
index=certificates not_after>-1d not_after<30d | table cn renewed grade ip issuer not_after tags last_seenRun in ShadowTrackr index=websites security_txt_exists=1 security_txt_valid=0 last_seen>-7d | table url security_txt_exists security_txt_valid security_txt_errors https_status tags last_seenRun in ShadowTrackr A security summary in your inbox every Monday morning, before your work week starts. It focuses on what changed and what needs attention.
Add as many recipients as you like; they do not need a ShadowTrackr account. This is the only report that is emailed by default.
$weekly_pdf_reportRun in ShadowTrackr Shows only the software versions on your assets that have known vulnerabilities.
Critical CVEs (CVSS 9 or higher) are shown in red: patch these immediately. Fix the others promptly too, because these assets face the internet and attackers actively look for them.
$software_vulnerabilities_report AND last_seen>-7dRun in ShadowTrackr Shows software on your assets with vulnerabilities that attackers are known to exploit right now. This is your most urgent patching list.
$exploited_vulnerabilities_report AND last_seen>-7dRun in ShadowTrackr Matches the software on your assets with CISA's Known Exploited Vulnerabilities (KEV) catalog.
Ideally this report is empty. Every match is an actively exploited vulnerability on your infrastructure and needs immediate action.
$cisa_vulnerabilities_report AND last_seen>-7dRun in ShadowTrackr The products exploited most often in the last three months, according to US CISA. Use it to decide which software to patch and harden first.
index=cves cisa>0 cisa_date_added>-3m by cisa_productRun in ShadowTrackr Actively exploited CVEs that US CISA added in the last month.
Patch every entry as soon as possible, and no later than the due date CISA sets.
index=cves cisa>0 cisa_date_added>-1m | table cve cvss_score cvss_severity cisa_vendor_project cisa_product cisa_date_added cisa_due_dateRun in ShadowTrackr Tests your domains against modern internet standards, using the Internet.nl method. It covers HTTPS and TLS configuration, DNSSEC, IPv6, HSTS, email security standards and modern encryption.
Only main domains (such as example.com) are included by default. To add a subdomain, open its URL page, click the action menu (three dots, top right) and choose Add to internet standards report.
$internet_standards_report AND last_seen>-7dRun in ShadowTrackr Grades every certificate against the NCSC-NL TLS guidelines (version 2025-05), the baseline most Dutch organisations are held to. This is a much stricter standard than the SSL Labs grade shown elsewhere.
Each certificate is rated per section: TLS versions, cipher suites, key exchange, authentication, and options such as compression, renegotiation and 0-RTT. Ratings use the guideline's four levels: Good, Sufficient, Phase out and Insufficient.
A section is only as strong as its weakest setting, and the certificate only as strong as its weakest section. Hover over a rating to see why it was given. In this version of the guideline, all CBC cipher suites and all DHE key exchange are rated Phase out.
$ncsc_tls_report AND last_seen>-7dRun in ShadowTrackr Shows for each of your servers whether its encryption is quantum-safe. Attackers can record encrypted traffic today and decrypt it once quantum computers are powerful enough ("harvest now, decrypt later"). Quantum-safe encryption prevents this.
We check web encryption (TLS) and remote login (SSH) on every server. Each server is Quantum-safe, Partly quantum-safe, Outdated version, Not quantum-safe, or Not checked yet, and gets a score from A+ to F. Those scores are averaged into one score for your organisation.
Addresses behind a service like Cloudflare show that service's settings, not your own server's. The report marks them and gives a separate score for your own servers.
$post_quantum_cryptography_report AND last_seen>-7dRun in ShadowTrackr Shows the email security of your domains. Google, Microsoft and other large providers reject mail from servers without proper MX, SPF, DMARC and DKIM records. Every red or orange indicator is a deliverability or spoofing risk.
Domains that never send email still need basic MX, SPF and DMARC records, so nobody can send email in their name.
$mailservers_report AND last_seen>-7dRun in ShadowTrackr Shows every security.txt file on your assets that contains errors, with the exact error and where it is.
