Vornin
Start Free
Scanner catalog

Fifteen scanners.
One signal.

Every scan type in Vornin, with what it finds, what it misses, and when to reach for it.

01 / 15
Network

Port Scanning

TCP/UDP port discovery with service fingerprinting. Identifies listening services, exposed admin interfaces, and firewall misconfigurations. Optional Nmap depth mode for OS and version detection.

Finds Open ports · exposed databases · forgotten dev tools · firewall gaps · service version disclosure
02 / 15
Encryption

SSL / TLS Analysis

Comprehensive certificate and protocol audit. Tests cipher strength, protocol versions, certificate chains, and known-vulnerability signatures. Watches for upcoming expiries.

Finds Expiring certs · self-signed chains · weak ciphers · deprecated TLS · Heartbleed · POODLE · ROBOT · missing HSTS
03 / 15
Web Application

Web Vulnerability Scanner

Crawls your site (authenticated or anonymous), then tests each endpoint for OWASP Top 10 issues. Configurable crawler depth, confidence thresholds, and authentication headers.

Finds XSS · SQL injection · CSRF · insecure headers (CSP, X-Frame-Options, HSTS) · cookie flags · directory traversal · information disclosure
04 / 15
API

API Security Scanner

REST API-specific checks. Enumerates endpoints, tests CORS, probes for auth bypass, and looks for information disclosure in error responses.

Finds CORS wildcards · auth bypass · verbose errors · stack traces · exposed GraphiQL · missing rate limits · public API docs · debug endpoints
05 / 15
Templates · Opt-in

Nuclei Template Scan

Runs the full Nuclei corpus on demand — thousands of community-maintained templates for CVEs, misconfigurations, and technology-specific signatures. Opt-in per scan; requires the Nuclei binary.

Finds Known CVEs · default credentials · exposed admin panels · tech-stack fingerprinting · misconfigured cloud services
06 / 15
DNS

DNS Security

Email authentication, zone-transfer probes, DNSSEC validation. Catches the misconfigurations attackers love — missing SPF, permissive DMARC policies, leaky zone transfers.

Finds Missing/invalid SPF · DKIM gaps · weak DMARC · zone-transfer exposure · DNSSEC failures · dangling DNS (takeover-prone)
07 / 15
Reconnaissance

Subdomain Discovery

Enumerates subdomains via DNS brute force, certificate-transparency crawl, and search-engine queries. Surfaces the staging servers and abandoned services IT forgot.

Finds Shadow IT · staging/dev environments · abandoned apps · subdomain takeover risks · wildcard DNS sprawl
08 / 15
Code Security

Static Analysis (SAST)

Semgrep-backed analysis of source repositories connected via Azure DevOps, GitHub, or GitLab. Runs on commits, pull requests, or on demand. Finds the bugs your linter won't.

Finds Injection flaws · insecure crypto · auth logic bugs · unsafe deserialization · error-handling gaps · taint-tracked data flows
09 / 15
Code Security

Secret Scanning

Gitleaks-powered sweep of repository history for API keys, tokens, and passwords. 100+ default patterns, plus custom regex rules per tenant.

Finds AWS keys · Azure tokens · DB passwords · JWTs · Slack webhooks · SendGrid keys · private keys · custom patterns
10 / 15
Supply Chain

Dependency Scanning

Trivy-backed software composition analysis. Parses lockfiles across ecosystems, cross-references NVD, and surfaces what's in CISA's Known Exploited Vulnerabilities catalog. Emits a CycloneDX SBOM for every scan.

Finds Known CVEs in NuGet / npm / pip / Maven / Go · outdated dependencies · license conflicts · KEV-listed criticals · CycloneDX SBOM
11 / 15
External Exposure

Subdomain Takeover

Combines DNS records with HTTP fingerprinting to flag abandoned DNS entries pointing at unclaimed cloud resources. Twenty-five provider signatures and climbing — GitHub Pages, S3, Heroku, Azure, Fastly, and more.

Finds Dangling CNAME → unclaimed bucket · abandoned PaaS app · orphaned CDN origin · expired SaaS tenant
12 / 15
Web / CMS

WordPress Vulnerability Scan

WPScan-grade enumeration for WordPress sites: core version, plugin and theme inventory, and cross-reference against the WPScan vulnerability database. For the one-third of the web that still runs on WordPress.

Finds Outdated core · vulnerable plugins / themes · exposed login endpoints · xmlrpc misconfigurations · user enumeration
13 / 15
Containers

Container Image Scan

Trivy-backed image analysis for Docker / OCI images — OS packages, application dependencies, and known exploit markers. Scan private registries with your own credentials; public images by name and tag.

Finds Base-image CVEs · vulnerable language packages inside the image · misconfigurations · exposed secrets embedded in layers
14 / 15
Orchestration

Kubernetes Posture

Trivy-powered Kubernetes cluster scan using a stored kubeconfig. Targets either the whole cluster (k8s://cluster) or a single namespace (k8s://namespace). Surfaces pod-level CVEs, baseline security gaps, RBAC drift, and admission-controller blind spots in one pass.

Finds Privileged pods · CVE-laden base images · over-permissioned ServiceAccounts · missing network policies · weak admission controllers · runtime-class drift
15 / 15
Cloud Posture

Cloud Security Posture

Multi-cloud CIS posture assessment using stored credentials. AWS: 15 live checks across IAM, S3, EC2, RDS, CloudTrail, KMS, Lambda, Config. Azure: 11 live (NSGs, storage, Key Vault, SQL, VM exposure, Defender, ACR). GCP: 15 live — 100% coverage (IAM, GCS, firewall, Compute, Cloud SQL, audit logging, KMS, GKE).

Finds Root accounts without MFA · stale 90-day keys · public buckets · unencrypted RDS · multi-region CloudTrail gaps · KMS rotation lapses · open NSG / firewall · stale GCP service-account keys · audit-log gaps
— Import only

Bring your own scanners.

Vornin does not run Nessus or OpenVAS for you — our fifteen built-in engines are shown above. If you already run them elsewhere, upload the XML / JSON / CSV export and Vornin drops the findings into the same deduplication, compliance mapping, evidence chain, and SLA pipeline as native scans. Fingerprinted, enriched, tracked.

Get started

Every tier, fifteen engines.

Scanner engines aren't held hostage. Every tier — Free included — ships all fifteen. The wedge is compliance breadth, retention, and auditor-pack export. See the breakdown →