ShadowTrackr

Detection Rules

High-confidence findings, not single-artefact guesses

Every tool for managing or discovering your attack surface runs on detection rules — but not all detection rules are equal. What actually matters is the quality of those rules and what they're built to detect. Where most EASM tools confirm a finding based on a single artefact, ShadowTrackr aims for three or more robust artefacts before confirming that a specific piece of software or an edge device is present. Where the data supports it, we go further still.

Sometimes there simply isn't enough evidence to be that certain — we might be able to identify a product but not its exact version. In those cases, we still surface what we've found. Our detection rules aren't static: we continuously review and update weaker or outdated rules as new evidence and techniques become available.

Where we focus rule development

Not all exposed software carries the same risk, so our rule development effort isn't spread evenly. We prioritize detection of high-risk software and edge devices — routers, switches, VPN endpoints, and other remote login services — because that's where real-world attacks concentrate. If there's a vulnerability in JavaScript running on one of your websites, you'll hear about it. But the biggest exposure is almost always in things like exposed Juniper, Citrix, MySQL, MS RDP or similar services. We maintain a dedicated report focused specifically on these device categories, so you can see at a glance where you're carrying the most risk.

Beyond banner grabbing

Detection isn't limited to what's running on your websites. For every host, ShadowTrackr checks open ports and identifies the software behind them — and that goes well beyond simple banner grabbing. We examine behavioral signals and binary fingerprints to identify what's actually there, including specific detail for SQL servers, RDP servers, DNS servers, and more.

What ShadowTrackr won't do

We do not fire exploits. Mapping your attack surface thoroughly is one thing; disrupting your systems in the process is another, and in most jurisdictions firing exploits without prior written authorization is illegal regardless of intent. Continuous scanning and continuous exploitation are fundamentally incompatible — if you need exploit validation, that's a scoped penetration test or red team engagement, not continuous monitoring.

Everything ShadowTrackr's scanner nodes do falls within normal, legal internet traffic.

From detection to prioritization

Reliable detection is only useful if it feeds into something actionable. Every confirmed software finding is automatically checked against ShadowTrackr's internal vulnerability database and scored for real-world risk — not just theoretical severity.

Vulnerability Management →

See how findings get matched to vulnerabilities and prioritized.

Asset Discovery →

See how discovery decides what belongs in scope in the first place.

See what ShadowTrackr detects on your edge devices and remote login services.