URLs without a security.txt file are not listed here; see the Missing security.txt Report for those.
index=websites security_txt_exists=1 security_txt_valid=0 last_seen>-7d | table url security_txt_exists security_txt_valid security_txt_errors https_status tags last_seenRun in ShadowTrackr Lists all URLs without a security.txt file. A valid security.txt tells security researchers how to report vulnerabilities to you.
For files that exist but contain errors, see the Security.txt Validation Report.
index=websites security_txt_exists=0 last_seen>-7d | table url security_txt_exists security_txt_valid https_status tags last_seenRun in ShadowTrackr Shows your supply chain on a world map, with every supplier found for your assets.
Below the map, a table lists the suppliers by number of assets and shows who controls each one: Sovereign European, Fully European, European subsidiary, or Non-European.
$supplier_dependency_report AND last_seen>-7dRun in ShadowTrackr Your vulnerabilities that were resolved in the last week.
A CVE counts as resolved when it is patched, withdrawn or marked as a false positive, or when the software can no longer be detected.
index=cves_assets resolved=True resolved_at>-7d | table cve cvss_score asset software resolved_at resolved_reasonRun in ShadowTrackr Checks whether your websites place cookies before the visitor has responded to a consent request. That may violate the GDPR and Article 5(3) of the European ePrivacy Directive (2002/58/EC).
cookie_on_load True means a cookie is set on first load, before any interaction; False means none is. A functional cookie set this way is not necessarily a violation.
index=websites (http_cookie_on_load=1 OR https_cookie_on_load=1) | table url, ip, tags, http_cookie_on_load, https_cookie_on_loadRun in ShadowTrackr Lists all software detected on your assets. Critical vulnerabilities (CVSS 9 or higher) are shown in red and should be patched immediately.
Detection is fully passive: we fingerprint what your assets already expose and never run login attempts, scripts or exploits. CVE data and CVSS scores come from MITRE and NIST.
$software_overview_report AND last_seen>-7dRun in ShadowTrackr Shows the ways into your infrastructure from the internet: RDP, SSH, VPN endpoints and database logins. Attackers target these services to get in.
Keep them patched and use multi-factor authentication where possible. Put services such as Microsoft Terminal Services and database logins behind a VPN: exposed directly to the internet, they are one exploit or leaked password away from a breach.
$remote_login_services_report AND last_seen>-7dRun in ShadowTrackr Checks your internet-facing assets against multiple blocklists. If an asset is listed, get it removed right away, before it hurts your email delivery or reputation.
Assets that are still listed have a red Last seen date; removed entries are shown in black. Informational listings, such as Tor exit nodes or Bitcoin nodes, are included too.
$blacklisted_assets_report AND last_seen>-7dRun in ShadowTrackr Groups your assets by cloud provider. For each provider, the domains shown have at least one subdomain hosted there, not necessarily all of them.
Click a provider name to see the details.
$cloudprovider_report AND last_seen>-7dRun in ShadowTrackr An overview of all domains found in your assets.
Even if a domain does not use email, give it an SPF null record (v=spf1 -all) so email providers can block anyone who abuses it for spam or phishing. For stronger protection, add DNSSEC, DKIM and DMARC as well.
$domains_report AND last_seen>-7dRun in ShadowTrackr Lists domains that expire within the next 30 days. Renew them in time: once a domain expires, someone else can register it and use it for phishing or point it at a competitor.
The Dutch registry does not publish expiry dates, so .nl domains do not appear here.
index=domains expiration_date < 30d AND expiration_date !="0000-00-00 00:00:00" AND last_seen>-7dRun in ShadowTrackr Finds look-alike versions of your domains (typos, misspellings, and letters swapped for numbers) that are registered and in use. Many more variations are checked behind the scenes; only the ones in use are shown.
For each match we check the nameservers, mailservers and website content to help you judge whether it is malicious. If it is, contact the hosting provider's abuse team and ask them to take it down (notice and takedown).
$phishy_domains_report AND last_seen>-7dRun in ShadowTrackr Grades your websites on common security measures: secure HTTP headers, secure cookies, Content Security Policy (CSP) and Subresource Integrity (SRI). Grading follows the Mozilla Observatory method.
