Shield Technology
CRYEYE

Cyber Security Audit Solution

CRYEYE — continuous deep audit & monitoring

CRYEYE is a cloud-based continuous deep audit and security monitoring solution with a variety of integrated tools that provides an all-in-one SaaS cybersecurity platform. Automate vulnerability detection across servers, websites, mobile applications, source code, and cloud solutions.

Scroll
Workflow

Eleven steps, one platform

Team management with roles and permissions, workspace and collaboration, asset management, NOC monitoring, continuous analysis, audit results in the vulnerability and incident registry, checklists and commenting, Active Directory integration, compliance to modern frameworks, incident response and forensics, and issue visualisation with projects reporting.

Platform workflow: eleven steps from team management through to issue visualisation and reporting
Team names and email addresses redacted
Continuous Penetration Testing
01NOC service & uptime monitoring
02Whitebox / source code review
03Active Directory security audits
04Breach detection
05Phishing & domain squatting
06Exploit monitoring
07Darknet monitoring
08Mobile app security scanning
09Assets management
10Manual penetration testing tools
11Infrastructure code security
12Workspaces & audits

Automated security auditing includes variety integrations, both commercial and open-source tools for scanning internal and external assets.

01 — NOC Service

Continuous availability
monitoring

Helps you continuously monitor availability of the assets.

Supported protocols

Add different types of supported protocols — HTTP, HTTPS, SSH, FTP — for future monitoring.

Statistics

Check availability in the statistics field for each asset.

Border events

If an asset goes down or up it is registered and displayed in the border event, so you never miss what happened while you were busy elsewhere.

Reports & control

Export a report for any asset in CSV. Massively enable or disable monitors, add or remove them, or clear heartbeat and border-event history.

Heartbeat and response-average monitoring across tracked assets
CSV export of uptime records with availability and status messages
Target URLs, IPs and record IDs redacted
02 — Whitebox

Source code review

Upload a zip archive of your source code or a GitHub repository. CRYEYE conducts a comprehensive scan of the codebase for potential vulnerabilities and security issues. Results are presented in a user-friendly interface, sortable by severity, score and CWE, with filtering options to streamline analysis. Audits cover Python, GO and PHP sources, and whitebox reports export to PDF.

CheckmarxSonarQubeFortify bughoundPROWhispersSnyk

Integrated commercial whitebox tools, alongside open-source scanners.

Source code scan: findings panel, repository file tree and annotated source
A finding with score, severity, CWE, CVSS3 and state, with description and remediation
Facts & Solutions

Every finding, scored
and actionable

Facts derived from scan findings carry severity, CVSS3 score and CWE number, accompanied by comprehensive descriptions and remediation solutions. Audit results can be accessed directly, and users assign statuses — Positive, False Positive, Accept Risk, Retest, Fixed. The system lets users add notes, mark items as 'Interesting', or create support tickets, with intuitive filters and search throughout.

03 — Active Directory

Directory audits and
attack monitoring

Automatic Active Directory security audits and attack monitoring help verify the security of the environment and identify potential vulnerabilities in your infrastructure. Built for easy analysis of Microsoft's directory services for the Windows Server family. Audits enumerate password setting policy, users with privileges, users whose password never expires, domain admins, users sharing a password, domain controller policies, accounts with MSSQL Service SPNs, gMSA policy OSINT and LAPS-configured admin passwords — exportable as a PDF report.

ACLightADHuntToolADReaperADRecon CertifyFindUncommonSharesGetDomainController Get-RBCD-ThreadednoPacPingCastle PowerUpSQLPowerViewPrintNightmareScanner SharpSpraySnafflerSpoolerScanner
Active Directory general information: domain controllers, users, admins, SPNs and group counts
Enumerated network shares with everyone-allowed and current-user-allowed flags

On the screenshots in this section

The directory data shown throughout is from a lab environment, not a customer estate. Where the platform displayed credential material — a LAPS administrator password, a gMSA managed-password blob — those slides have been left out rather than blurred.

11 — Infrastructure as code

Scanning the code that
defines your infrastructure

Infrastructure code security scanning is the process of evaluating the security of the code used to define and configure an organization's infrastructure. It helps organizations identify and address security vulnerabilities and misconfigurations early in the development and deployment process — reducing the risk of breaches, ensuring compliance, and improving overall security posture.

Docker

Evaluates Dockerfiles used to build images, identifying risks in the containerization process so images are built securely and container-based compromise is minimised.

Terraform

Evaluates Terraform configuration files, reducing the risk of misconfigurations, vulnerabilities or non-compliance in provisioned infrastructure.

AWS CloudFormation

Evaluates CloudFormation templates so AWS deployments are configured securely and align with best security practices.

Ansible

Evaluates playbooks and configuration files, so infrastructure automation is built securely and free of misconfiguration.

Helm

Evaluates Helm charts — the packages that deploy and configure applications on Kubernetes.

Kubernetes

Evaluates Kubernetes manifests, ensuring deployments are configured securely as the platform automates container management.

Azure Resource Manager

Evaluates ARM templates — the deployment and management layer for creating, updating and deleting Azure resources.

