Features

Find it. Understand it. Prove you fixed it.

Bastionize combines attack-surface discovery, authorized assessment, and audit-ready reporting in one non-intrusive workflow.

๐ŸŒ

Attack-surface discovery

Point Bastionize at a domain and it enumerates subdomains from Certificate Transparency logs and a DNS wordlist, keeping only hosts that resolve to a public address. Every candidate passes the same SSRF/denylist guard as a scan.

๐Ÿงช

Passive & safe-active checks

DNS & mail hygiene, TLS/certificate analysis, security headers, cookies, CORS, sensitive-file exposure, open ports, technology and outdated-component detection โ€” non-intrusive and high-signal.

๐Ÿ›ก๏ธ

Authorized active testing

Error-based SQL injection, reflected-input, open-redirect, and deprecated-TLS enumeration unlock only after you verify domain ownership via a DNS TXT or hosted-file token. Every scan records who authorized it.

๐ŸŽฏ

OWASP Top Ten mapping

Findings are tagged to OWASP 2021 categories, with a coverage matrix across all ten โ€” and explicit "manual review required" notes for what a black-box scanner genuinely can't confirm.

๐Ÿ“„

Enterprise reporting

A classified cover page, table of contents, executive summary with an overall risk rating, scope & methodology, per-target testing summary, numbered findings, and a testing-data appendix โ€” print to PDF.

โšก

Live results & grading

Findings stream in real time over a live connection, with a severity-weighted Aโ€“F grade per target and per category so you can triage as the scan runs.

๐Ÿ”’

Safe by construction

No exploitation, no denial-of-service, no credential attacks. A two-layer SSRF guard re-validates every outbound connection at connect time to prevent DNS-rebinding abuse.

๐Ÿงพ

Engagement metadata

Capture client, system, scope, testing window, tester, and classification up front โ€” it flows straight into the report so documentation is never an afterthought.