Recon workbench

Know your attack surface before someone else does

Best-of-breed open-source engines, orchestrated inside a signed scope, with every finding ranked on one explainable scale.

Coverage

What Vanguard covers

Recon, scanning and triage across web, network and code — one normalized findings model.

See the capabilities
  • 01

    Recon

    Subdomains, URL archives, ports and services, mapped and kept in scope.

  • 02

    Scanning

    Vulnerabilities, misconfiguration, secrets and TLS, in ephemeral hardened containers.

  • 03

    Priority

    Severity, CVSS, EPSS, KEV and internet exposure on one 0-100 scale.

  • 04

    Retest and reports

    One-click targeted retest, and reports in HTML, Markdown, JSON and SARIF.

Process

How it works

Explore an example engagement. Choose a target, change priority signals and check the outcome of a fix.

Interactive example. Illustrative data; no scans are run.

Scope and authorization

Define the allow-list and record the signed authorization. Nothing runs outside it.

Signed authorization
RoE
In scope
api.example.com
In scope

Target allowed within the signed authorization.

Recon and scan pipeline

Open-source engines run as ephemeral, hardened containers, pinned by digest.

Ready to explore

Discover hosts and services inside the authorized scope. The result becomes input for scoped checks.

Normalized findings model
Target
api.example.com
Severity
High
CVSS
8.0

Recon, scanning and triage across web, network and code — one normalized findings model.

Explainable priority

Every finding scored 0-100, every point shown next to the reason it was given.

40%

CVSS stays at 8.0 in this example.

Priority

63/100

P2This cycle

Severity
+38
CVSS
+12
EPSS
+8
KEV
+0
Public-facing asset
+5

Retest and reports

For template-based nuclei findings, repeat the same check on the same asset. Its result determines whether the finding remains open or becomes fixed.

Retest
OPEN

The finding remains open. The original issue is still detected.

Audit trailfinding.retest-confirmed

Report preview

HTML

Illustrative report. Changes in the example appear here; no real scan results.

Target
api.example.com
Severity
High
Priority
P2 · 63/100
Retest
OPEN
See all capabilities
Proof

Built to be audited

0
Jobs outside the allow-list, enforced before every scan
0-100
Priority scale, every point accounted for
4
Report formats: HTML, Markdown, JSON, SARIF
Capabilities

See it in the workbench

Scope and authorization, the recon and scan pipeline, explainable priority, ATT&CK coverage, retest and reports.

Vanguard findings table ranked by priority score, with KEV and EPSS badges.Vanguard findings table ranked by priority score, with KEV and EPSS badges.
Enlarge capture
Vanguard interface with example data. UI in English.

Explainable priority

Vanguard findings table ranked by priority score, with KEV and EPSS badges.Vanguard findings table ranked by priority score, with KEV and EPSS badges.

Vanguard interface with example data. UI in English.

0-100 Explainable priority
See all capabilities
Engines

Best-of-breed, orchestrated

Vanguard drives established open-source engines and normalizes their output into one findings model.

  • subfinder
  • gau
  • naabu
  • nmap
  • httpx
  • katana
  • ffuf
  • arjun
  • nuclei
  • trivy
  • sqlmap
  • dalfox
  • sslscan
  • gitleaks
  • semgrep
  • radare2

No engine licences: all open source. You keep the source, the data and the audit trail.

Why Vanguard

Why teams choose it

  1. 01

    Self-hosted, EU-native

    Findings and evidence stay on your infrastructure, not a third party’s cloud.

  2. 02

    Explainable priority

    A 0-100 score you can defend line by line, not a proprietary black box.

  3. 03

    Auditable by design

    Append-only audit log, signed authorization, kill-switch on every engagement.

  4. 04

    No lock-in

    Open-source engines, Postgres, an OpenAPI surface. Leave whenever you want.

Access

Quoted on scope

Engagement models

For one system, one release, one deadline

Assessment

On request

  • Scoped engagement with signed RoE
  • Recon, scan and manual triage
  • Prioritized report
  • Retest of fixed findings

For teams that ship every week

Continuous

On request

  • Recurring scheduled scans
  • KEV and EPSS watch on your findings
  • Webhook alerts to your chat
  • Retest cycles on every fix

For security teams, on invitation

Workbench

On request

  • Access to your engagements, on invitation
  • Findings, evidence and reports in one place
  • REST and MCP for your tools and agents
  • Org-scoped tokens and audit log
Help

FAQ

Do you scan anything without written authorization?

No. Every engagement carries a scope allow-list and a signed authorization. A job aimed outside the scope is refused before it starts, a kill-switch stops what is running, and every action lands in an append-only audit log.

Where do findings and evidence live?

On Altovar infrastructure in the EU. The AI assistance is optional, and in our deployment it runs only through Altovar’s own gateway: no finding reaches a third-party model service.

Which engines run the scans?

Established open-source engines for discovery, crawling, dynamic testing, TLS, secrets and code analysis, among them nmap, nuclei, httpx and trivy. Each runs in an ephemeral, hardened container, and public engine images are pinned by digest.

How is a finding prioritized?

With the Vanguard Priority Score: severity, CVSS, the probability of exploitation (EPSS), presence in the known-exploited catalog (KEV) and internet exposure add up to a 0-100 score. Every point is shown next to the reason it was given.

Can our tools or AI agents drive it?

Yes. A REST API described in OpenAPI and an MCP server expose the same operations, with tokens scoped to your organization. Stress testing is deliberately out of reach for agents.

Do you run denial-of-service tests?

Resilience testing is its own authorized, audited workflow with a kill-switch, run through an external legal provider you approve. Vanguard never generates flood traffic itself: no botnets, no amplification.