FREE ATTACK SURFACE SNAPSHOT
See what attackers already know.
Enter your domain. We run passive recon across five public data sources — open ports, exposed subdomains, breach history, email spoofing exposure, and web security headers — and return a scored risk snapshot. No intrusive scanning, no account, about 60 seconds.
ATTACK SURFACE FAQ
What the snapshot checks.
What does the Attack Surface Snapshot check?
Five public data sources: open ports and services (Shodan InternetDB), exposed subdomains (certificate transparency logs), known breach history (the public breach directory), email spoofing exposure (SPF, DMARC, DKIM, MX), and HTTP security headers (HSTS, CSP, X-Frame-Options, and more). It returns a 0–100 risk score, finding cards, and prioritized recommendations.
Is this an intrusive scan?
No. The snapshot is fully passive — it only reads data that is already public. It never sends traffic that probes, logs into, or stresses your systems, so it is safe to run against your production domain.
Is the Attack Surface Snapshot free?
Yes. CannaShield provides the snapshot as a free first look for cannabis business domains. It does not replace a full vCISO assessment, which reviews internal posture passive recon can't see.
What happens after the scan?
You get your scored snapshot on screen immediately. Critical findings — like an exposed RDP port, a spoofable domain, or a known breach — map directly to CannaShield's Downtime Prevention and License Protection services.