Work / SentinelForge
Case study 04
SentinelForge
Attack-surface discovery and security posture analysis, with the guard rails built in.
The problem
Most organisations cannot describe their own external attack surface. Somebody eventually maps it for them, and that somebody is rarely friendly.
The system
Five scanner modules under one orchestrator. Asset discovery walks root domains, subdomains, DNS records and certificates. DNS analysis checks SPF, DMARC, DKIM, CAA and DNSSEC. TLS analysis reads certificate validity, chain issues, protocol versions and cipher suites. HTTP analysis checks HSTS, CSP, X-Content-Type-Options, Referrer-Policy and cookie flags. Technology detection fingerprints frameworks, CMS, servers and CDN. Everything feeds a severity-weighted risk engine with a published methodology.
- Scope
- Infrastructure you own or are authorised to test
- Authorization
- Confirmed by the user before every scan
- Blocked
- Private IPs, localhost, cloud metadata endpoints
- Protections
- SSRF defences prevent scanning unauthorised targets
- Scoring
- Critical 10, High 8, Medium 5, Low 2, Info 0
The result
Findings carry severity, category, evidence and remediation. Reports export as JSON or PDF with an executive summary, the scope tested and recommendations. A REST API with OpenAPI documentation and JWT authentication makes it usable from other tooling, and a CLI covers every capability.
Let's build something useful.
Send the problem, not a spec. I reply with an approach and a scope I can hold to.