Vulnerability managementLIVE
Every finding deduplicated across scans, triaged by severity, with CVSS scoring and remediation guidance built in.
Findings pile up fast once you're scanning continuously. CyberSpec's findings table is built for triage, not just listing: every finding tracks a first-seen and last-seen timestamp instead of creating a new row on every rescan, severity and status filters narrow the table down to what actually needs attention today, and bulk actions let you clear a batch of accepted risks in one pass instead of clicking through each one.
- Global findings table filterable by severity, CVE, asset, and status
- Bulk status actions — mark resolved, false positive, or risk accepted in bulk
- Automatic dedupe across repeated scans (first-seen/last-seen tracking, not duplicate rows)
- CVSS score + vector, CVE/CWE reference, and remediation guidance on every finding
Deduplication is the difference between a tool and a spreadsheet
Scan the same asset weekly and a naive scanner hands you the same finding fifty-two times. CyberSpec tracks each finding by its underlying identity — asset, host and port, and the weakness itself — and updates a last-seen timestamp instead of writing a new row. The practical effect: your open-findings count means something. It goes up when your exposure genuinely grows and down when you fix things, rather than climbing forever because the scanner has no memory between runs.
Triage in bulk, because most findings are decisions you already made
A real backlog contains a lot of findings you have already assessed: a service that is deliberately public, a CVE that does not apply to your build, a risk the business signed off on. Filter the table down to that set and mark the whole batch resolved, false positive, or risk accepted in one action. Each status change is recorded against the finding, so the next person to open it sees the decision and who made it rather than re-litigating it.
Every finding arrives with enough context to act on
Each finding carries its CVSS score and vector string, the CVE and CWE references, the exact host and port it was seen on, and remediation guidance — plus basic CVE enrichment (description and known references) folded inline. That is the difference between "port 443 is running an old OpenSSL" and a ticket an engineer can pick up without a research detour first.
Explore the rest of CyberSpec
Network scanning
On-demand and scheduled scans against domains, IPs, and CIDR ranges, with live progress and CVE correlation.
Compliance mapping
Every open finding mapped to the SOC 2, ISO 27001, and PCI DSS control families it touches — automatically.
SOC 2, ISO 27001 & PCI DSS
What CyberSpec covers framework by framework, for the compliance side of the house.
Pricing
Free for one asset, $20/month for twenty, custom above that.