The platform
One engine, from discovery to the board brief.
Verskop follows the same path an adversary would. It maps your external footprint, correlates it against live intelligence, and tests what is exploitable. Then it reports the result in terms a board can act on, and keeps watching as the surface changes.
External discovery
Verskop enumerates the attack surface an outsider can reach without touching anything they should not: subdomains, live hosts, open ports, TLS certificates, and the technology stack behind each service. It resolves what is really there and filters out wildcard noise and duplicate aliases, leaving an asset count that reflects what is genuinely exposed.
- Subdomain and host discovery with wildcard and alias de-duplication
- Port and service exposure, cleartext services flagged
- Certificate and TLS posture
- Per-host technology fingerprinting, version-confirmed where the evidence allows
Vulnerability intelligence
Detected software is matched to live vulnerability intelligence drawn from multiple sources. Verskop blends NVD, CISA KEV, and EPSS with additional advisory sources. Coverage holds even if one source goes quiet, and corroborating a finding across several of them raises confidence in the result.
- NVD, CISA Known Exploited Vulnerabilities, and EPSS exploit-probability scoring
- Multi-source corroboration for client-side and package-level flaws
- Version-aware matching that keeps a patched host from being flagged for an old CVE
Exposure validation
Correlation surfaces what could be exploitable, and Verskop then tests it directly. Its adversary emulation runs against the real target to confirm whether the exposure is genuine, and it never runs without authorization. Each finding comes back with the evidence that supports it.
- Authorization-gated active testing, verified before a single packet is sent
- Exploitability confirmed against the live target, going beyond what a version number can tell you
- Foothold and attack-path context mapped to MITRE ATT&CK
Compliance mapping
Findings map to regulatory frameworks with real enforcement precedent, and the whole step is opt-in. Verskop suggests what may apply based on what your site does, and the choice of framework stays with you. It shows a framework's penalty and enforcement baseline even when you have zero findings against it.
- 48 frameworks, including CMMC, NIST 800-171, NIST CSF, HIPAA, PCI DSS, CJIS, and SOC 2
- Opt-in by design, with suggestions grounded in observed capability
- Enforcement precedent shown, with the real cost of a violation
Executive reporting
The output is a finished brief a board can act on. FAIR quantifies the financial exposure, the attack narrative is written in STRIDE and ATT&CK terms, and the CVE and KEV citations stay in place while the tooling names are left out.
- FAIR-based financial exposure, aggregated per asset to avoid double-counting
- STRIDE and MITRE ATT&CK narrative a non-specialist can follow
- A finished brief, with the citations that back every claim
Continuous monitoring
Your exposure changes from one week to the next. Verskop re-scans on a schedule and flags new exposure as soon as it appears. A certificate nearing expiry, a newly opened service, or a freshly disclosed CVE against your stack shows up in the next scan, while there is still time to act on it.
- Scheduled re-scans with change detection
- New exposure and newly weaponized CVEs surfaced as they land
- A running record that ties each scan to the one before it
How grading works
Every finding graded confirmed or assessed.
Confirmed means Verskop observed it on the live host and can cite the evidence. Assessed means it was inferred and belongs in a verify tier, out of the risk total and out of the financial exposure until someone checks it.
A version-less product is never counted as a confirmed exposure. That keeps the headline number honest, and it holds up when an auditor or a contracting officer checks the work.
Observed on the live host. Server-side path traversal on CISA's Known Exploited Vulnerabilities list.
The stack suggests PHP, but no version was observed. Listed to verify, never counted as a confirmed exposure.
The standards this rests on
Every finding traces to one of these public authorities, so a reader can check it outside Verskop. The only claim that is ours is what Rampart Cybersecurity LLC and Verskop do.
See it on your domain
Point it at what you protect.
We will run it and walk you through the brief, with the evidence behind every finding.