic and prioritises useful targets such as reachable web services, the www hostname and security-sensitive names such as admin, login, vpn, api, staging, mail and similar services.

  5. 5

    Run the selected security modules

    The selected scan type determines which modules run. Checks collect external evidence and produce structured findings with affected asset, check name, status, severity, confidence, evidence, explanation and recommended remediation.

  6. 6

    Score and compare the results

    EightScope calculates the posture score from open findings and compares completed scans only when the coverage is suitable for comparison. A deeper scan may produce a lower score simply because it assessed more of the attack surface. That does not always mean the organisation became less secure.

Scan types

Module counts stay aligned with the product so this page reflects what customers can run today.

Quick scan

7 modules · ~30 seconds

A fast external preview of the verified root domain. Quick scans cover core DNS, TLS, HTTP-header and web-exposure checks.

  • assesses the verified root domain only for TLS and HTTP headers
  • does not perform port scanning
  • does not perform subdomain discovery
  • does not represent full attack-surface coverage
  • useful for an initial preview or a fast recheck

Standard scan

15 modules · ~2 minutes

The recommended baseline for regular posture monitoring. Standard scans combine core security checks with subdomain discovery, common-port assessment and broader external coverage while excluding the slowest modules.

  • discovers related hostnames
  • assesses common externally reachable services
  • checks TLS and HTTP headers across selected assets
  • excludes heavier checks such as typosquatting, CVE matching and open-redirect probing
  • best suited to recurring monitoring

Full scan

26 modules · ~5 minutes

The broadest EightScope assessment. Full scans run every available external security module, including deeper discovery and higher-cost checks.

  • includes all standard coverage
  • includes typosquatting checks
  • includes CVE matching against detected technologies
  • includes login-panel and API-surface discovery
  • includes public JavaScript secret-pattern checks
  • includes service-banner and reputation checks
  • still uses the normal common-port profile unless the deep port-scan option is selected

A deep port scan checks all 65,535 TCP ports and requires the relevant option and customer consent. When a normal port scan runs, EightScope also performs limited UDP checks for ports 53, 123 and 161. UDP coverage is not exhaustive.

What we assess

DNS and email security

EightScope may assess

  • DNS resolution and record configuration
  • mail exchange records
  • SPF
  • DMARC
  • common DKIM selectors
  • DNSSEC indicators
  • CAA records
  • email-related configuration weaknesses

DKIM discovery checks common selectors. An organisation may use a valid custom selector that EightScope does not discover.

TLS and certificate security

EightScope may assess

  • certificate validity and expiry
  • hostname matching
  • certificate chain information
  • self-signed certificates
  • supported protocol versions
  • selected cipher and transport indicators
  • alternate HTTPS services when deep TLS assessment is enabled
  • OCSP-related indicators when supported by the selected scan options

HTTP and browser protections

EightScope may assess

  • HTTPS availability
  • HTTP Strict Transport Security
  • Content Security Policy
  • framing protections
  • referrer policy
  • permissions policy
  • cookie Secure, HttpOnly and SameSite attributes
  • redirect behaviour
  • web application firewall indicators
  • publicly visible HTTP behaviour

Ports and exposed services

EightScope may assess

  • common TCP ports
  • all TCP ports when deep port scanning is enabled
  • limited UDP services
  • public service banners
  • exposed administration services
  • remote-access services
  • mail and infrastructure services
  • software-version information exposed by services

An open port is not automatically a vulnerability. Its severity depends on the service, exposure, configuration and available evidence.

Public web exposure

EightScope may assess

  • exposed environment or configuration files
  • exposed source-control paths
  • backup files
  • directory listings
  • public API documentation
  • debug interfaces
  • login and administration panels
  • WordPress-specific exposure
  • public email addresses
  • first-party JavaScript files containing secret-like patterns
  • outdated front-end libraries
  • publicly linked cloud-storage resources

Secret detection is pattern-based. A matching value may be a real credential, a test value or a false positive and should be validated before action is taken.

Attack-surface and brand signals

EightScope may assess

  • discovered subdomains
  • Certificate Transparency activity
  • possible subdomain-takeover conditions
  • lookalike or typosquatted domains
  • unusual public assets
  • domain-reputation signals
  • Safe Browsing signals when the required provider integration is configured

When a provider integration is unavailable, the result must be shown as not assessed rather than passed.

Essential Eight external indicators

EightScope maps relevant findings to externally observable Essential Eight risk indicators.

This mapping is provided to help customers organise risk. Many Essential Eight controls cannot be reliably assessed from the public internet, including internal application control, patch-management processes, administrative privileges, MFA coverage, backup practices and internal Microsoft Office settings.

