Continuous Engine Supported Tests
List of test categories and test types supported by the Continuous engine.
The Continuous engine supports the following test categories and test types. This list is always evolving and may be updated multiple times.
| Test Category | Test Type |
|---|---|
| Infrastructure - DNS | Zone transfer |
| Infrastructure - DNS | Record exposures (TXT, NS, MX, CAA) |
| Infrastructure - DNS | WAF/SaaS detection |
| Infrastructure - DNS | DMARC/SPF/DKIM misconfigurations |
| Infrastructure - Email | Protocol detection (SMTP, IMAP, POP3, ESMTP) |
| Infrastructure - Email | STARTTLS missing |
| Infrastructure - Email | SMTP without TLS |
| Infrastructure - FTP | Anonymous login |
| Infrastructure - FTP | Weak credentials |
| Infrastructure - FTP | Missing TLS |
| Infrastructure - SSH | Weak ciphers/MACs/key exchange |
| Infrastructure - SSH | Weak host keys |
| Infrastructure - SSH | Password login enabled |
| Infrastructure - SSH | Known attacks (Terrapin, regreSSHion) |
| Infrastructure - Databases | MySQL/Postgres/MongoDB/SQL Server exposure |
| Infrastructure - Databases | Weak/default credentials |
| Infrastructure - Databases | Dump file leaks |
| Infrastructure - Directory Services | LDAP anonymous/null binds |
| Infrastructure - File/Service Exposure | Rsync enumeration |
| Infrastructure - File/Service Exposure | SMB signing disabled |
| Infrastructure - File/Service Exposure | Memcached exposure |
| Infrastructure - File/Service Exposure | ProFTPD/OpenSSH/Erlang/Exim vulnerabilities |
| Infrastructure - Monitoring/Exporters | Prometheus |
| Infrastructure - Monitoring/Exporters | Node/DB exporters |
| Infrastructure - Monitoring/Exporters | Kubernetes metrics |
| Infrastructure - Monitoring/Exporters | cAdvisor |
| Infrastructure - Monitoring/Exporters | Ganglia |
| Infrastructure - Monitoring/Exporters | Consul |
| Infrastructure - Monitoring/Exporters | Grafana |
| Infrastructure - Web Servers | Apache |
| Infrastructure - DevOps & CI/CD | Jenkins |
| Infrastructure - DevOps & CI/CD | GitLab |
| Infrastructure - Identity & Access Management | Keycloak |
| Mobile | Permission misconfigurations |
| Mobile | Vulnerable versions |
| Mobile | Clear-text traffic |
| Mobile | World-writable files |
| Mobile | Debug certificates |
| Web Apps - CMS/Frameworks | WordPress (Plugin CVEs, SQLi, XSS, uploads, enumeration, config/backup/debug) |
| Web Apps - CMS/Frameworks | Joomla |
| Web Apps - CMS/Frameworks | Drupal |
| Web Apps - CMS/Frameworks | Magento |
| Web Apps - CMS/Frameworks | Moodle |
| Web Apps - CMS/Frameworks | Liferay |
| Web Apps - CMS/Frameworks | Laravel |
| Web Apps - CMS/Frameworks | Django |
| Web Apps - CMS/Frameworks | Spring Boot |
| Web Apps - CMS/Frameworks | PHP apps (phpMyAdmin, PhpSysInfo, etc.) |
| Web Apps - Enterprise Software | SAP |
| Web Apps - Enterprise Software | Jira |
| Web Apps - Generic Issues | Sensitive file/config exposure (.env, .git, backups) |
| Web Apps - Generic Issues | Missing/malformed security headers (HSTS, CSP, X-Frame, X-Content-Type, Cookies) |
| Web Apps - Generic Issues | SSL/TLS issues (expired/mismatched certs, weak ciphers) |
| Web Apps - Generic Issues | API/metadata/key exposures |
| Web Apps - Generic Issues | Directory listing |
| Web Apps - Generic Issues | Open proxy |
| Web Apps - Generic Issues | Subdomain takeover |
| Web Apps - Generic Issues | Mixed content |
| Web Apps - Generic Issues | Authentication/authorization flaws (default creds, bypass, missing auth, IDOR) |
| Web Apps - Generic Issues | Injection (SQLi: error/time/blind; command injection; CRLF; XInclude; SSTI) |
| Web Apps - Generic Issues | XSS (reflected, stored, DOM) |
| Web Apps - Generic Issues | File/Path issues (LFI, traversal, arbitrary file upload/read) |
| Web Apps - Generic Issues | Server-side issues (RCE, SSRF, XXE, cache poisoning, open redirect) |
| Web Apps - Generic Issues | Session/Token flaws (fixation, weak/missing CSRF, leaks) |
| Web Apps - Generic Issues | Information disclosure (stack traces, internal IPs, PII/password exposure) |
| Advanced - Cloud & SaaS | AWS bucket exposure/takeover |
| Advanced - Cloud & SaaS | Azure tenant leaks |
| Advanced - Cloud & SaaS | GitHub/Bitbucket/Netlify takeovers |
| Advanced - Cloud & SaaS | CDN poisoning |
| Advanced - IoT/Devices | Exposed cameras, DVRs, routers, industrial software (e.g., Hikvision, Reolink, TP-Link, Cisco ASA) |
| Advanced - Special Cases | Critical CVEs and exploits (e.g., Log4j RCE, Text4Shell, Oracle WebLogic RCE, Exchange RCE, Okta/Zoom/Jitsi vulnerabilities, WP2shell, KindaRails2Shell) |
| Threat Intel | Exposed Secrets (API keys, Private Keys, etc.) in publicly available repositories |
| Threat Intel | Exposed Credentials in publicly available repositories |