Inside the platform
Breach detection project creation with asset types
Domain squatting and phishing candidate detection
Exploit monitoring across exploit and CVE databases
CVE dashboard with exploit counts by severity
CVE records with references, affected software and proof-of-concept flags
CVE news gathered from GitHub repositories
Darknet feed monitoring with subscribed sources
Static analysis of an Android package showing detected leak categories
Automated audits queued against a mobile application
Manual penetration testing tool launcher
Nmap web interface running in the CRYEYE cloud
Workspaces with per-project asset counts
Workspace charts: asset mix and uptime
Singular audit project with settings, notes and reporting
Audit management panel with progress and controls
Findings across all audits, categorised and filterable
Breach detection01 / 16
04–07 — Monitoring

Watching what happens
outside your perimeter

Breach detection

Continuously monitor asset types — domain, IP address, URL, company name, Git repositories, email, cloud, cloud name, IBAN and keyword — for leaks and violations in the Darknet. Issues appear inside the project and are monitored at a set frequency: once a day, week or month, with email notification of anything found, or never, to suspend an asset.

Phishing detection

Search for new potential phishing websites created by cybercriminals to trick users into divulging usernames, passwords, credit card details or other personal and financial information. These sites are designed to closely mimic legitimate websites of trusted organizations — banks, social media platforms, online retailers and email providers.

Exploit monitoring

Monitor system assets for potential exploits using news, GitHub, exploit databases and CVE databases, gathering the technologies and services used on the site. Sources include Exploit DB, WordpressExploit, GithubExploit, 0day.Today and Metasploit, with CVE statistics by severity and by version.

Darknet monitoring

If your data is seen on the Darknet you will be the first to know, helping you predict future leaks or exploited technology vulnerabilities and protect your organisation in advance. Subscribe to blogs, sites and marketplaces, view the feed from subscribed channels, and create triggers from a simple keyword to a complex regular expression.

0
Exploit & CVE databases
0
Audits in Multiscan
08 — Mobile

Android and iOS
application scanning

Static analysis of Android and iOS mobile applications, surfacing facts such as potential API key leaks inside an application. CRYEYE integrates numerous open-source and commercial audits for automatic scanning of mobile applications.

Vulnerabilities in mobile applications — APK files on Android, and applications on iOS devices — are weaknesses or flaws in the app's design, code or implementation that could be exploited to compromise the security and functionality of the application, the device it is installed on, or the data it interacts with.

MobSFApkleaksIpanemaCheckmarx IPAMotan
Static analysis of an Android package showing detected leak categories
Package name and two leaked API keys redacted
09–10 — Assets & manual testing

A full cloud solution for
manual checks

Add many different asset types to your Workspace for scanning by the audit system to find vulnerabilities, misconfigurations and information leaks. Categories span web, infrastructure, mobile, source code analysis, binary analysis, recon, network forensics, names, titles or identifications, and more. Alongside the automation, a full cloud solution for manual checks allows users to run a complete cycle of vulnerability assessment or penetration testing.

ArcherysecBeefBlankCommix CyberchefDamn-Web-ScannerDradis-CEEast ExplainshellFaradayFuxiIronwasp KageMSF-Consolemirror-milw0rmMobSF PoCBoxProxenetPwndropRequestBin SqlmapSqlmap Web GUIVegaWebnmap XXE-InjectorXplicoZAP
12 — Workspaces & audits

Your agile hub
for success

Manage individual projects with customizable goals, conduct thorough security audits, capture insights with notes, and create comprehensive checklists. Every Workspace supports URLs, IPs, Android and Apple applications, Git repositories, Dockerfiles, Docker images, AWS CloudFormation, Azure Resource Manager, emails, phone numbers, keywords, Kubernetes, Terraform, technology and more. Personalize each with a name, description and image, and unite developers, security specialists, QA, management, clients and customers in a shared environment.

Add assets

Add objectives individually, as a list, or by uploading a file. Send them straight to Breach Detection, Darknet Monitoring, Whitebox Analysis or Uptime Monitoring, or hold them in the Assets tab for later.

Singular audits

Each target is analysed in its own project space, with its own settings, notes system, reporting infrastructure and statistics. Personalize headers, scan with authentication by transferring cookies or auth tokens, and schedule audits to launch on your terms.

CryAI Wizard

Accurate identification of the technologies in use is paramount to running relevant audits. The Wizard evaluates website technologies and services against its database and proposes matching audits; technologies can also be added manually.

Audit management

Track progress and performance of each audit, pause, resume or halt scans, initiate new ones, create reports, and upload reports from external scanners.

Multi-target audits

Manage multiple projects simultaneously, each scanning a diverse range of targets — URLs, IPs, mobile application files, source code links and more — with the system selecting the most suitable audits for your chosen purpose.

Unified findings

Results across all audits in one categorised view. Sort by severity, creation date, CWE and audit name, mark anything as 'Interesting' like a bookmark, and transfer results into Notes in a click.

Vulnerability management

From finding
to report

Users can get help on any fact found during a scan — additional information or classification of the vulnerability — and report a fact as untrue or false-positive. Manage vulnerabilities using semi-automatic tools, send them to notes as facts, or create new ones.

The report generator produces customizable reports from the facts, results and resources extracted during a vulnerability assessment. Each includes a QR code giving direct access to the HTML-based results in your browser, so nothing in the report is missed.

Findings across all audits, categorised and filterable
Shield Technology

Thank you

CRYEYE — Cyber Security Audit Solution

Speak to Shield Technology about deploying CRYEYE across your estate.