CSP and SRI are rarely used, yet they give strong protection against cross-site scripting (XSS) and data-injection attacks.
$websites_report AND last_seen>-7dRun in ShadowTrackr Shows only the websites with security issues. Use it as your to-do list: every entry needs attention.
index=websites problem=1 AND last_seen>-7d AND ip!=urlRun in ShadowTrackr The detailed test results behind your website grades, per HTTP header and security control, following the Mozilla Observatory method.
Most scores improve with a change to your webserver configuration. CSP can take more work; the other headers are usually quick to fix.
$websites_security_report AND last_seen>-7dRun in ShadowTrackr Lists websites that are not yours but run on the same shared hosting as yours. If any of them is a risk to your organisation, ask your hosting provider for a change.
If some of these websites are yours after all, you can find them under Suggestions and add them as assets.
$shared_hosting_report AND last_seen>-7dRun in ShadowTrackr Lists all hosts seen in the last 7 days. Use it to keep your inventory up to date, spot new or unexpected hosts, and confirm that decommissioned systems are really gone.
$hosts_report AND last_seen>-7dRun in ShadowTrackr Shows hosts with insecure or misconfigured ports open to the internet, including services without proper TLS encryption.
Without TLS, traffic can be intercepted, which allows eavesdropping, session hijacking and stolen credentials. Fix every finding in this report as a priority.
index=hosts problem=1 AND last_seen>-7dRun in ShadowTrackr Lists ports that are rarely open on internet-facing hosts. Standard web (80, 443), email, FTP and SSH ports are left out.
Our scanning nodes identify the protocol actually running on each port, so SMTP on port 2525, for example, is recognised as SMTP.
$rare_ports_report AND last_seen>-7dRun in ShadowTrackr Shows hosts with open ports other than 80 and 443: the non-web services visible from the internet. Check it regularly to confirm that only the services you intend are reachable.
$non_webserver_hosts_report AND last_seen>-7dRun in ShadowTrackr Lists hosts whose IP address does not appear in any known DNS record. Such hosts are easy to overlook, so check that each one is still needed.
$hosts_without_dns AND last_seen>-7dRun in ShadowTrackr Lists all SSL/TLS certificates found on your assets. Use it to keep a complete inventory, check who issued each certificate, and spot certificates that should not be there.
$certificates_report AND last_seen>-7dRun in ShadowTrackr Shows certificates with security issues, such as weak algorithms, incorrect chains or trust problems. Investigate and fix each one to keep your connections secure.
index=certificates problem=1 AND last_seen>-7dRun in ShadowTrackr Shows certificates that expire within the next 30 days, and whether they have already been renewed. An expired certificate makes browsers show a security warning instead of your website.
Use this report to check that your renewal process works. Certificates that have already expired are shown with grade T (trust issue) in the certificates overview.
index=certificates not_after>-1d not_after<30d | table cn renewed grade ip issuer not_after tags last_seenRun in ShadowTrackr Finds DNS records that still resolve but no longer point to an active website or server. Remove them to shrink your attack surface and prevent subdomain takeover.
$stale_dns_records_report AND last_seen>-7dRun in ShadowTrackr A Sankey diagram with your domains on the left and, on the right, the nameservers that hold their DNS records. It shows which DNS providers your online presence depends on.
$dns_dependency_report AND last_seen>-7dRun in ShadowTrackr Shows where your domains, email addresses or custom keywords appeared on common dump sites and code-sharing sites.
$datadump_detections_report AND last_seen>-7dRun in ShadowTrackr Lists email addresses on your assets that appear in known data breaches, each with a compromised password.
Ask the affected users to change their passwords, and consider enforcing multi-factor authentication to protect against reused passwords.
$exposed_email_addresses_report AND last_seen>-7dRun in ShadowTrackr An overview of the internet service providers that host your assets, with their AS numbers and locations. Use it to see where your infrastructure is physically hosted and to confirm that assets are in the regions you expect.
$isp_report AND last_seen>-7dRun in ShadowTrackr