Skip to content
Service 08

Vulnerability Scanning

Ad-hoc or recurring scans, with the raw output plus an analyst pass that separates the findings that matter from the noise.

Need a scan?

Brackish runs vulnerability scans on demand or on a regular cadence, using several different tools rather than relying on any single engine's coverage.

You get the raw output — it is your data, and some compliance processes require it. But raw scanner output is not a security deliverable. Our team works through it, removes what does not apply to your environment, and prioritizes what is left according to the risk it actually represents to you.

Where scanning fits

Scanning is a hygiene control. It is good at telling you that a known vulnerability exists on a host you own, and it is fast and cheap enough to run frequently. That makes it a sensible thing to do between engagements.

It is not a penetration test. A scanner cannot chain two low-severity findings into a critical one, cannot reason about your business logic, and cannot tell you that the "informational" finding on one host becomes serious because of what it is connected to. If you need to know how you would actually be breached, you need a penetration test. If you need to know whether last month's patches landed, a scan will tell you.

Why work with us

Decades of penetration testing experience. The people reviewing your scan output are the same people who conduct our testing engagements, so the triage reflects what is genuinely exploitable.

Award-winning bug bounty research. Our testers find novel vulnerabilities in their own research, which is a different skill from reading a scanner report and a useful one to have applied to yours.

Straight answers. If a finding does not matter in your environment, we say so. Padding a report with theoretical issues wastes your remediation budget.

What you receive

The raw scanner output, a triaged and re-prioritized findings list with false positives removed, and a short summary of what changed since the previous scan where you are on a recurring schedule.

Common questions

Vulnerability Scanning — what clients ask

Is a scan the same as a penetration test?
No, and anyone selling it as one is misleading you. A scan compares what it observes against a database of known issues. A penetration test involves someone actively trying to break in, chaining findings and exploiting logic no scanner understands. Scanning is a good recurring hygiene control and a poor substitute for testing.
What does the analyst pass actually add?
Scanners over-report. They flag issues that do not apply to your configuration, rate findings on generic severity rather than your exposure, and miss context that changes the priority entirely. Our testers work through the output, discard what is not real, and re-rank what is left against your environment.
Can you run scans on a recurring schedule?
Yes. Monthly or quarterly scanning against your external estate is a reasonable baseline between penetration tests. If you want continuous coverage with validation rather than periodic snapshots, attack surface management is the better fit.

Strengthen your defenses.

Tell us what you need tested. We’ll come back with scope, timeline, and a fixed price.

Request a quote