# S4E S4E is a **Continuous Threat Exposure Management (CTEM)** platform for all business sizes. It is an AI-powered cybersecurity solution that helps individuals and organizations manage their digital risks through continuous asset monitoring, vulnerability scanning, and automated reporting. ## Key Pages ### Platform [Platform](https://s4e.io/platform) — Overview of the S4E platform: features include the intuitive dashboard, asset management tools, scan manager workflows, AI-generated scans, awareness training, expert support services, and advanced reporting capabilities. ### Free Security Tools [Free Security Tools](https://s4e.io/free-security-tools) — A suite of free, web-based security tools provided by S4E to perform quick scans and gather vulnerability data with downloadable outputs like PDF, CSV, HTML, and video. ### Features - [Website Security Check](https://s4e.io/features/website-security-check) — Conduct free full or light website scans that cover common misconfigurations, network and web vulnerabilities, with visual report summaries. - [AI-Based Security Scanner](https://s4e.io/features/ai-based-security-scanner) — Users describe what they want to scan in plain language; S4E’s AI generates and runs the appropriate scan code in real time. - [AI-Based Solutions](https://s4e.io/features/ai-based-solutions) — Transforms scan results into prioritized, actionable remediation steps tailored to user configurations, enabling fast and precise fixes. - [ASV PCI Compliance Scan Report](https://s4e.io/features/asv-pci-compliance-scan-report) — Provides PCI DSS compliance scan reports through Approved Scanning Vendor (ASV) certification, delivering audit-ready documentation and continuous compliance support. ### Scan Parent - [Informational](https://s4e.io/scan/parent/informational) — Low/no-risk findings for informational purposes. Often best practice tips or config hints. - [Denial of Service (DoS)](https://s4e.io/scan/parent/denial-of-service) — Resource exhaustion attacks causing downtime. Mitigate via rate limiting, WAF, monitoring. - [Malware Detection](https://s4e.io/scan/parent/malware-detection) — Detects unauthorized malicious software. Requires removal, source analysis, and hardening. - [Improper File Process](https://s4e.io/scan/parent/improper-file-process) — Unsafe file handling (LFI/RFI, uploads, traversal). Fix via validation, type restrictions, secure paths. - [Insecure Authorization](https://s4e.io/scan/parent/insecure-authorization) — Weak resource access control (e.g., IDOR). Enforce strict role/permission checks. - [Insecure Authentication](https://s4e.io/scan/parent/insecure-authentication) — Weak identity verification (e.g., poor passwords, no MFA). Improve login security and session management. - [Security Misconfiguration](https://s4e.io/scan/parent/security-misconfiguration) — Unsafe default settings or open services. Apply secure configs, least privilege, and reviews. - [Unsupported / Outdated Software Usage](https://s4e.io/scan/parent/unsupported-outdated-software-usage) — Outdated/unpatched/EOL software. Patch or replace promptly. - [Injection](https://s4e.io/scan/parent/injection) — Unvalidated input to interpreters (SQL, Command Injection, XXE). Use validation and parameterized queries. - [Missing / Weak Encryption](https://s4e.io/scan/parent/missing-weak-encryption) — Plaintext or weak crypto. Use strong encryption, proper key management, and TLS. ### Scan Categories S4E scans cover a wide range of categories. Below is the full list of supported categories: - **DNS Controls** — Health and security check related to DNS - **SSL Controls** — Health and security check related to SSL - **Misconfiguration** — Misconfiguration controls for apps and services (default pages, default passwords, default configs, backup file scans, etc.) - **Network Vulnerabilities** — General network vulnerabilities (basic passwords for services, lack of hardening for services, etc.) - **Web Vulnerabilities** — Crawler & Web vulnerabilities (automated crawler and web app vulnerabilities) - **Information Scans** — Information discovery scans (tech detection, leaked credentials, email harvesting, open ports, services, etc.) - **Product Based Web Vulnerabilities** — Product-based web vulnerabilities (WordPress, Joomla, IceWarp, etc.) - **Product Based Network Vulnerabilities** — Product-based network vulnerabilities (ProFTPD Backdoor, Apache DoS, Microsoft Exchange vulnerabilities, etc.) - **Exposed Panels** — Exposed and accessible administrative or debug panels (phpMyAdmin, Elasticsearch dashboards, etc.) ### Pricing & Plans | Plan | Price | Key Features | |----------------|----------------------|--------------| | **Everyone** | Free | Unlimited asset verification, Security scans, Reports, API access, Extension usage, Weekly quizzes, Security bulletins. | | **Expert** | $190/year - $19/month| Everything in Everyone + Low-skill required, 1 Advanced Security Asset. | | **Elite** | $690/year - $69/month| Everything in Expert + 10 Advanced Security Assets, Customizable dashboards, Threat intelligence, AI-based risk prediction. | | **Enterprise** | Contact | Everything in Elite + Team management, Integrations, Enterprise-grade support. | #### Pricing Overview [Pricing](https://s4e.io/pricing) — High-level view of S4E’s subscription tiers and pricing structure. Everyone: Free, Expert: $19/mo, Elite: $69/mo, Enterprise: Contact. #### Plans - [Everyone Plan](https://s4e.io/plans/everyone) — Free tier: access to security tools, report generation, and scan features without verification. Advanced Security Assets: 0. 