The mapping is not an Essential Eight maturity assessment or compliance certification.

Asset coverage

Discovery does not equal assessment.

EightScope lists the hostnames it discovers, but not every discovered hostname receives every security check during a single scan.

DNS coverage

DNS resolution is attempted for discovered in-scope hostnames. Hostnames that do not resolve, return unsafe addresses or produce lookup errors are kept in the inventory with an appropriate status.

HTTP and HTTPS reachability

Reachability probing is capped and prioritised. A hostname that was not probed must be shown as not probed, not as unreachable or secure.

TLS and HTTP-header coverage

For Standard and Full scans, EightScope assesses:

  • the verified root domain
  • up to 20 selected non-root hostnames

For Quick scans, TLS and HTTP headers are assessed on the verified root domain only.

For non-root hostnames, reachable HTTP or HTTPS services are prioritised. Within those groups, www and security-sensitive hostnames receive higher priority, followed by deterministic hostname ordering.

Hostname-aware assessment

TLS and HTTP headers are assessed separately for each hostname using the hostname’s own TLS SNI and HTTP Host identity.

Two hostnames are not treated as equivalent merely because they use:

  • the same IP address
  • the same hosting provider
  • the same reverse proxy
  • the same CDN

This matters because different hostnames on shared infrastructure can present different certificates, redirects, headers, applications and security configurations.

Coverage states

Assessed

The module completed meaningful checks against the asset.

Not assessed

The asset was discovered but the module did not run or was outside the applicable scan limit.

Not probed

The asset was discovered but was not selected for an HTTP or HTTPS reachability probe.

Blocked for safety

The hostname resolved to a non-public or otherwise unsafe destination.

Assessment error

The check began but could not complete because of a timeout, connection problem or scanner error.

Inconclusive

The scan collected some evidence but could not make a reliable pass or fail decision.

None of these incomplete states should be interpreted as confirmation that an asset is secure.

Findings, severity and confidence

Finding status

Finding status meanings
StatusMeaning
PassThe tested condition met the check’s requirements at the time of the scan.
FailEvidence indicates a security issue or unsafe condition.
WarningEvidence indicates a weakness, concern or condition requiring review.
InconclusiveThere was not enough reliable evidence to make a pass or fail decision.
Skipped / not assessedThe check did not run or could not safely complete.

Only open Fail and Warning findings can reduce the headline posture score. Passed, skipped and inconclusive findings do not reduce it.

Severity

Severity meanings
SeverityGeneral meaning
CriticalDirect or severe exposure that may enable serious compromise and requires immediate review.
HighMaterial security weakness with significant potential impact.
MediumMeaningful weakness with lower immediate impact or exploitability.
LowSecurity-hardening or hygiene issue with limited direct impact.
InformationalContext that may help investigation but does not directly reduce the score.

Severity represents EightScope’s assessment of the observed external condition. It is not a complete business-risk calculation because EightScope does not know every asset’s business value, data sensitivity or internal compensating controls.

Confidence

Confidence levels and score treatment
ConfidenceMeaningScore treatment
ConfirmedDirect evidence supports the finding.Full severity deduction.
LikelyEvidence strongly suggests the finding, but manual validation may still be needed.Half severity deduction, rounded down.
PossibleA weak or indirect signal requires validation.No score deduction.

Possible findings remain visible so customers can investigate them without allowing uncertain detections to unfairly damage the headline score.

How the posture score works

Headline score

The EightScope posture score starts at 100 and subtracts points for open findings.

Score deductions by severity and confidence
SeverityConfirmed deductionLikely deductionPossible deduction
Critical1260
High630
Medium310
Low100
Informational000

Likely deductions are calculated at half weight and rounded down to a whole point. The final score is limited to a range from 0 to 100.

Repeated findings and score caps

EightScope avoids allowing one repeated configuration problem to overwhelm the headline score.

For host-level configuration checks, such as the same missing security header appearing across many hostnames, only the worst scoring instance from that check family contributes to the headline score.

Every affected hostname remains visible in the findings and asset inventory.

Distinct exposures can still contribute separately when they represent separate security targets, including:

  • different open ports
  • different exposed files
  • different URL paths
  • different API endpoints

Duplicate cookie-security findings covering the same cookie are collapsed to the worst relevant instance for scoring.

Module scores

Individual module scores are intended for drill-down and may use module-specific behaviour. They may not exactly match the calculation used for the overall headline score.

