Bastionize combines attack-surface discovery, authorized assessment, and audit-ready reporting in one non-intrusive workflow.
Point Bastionize at a domain and it enumerates subdomains from Certificate Transparency logs and a DNS wordlist, keeping only hosts that resolve to a public address. Every candidate passes the same SSRF/denylist guard as a scan.
DNS & mail hygiene, TLS/certificate analysis, security headers, cookies, CORS, sensitive-file exposure, open ports, technology and outdated-component detection โ non-intrusive and high-signal.
Error-based SQL injection, reflected-input, open-redirect, and deprecated-TLS enumeration unlock only after you verify domain ownership via a DNS TXT or hosted-file token. Every scan records who authorized it.
Findings are tagged to OWASP 2021 categories, with a coverage matrix across all ten โ and explicit "manual review required" notes for what a black-box scanner genuinely can't confirm.
A classified cover page, table of contents, executive summary with an overall risk rating, scope & methodology, per-target testing summary, numbered findings, and a testing-data appendix โ print to PDF.
Findings stream in real time over a live connection, with a severity-weighted AโF grade per target and per category so you can triage as the scan runs.
No exploitation, no denial-of-service, no credential attacks. A two-layer SSRF guard re-validates every outbound connection at connect time to prevent DNS-rebinding abuse.
Capture client, system, scope, testing window, tester, and classification up front โ it flows straight into the report so documentation is never an afterthought.