1 Full scan per month. - [Expert Plan](https://s4e.io/plans/expert) — Intended for small to medium businesses needing enhanced scanning and compliance features. Advanced Security Assets: Up to 1. 1 Full scan per day. - [Elite Plan](https://s4e.io/plans/elite) — Designed for advanced users and security teams managing multiple assets; includes continuous monitoring and priority support. Advanced Security Assets: Up to 10. Unlimited full scan. ## Scan Types Comparison - [Scan Comparison](https://s4e.io/scans-comparison): Guide comparing Single, Light, Full, Continuous, and Crawl-only scans. ### Scan scope | | Single Scan | Light Scan | Full Scan | Continuous Security | Crawl Only | |-----------------------|---------------|-------------|-------------|---------------------|-------------| | **Scope** | Only one URL | Domain or IP| Domain or IP| Domain or IP | Domain or IP| | **Security Check #** | 1 | 1000+ | 7500+ | 7500+ | None | | **Application Crawling** | No | Yes | Yes | Yes | Yes | ### Features | | Single Scan | Light Scan | Full Scan | Continuous Security | Crawl Only | |-------------------------------|-------------|------------|-----------|---------------------|----------------| | **Start with** | Manually | Manually | Manually | Automatically | Manually | | **Automatic scheduling** | No | No | No | Yes | No | | **AI-Powered Crawler** | No | Yes | Yes | Yes | Yes | | **Historical Report** | Yes | Yes | Yes | Yes | Yes | | **Newly Discovered Vulnerability Checks** | No | No | No | Yes | No | | **Available at** | Free | Free | Free One Per Month | Expert, Elite, Enterprise | Free | | **Output at** | Scan Reports| Scan Reports| Scan Reports| Scan Reports | Crawler Results | ### Scan Categories | | Single Scan | Light Scan | Full Scan | Continuous Security | Crawl Only | |-----------------------------------|-------------|------------|-----------|---------------------|------------| | **DNS Controls** | No | Yes | Optional | Optional | No | | **SSL Controls** | No | No | Optional | Optional | No | | **Misconfiguration** | No | Yes | Optional | Optional | No | | **Network Vulnerabilities** | No | No | Optional | Optional | No | | **Web Vulnerabilities** | No | No | Optional | Optional | No | | **Information Scans** | No | Yes | Optional | Optional | No | | **Product Based Web Vulnerabilities** | No | Yes | Optional | Optional | No | | **Product Based Network Vulnerabilities** | No | Yes | Optional | Optional | No | ## Web Vulnerability Scanners - [Online Generic SQL Injection Vulnerability Scanner](https://s4e.io/tools/sql-injection-vulnerability-scanner) — Tests for SQL Injection flaws in GET, POST, PUT, and DELETE parameters that could allow database access, data extraction, or command execution. - [Free and Online Generic XSS Scanner](https://s4e.io/tools/free-and-online-xss-scanner) — Detects Reflected, Stored, and DOM-based XSS vulnerabilities that could lead to session hijacking, data theft, or malicious script execution in browsers. - [Online Generic File Inclusion - LFI/RFI Vulnerability Scanner](https://s4e.io/tools/online-file-inclusion-lfi-rfi-vulnerability-scanner) — Identifies Local and Remote File Inclusion issues that may expose sensitive files or enable remote code execution on the server. - [Generic SSRF Vulnerability Scanner](https://s4e.io/tools/online-ssrf-vulnerability-scanner) — Scans for Server-Side Request Forgery vulnerabilities that can force servers to access internal services, local files, or external systems. - [Generic CRLF Injection Vulnerability Scanner](https://s4e.io/tools/crlf-injection-vulnerability-scanner) — Finds CRLF injection points that could allow response splitting, log poisoning, or injection of malicious headers and scripts. - [Generic Command Injection Vulnerability Scanner](https://s4e.io/tools/command-injection-vulnerability-scanner) — Detects command injection flaws where unsanitized input is executed as OS commands, potentially leading to full system compromise. - [Generic Open Redirect Vulnerability Scanner](https://s4e.io/tools/open-redirect-vulnerability-scanner) — Identifies open redirect issues that attackers can exploit for phishing, malware distribution, or user redirection to malicious sites. - [Generic CSRF Vulnerability Scanner](https://s4e.io/tools/csrf-vulnerability-scanner) — Tests for Cross-Site Request Forgery vulnerabilities that trick logged-in users into performing unauthorized actions on applications. - [Generic XXE Vulnerability Scanner](https://s4e.io/tools/online-xxe-vulnerability-scanner) — Detects XML External Entity attacks that could expose sensitive files, leak internal network data, or enable SSRF exploits. ## Mostly Used Scans -[Subdomain Finder](https://s4e.io/tools/find-subdomains) — Identifies and lists registered subdomains for a given domain. Useful for security assessments, attack surface mapping, and