Letter grades

Letter grades from numeric score
ScoreBase grade
90 to 100A+
80 to 89A
70 to 79B
60 to 69C
40 to 59D
Below 40F

Grade safety rules (ceilings only; never upgrades):

  • A confirmed Critical finding prevents the grade from being higher than C. It cannot improve a lower grade.
  • Scores below 40 remain F, even when a confirmed Critical finding exists.
  • Three or more High findings that are not classified as Possible also prevent the grade from being higher than C.

These ceilings prevent a high numeric score from hiding severe findings. They never raise a poor grade.

Optional AI-assisted wording

Optional AI-assisted report wording never changes findings, evidence, severity, priority, score or grade. EightScope remains authoritative for those results.

When enabled, AI may only write an executive summary, rewrite or summarise existing EightScope explanations and remediation guidance for up to eight findings in EightScope's existing priority order, and paraphrase scan limitations. It is not used as an authoritative source for new findings, CVEs, evidence, severity, priority or remediation.

Inputs are allowlisted and sanitised. EightScope does not send the complete scan result, raw evidence, hostnames, email addresses, IP addresses or WHOIS records to the model by design.

Generated output is validated. Output that introduces unsupported claims or structural changes is rejected and is not stored or displayed.

When AI-assisted wording is enabled and a generation runs, processing uses Amazon Bedrock in the Sydney region (ap-southeast-2).

AI-assisted wording is optional and off by default. Opening a saved report or downloading a PDF reads stored ready output only and does not call the model again.

Related disclosures: Trust Centre · Privacy Policy · FAQ

Monitoring and change tracking

Scheduled monitoring

EightScope monitoring runs scheduled batch rescans using the frequency and scan depth available on the customer’s plan and domain settings.

Scheduled monitoring is not real-time or continuous surveillance. Changes that occur between scheduled scans may not be detected until the next scan runs.

Scheduled monitoring scans do not consume the customer’s manual monthly scan credits.

Comparable scans

EightScope avoids claiming that a finding was fixed when the later scan did not reassess it.

Finding comparisons require suitable coverage, generally:

  • the same scan type, or
  • an equivalent set of attempted modules
  • a completed scan rather than a partial scan
  • successful reassessment of the relevant asset and module

For example, a Quick scan must not mark a Full-scan finding as resolved when the Quick scan did not run that module.

Finding identity

Findings are tracked using stable information including:

  • affected asset
  • scan module
  • check identifier
  • relevant port, path, file or endpoint

This allows the platform to distinguish between new findings, ongoing findings, resolved findings, severity changes and asset-specific changes.

Methodology changes

When EightScope changes its asset-coverage or finding-identity methodology in a way that would make historical comparisons misleading, the methodology version is changed.

Scans using incompatible methodology or coverage should not be presented as directly comparable without a clear warning.

Interpreting score changes

A lower score does not always mean security became worse. It may also occur because:

  • a deeper scan type was used
  • more assets were discovered
  • more modules completed successfully
  • a previously unreachable asset became assessable
  • the scoring methodology changed

The scan comparison should explain these coverage differences wherever possible.

Known limitations

EightScope does not perform

  • authenticated application testing
  • SQL injection or cross-site scripting exploitation
  • form fuzzing
  • payment-flow testing
  • credential attacks
  • internal network scanning
  • endpoint or device assessment
  • identity-provider or MFA configuration review
  • source-code analysis
  • cloud-account CSPM for AWS, Azure or Google Cloud
  • full Essential Eight maturity assessment
  • exhaustive UDP scanning
  • guaranteed discovery of every subdomain, asset or DKIM selector

Other limitations

  • firewalls, WAFs, CDNs and rate limits can affect results
  • public certificate and DNS data may be incomplete or delayed
  • technologies can hide or falsify version information
  • network timeouts can prevent checks from completing
  • a public service can change immediately after a scan
  • CVE matching depends on reliable technology and version detection
  • secret-pattern and exposure checks can produce false positives
  • some vulnerabilities cannot be identified without authentication or exploitation
  • Safe Browsing and other third-party checks depend on provider availability and configuration

EightScope is one layer of a security program. Important findings should be validated, prioritised using business context and combined with internal security testing where appropriate.

How to use your results

  1. 1Review Critical and High findings first.
  2. 2Confirm whether the affected asset is still required and intended to be public.
  3. 3Validate Likely and Possible findings before making disruptive changes.
  4. 4Review every asset marked Not assessed, Not probed, Blocked or Error.
  5. 5Follow the finding’s remediation guidance and keep evidence of the change.
  6. 6Rerun the same scan type to confirm remediation.
  7. 7Investigate newly discovered hostnames and unexpected score changes.
  8. 8Use Full scans periodically for broader coverage, not only after an incident.
  9. 9Combine EightScope with internal vulnerability management, patching, access control, backups and incident response.