CVE Tools

External security assessments

Know what your
company exposes.

Find out which internet-facing systems need attention — and give your team a clear next step.

Connect vulnerability information to your own systems with a scoped security assessment.

Request an assessment Explore an example

Your domain + work email. Scope agreed before testing.

OUTSIDE YOUR NETWORK
Your companyEXTERNAL SURFACE
Websites
APIs
Exposed services
Which are reachable? Which need a closer look?Scope illustration · not a live scan
A CVE is a starting point.

Your product Your configuration Your exposure Your next action

People behind the assessments.

Personal qualifications held by individual specialists involved in assessments. These are not certifications of CVE Tools as a company.

  • OSCP
  • OSWP
  • OSWA
  • HTB CPTS
  • C|EH Master
  • ISO/IEC 27001 Lead Auditor

From observation to action

A finding should
lead somewhere.

See how a security review connects an exposed system to evidence and a useful next step.

Illustrative scenario · not a customer report
CVE TOOLS / REVIEW METHOD
OBSERVATION

An administration page is reachable.

In this example, an administration page can be reached from the public internet. That alone does not establish a vulnerability.

Is public access intentional?

Establish ownership, purpose and intended access before deciding what to test.

Checked once.
Changed since.

New deployments and new vulnerability information can change what needs attention. Regular checks help you revisit the picture.

  1. 01

    Establish the baseline

    Agree the assets and checks. Understand the starting point.

  2. 02

    Something changes

    A service goes online. A configuration changes. A CVE is published.

  3. 03

    Review what matters

    Assess relevance and agree further checks or remediation.

  4. 04

    Check the follow-up

    Discuss how to verify fixes and revisit open questions.

Illustrative workflow. Monitoring coverage and frequency are agreed separately.

Keep watch.
Or take a closer look.

Start with the question you need answered. You can request a specific assessment without a monitoring subscription.

01

Regular external checks

For tracking changes across internet-facing systems and following the status of known issues.

Continuity · Changes · Priorities
02

Specialist assessment

For investigating a specific network, web application or API — including access controls and application logic.

Defined scope · Evidence · Recommendations

Start with your company

What needs
a closer look?

Start with your company domain and work email. The CVE Tools team will contact you to discuss the assessment.

  1. 1Send your domain and work email.
  2. 2Discuss scope, price and timing with our team.
  3. 3Authorize the agreed testing.

No account needed. Only submit systems you own or are authorized to discuss.

Vulnerability of interest: CVE-2011-1823. We will include this in your request.

Add more assets (optional)

Additional domains or public IP addresses, separated by commas, spaces or new lines.

Tell us about yourself (optional)

Sending a request does not commit you to a purchase. Privacy policy.

A few practical
questions.

Does submitting a domain start a scan?

No. It sends a request to the CVE Tools team. We contact you to agree which systems to assess, the approach and the expected results. Active testing requires your explicit authorization.

What does an assessment cost?

The scope, price and timing are agreed before work begins. Sending a request does not commit you to purchasing an assessment or subscribing to monitoring.

Can you check a specific CVE?

Tell us which CVE concerns you. We first establish whether the affected product, version and configuration are relevant to your systems, and agree which checks are appropriate.

Is this a penetration test or regular monitoring?

You can discuss either. Regular external checks help track changes over time. A penetration test is a separately scoped assessment that can investigate attack paths and application logic in more depth.

Do I need an account or software to send a request?

No. Start with your company domain and work email. Any access or setup required for the assessment is discussed when agreeing its scope.