asset discovery. -[Allowed HTTP Methods](https://s4e.io/tools/http-methods) — Checks and lists the HTTP methods supported by a specified web server. Helps detect potentially unsafe or misconfigured methods that could be exploited. -[DNS TXT Record Lookup](https://s4e.io/tools/txt-record-lookup) — Queries DNS TXT records for a given domain. Commonly used to verify SPF, DKIM, and DMARC email security configurations. -[SSL/TLS Supported Cipher](https://s4e.io/tools/check-ssl-supported-cipher) — Scans the SSL/TLS configuration of a server to list supported cipher suites. Highlights weak or outdated encryption algorithms for remediation. -[PCI-DSS 6.4.3 Compliance Checker](https://s4e.io/tools/pci-dss-6-4-3-compliance-checker) — Scans payment pages for unauthorized or tampered scripts, verifies integrity (SRI), and ensures compliance with PCI-DSS 6.4.3 to protect against client-side attacks like Magecart. -[PCI-DSS 11.6.1 Compliance Checker](https://s4e.io/tools/pci-dss-11-6-1-compliance-checker) — Analyzes HTTP headers to detect unauthorized changes, misconfigurations, or missing security headers, ensuring compliance with PCI-DSS 11.6.1 and mitigating redirection or injection risks. ## Partner Program - [Partners](https://s4e.io/partners): Program overview for offering AI-powered **EASM**, **VA**, and **CTEM** solutions. Quick SaaS deployment, flexible configurations, and a trusted global network. Reasons to partner include: proven expertise, AI-powered innovation, full CTEM alignment, scalable solutions, SaaS simplicity, and flexible pricing. - [S4E for Partners](https://s4e.io/partners/s4e-io-for-partners): Solution highlights for partners—**Comprehensive VA**, **automated scheduling**, **AI-powered scan creation**, **real-time visibility**, and **continuous innovation**. - [Partnership Models](https://s4e.io/partners/partnership-models): Flexible models for **Resellers**, **Distributors**, and **MSSPs**. Benefits include competitive margins, co-branded materials, training, regional rights, volume incentives, dedicated account management, API-driven integrations, and near zero-click onboarding. - [How It Works](https://s4e.io/partners/how-it-works): Process at a glance → **Apply** → **Onboarding & platform access** → **Training & (upcoming) certification** → **Start offering S4E solutions** → **Ongoing support & growth**. - [Apply Now](https://s4e.io/partners/become-partner): Application form (Full name, Email, Phone, Company, Website, Country, Employees, Partnership type, Target market, Estimated customer base, Message/referral). ## Affiliate Program [S4E Affiliate Program](https://s4e.io/affiliate): Earn money by promoting S4E and get rewarded for successful referrals. ## API S4E provides an API for starting scans, retrieving results, and managing user data. All requests require a valid API token from the **[API Token](https://app.s4e.io/api-token)** page. Base URL: `https://api.s4e.io/api` ### Generic Request Template ```bash curl -X POST "/" \ -H "accept: application/json" \ -H "Content-Type: application/json" \ -d '{ "token": "", "asset": "", "slug": "", "other_params": { ... } }' ``` ### Generic Response Template ```json { "code": 200, "message": "ok", "error": false, "value": { ... } } ``` ## Integrations - [Integrations](https://app.s4e.io/integrations): S4E integrates with popular platforms and services to improve workflows and deliver real-time alerts. - **SMS** — Receive critical alerts and notifications via SMS. - **Discord** — Send important notifications to your community channels on Discord. - **Slack** — Share alerts and updates directly with your team on Slack. - **DigitalOcean** — Effortlessly manage and import your domains via DigitalOcean. You can choose between automatic syncing or manual addition of domains. - **Cloudflare** — Easily import and manage your domains through Cloudflare. You can choose to sync domains automatically or add them manually. ## Extensions & Plugins - [S4E Chrome Extension](https://chromewebstore.google.com/detail/s4e-continuous-threat-exp/poklckfkkeebomnafifkjddabdapipkb): Brings the full benefits of the S4E platform directly to your browser, accelerating your workflow. - [S4E WordPress Plugin](https://wordpress.org/plugins/s4e-effortless-continuous-cybersecurity/): Protects your WordPress site with effortless, continuous cybersecurity powered by the S4E platform. Features include easy setup, automatic asset verification, and secure API integration. ## Policies - [Privacy Policy](https://s4e.io/privacy-policy): Explains how S4E collects, uses, stores, and protects personal data and user information. - [Terms of Use](https://s4e.io/terms-of-use): Sets the rules for using S4E services, including account responsibilities, acceptable use, and limitations of liability. ## Help Center - [Help Center](https://help.s4e.io): Knowledge base with guides, FAQs, and support resources to help you get started. ### Other Resources - [About Us](https://s4e.io/about-us) — Company background, mission, and team information about S4E. - [FAQ](https://s4e.io/faq) — Frequently Asked Questions about S4E. - [Contact Us](https://s4e.io/contact) — Get in touch with the S4E team for inquiries, support, or partnership opportunities.