How CheckFix Analyzes Your IT Infrastructure

Fully automated external security analysis in 24 hours. From domain to A-F Security Score with prioritized fix list.

Input
Your domain(s)
Output
Technical report + to-do list with concrete fix instructions

The CheckFix Scan in Three Steps

CheckFix

What gets scanned?

Subdomains, open ports, running services, known CVEs, TLS configuration, security headers, HTTP responses, system uptime, SSL certificates

CheckFix

How does it scan?

5 phases, 15 automated steps. Tools: nmap, Gossling SSL/TLS Scanner, nuclei, httpx, subfinder + CVE databases. Non-invasive, purely external scanning.

CheckFix

What do you get?

A-F Security Score, prioritized to-do list (Critical → Low), PDF reports, screenshots of all web services, concrete fix instructions per finding

The 5 Analysis Phases in Detail

1

Reconnaissance – Mapping Your Entire Infrastructure

CheckFix starts with subdomain enumeration via Certificate Transparency Logs, passive DNS databases, and permutation fuzzing. The tool finds not only your production systems but also forgotten development servers, old test environments, or shadow IT.

The discovered domains are resolved to IP addresses and enriched with geolocation and ASN data. This shows you which systems are running with which hosting provider and whether critical services are unexpectedly hosted in non-EU countries.

Tools: subfinder, puredns, alterx, dnsx

Finds: Forgotten dev servers, shadow IT, acquisition remnants, exposed test environments

Example finding:“staging.example.com runs on outdated software and is publicly accessible”

2

Service Discovery – Open Services and Known Vulnerabilities

CheckFix scans all 65,535 TCP ports per IP address and identifies running services: web servers, SSH, databases, mail servers, FTP, SMB, exposed admin panels. The detected software versions are automatically cross-referenced with the Vulners CVE database.

Additionally, CheckFix pulls historical data from Shodan – making visible even services that were recently closed but were exposed in the past.

Tools: nmap with Vulners integration, Shodan API

Finds: Open ports, outdated software versions, known CVEs with CVSS scores, exposed management interfaces

Example finding:“Apache 2.4.29 on port 80 → CVE-2021-41773 (CVSS 9.8) → Remote code execution possible”

3

HTTP Enumeration – Web Services Under the Microscope

All HTTP/HTTPS services are analyzed in detail: Technology fingerprinting identifies CMS systems (WordPress, Drupal), JavaScript libraries, web frameworks, and CDN providers. Outdated installations, active debug modes, or publicly accessible admin panels are immediately detected.

CheckFix automatically creates screenshots of all websites – technical findings become visually traceable. Login panels, exposed dashboards, or misconfigurations are directly visible.

Tools: httpx, headless browser (Chrome/Firefox)

Finds: Outdated CMS versions, exposed admin interfaces, directory listings, debug modes, backup files

Example finding:“WordPress 5.8 detected → 12 known vulnerabilities, update to 6.4 recommended”

4

Vulnerability Analysis – Security Headers and System Errors

CheckFix checks all HTTP services for missing or misconfigured security headers: Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy. Each missing header increases the risk of XSS attacks, clickjacking, or man-in-the-middle scenarios.

The Response Pattern Analysis correlates findings across all subdomains: If 15 different hosts use the same outdated jQuery or consistently run without HSTS, this indicates systematic infrastructure problems.

Tools: nuclei with security header templates

Finds: Missing CSP/HSTS headers, insecure cookie flags, systemic misconfigurations

Example finding:“CSP completely missing → XSS attacks possible, HSTS not set → downgrade attacks risky”

5

Advanced Analysis – TLS, Uptime and Cryptography

CheckFix performs a comprehensive TLS/SSL analysis using our in-house testing system Gossling: Which protocol versions are active? Are insecure cipher suites such as RC4 or 3DES accepted? Are certificates valid and correctly configured? Do vulnerabilities like POODLE, BEAST, or Heartbleed exist?

The grading follows the methodology defined by Qualys SSL Labs (SSL Server Rating Guide). Gossling continuously runs comparison tests against SSL Labs to ensure consistent results. No intermediate grades (+/−) are assigned: each host receives the worst TLS grade across all tested endpoints, and the average of all host grades determines the company’s overall TLS score.

Gossling is also publicly available: At gossling.checkfix.io, anyone can check the TLS configuration of their own domain for free – in line with our open-source philosophy.

The System Uptime Detection analyzes TCP timestamps and identifies servers that have been running for months without a restart – an indicator of missing security updates and unpatched kernels.

Tools: Gossling (in-house development), hping3

Finds: Insecure TLS versions, weak cipher suites, certificate issues, unpatched systems

Example finding:“TLS 1.0 still active + RC4 cipher allowed → Grade D → Downgrade attacks possible”

What You Receive After the Analysis

CheckFix automatically generates your security report and structures all findings into a prioritized to-do list:

Critical (CS1, CS2, …)

CVSS 9.0+, F-Grade

Remote code execution, exposed databases, critical misconfigurations

High (HS1, HS2, …)

CVSS 7.0-8.9, D/E-Grade

Outdated software with known exploits, missing HSTS headers

Medium (MS1, MS2, …)

CVSS 3.0-6.9, B/C-Grade

Weak TLS configuration, missing security headers

Low (LS1, LS2, …)

CVSS 0.1-2.9, A-Grade

Best-practice optimizations, minor misconfigurations

Your Deliverables

CheckFix

Executive Summary (PDF)

High-level overview for management: Security Score, critical findings, industry benchmark

CheckFix

To-Do List (Markdown)

Prioritized checklist with direct fix instructions – ready for your ticketing system

CheckFix

Technical Report (PDF)

Host-by-host analysis for security and IT teams: All details on ports, CVEs, TLS grades

CheckFix

Screenshots

Visual documentation of all web services – ideal for security reviews and audits

Each to-do contains concrete fix instructions: Which host is affected, what vulnerability exists, how to fix it. No interpreting raw data – simply work through the list from top to bottom.

Technology Stack Overview

CheckFix uses proven open-source tools and public databases:

Reconnaissance: subfinder, puredns, alterx, dnsx
Service Discovery: nmap with Vulners integration, Shodan API
HTTP Analysis: httpx, headless browser for screenshots
Vulnerability Scanning: nuclei, testssl.sh
Intelligence: IPInfo API, CVE databases

All methods are reproducible, all tools and versions are documented – ideal for compliance audits.

CheckFix is Non-Invasive and GDPR-Compliant

Non-invasiveNo exploitation, no login attempts, no brute-force attacks

Purely externalOnly publicly visible data, no agents on your servers

GDPR-compliantEU hosting, no personal data collected

Audit-readyReproducible methodology, documented tools & versions

 

Ready for Your First Security Check?

Difference from penetration testing: CheckFix identifies vulnerabilities automatically and non-invasively. A pentest actively and manually exploits them. CheckFix is ideal for regular security checks, pentests for more in-depth manual analyses after major changes.

Contact

E-mail: office@checkfix.io

Phone: +43 660 77 24 524

secinto

secinto GmbH

Poststraße 3

8530 Deutschlandsberg

Austria

E-mail: office@checkfix.com

*Studie KPMG zur Cybersecurity in Österreich 2023