Welcome back
Your security overview at a glance.
Recent Scans
Quick Scan
Run a new security scan on any URL. All 7 agents analyze your target.
Run a Scan
Enter a URL to scan. Our agents analyze security headers, exposed files, compliance, DNS, and more.
Advanced Scan
Deep security testing that goes beyond external scans. Select the scan types you want to run.
Provide login credentials for a test account (not admin). We will log in, test session cookie security, check access control, test session fixation, and verify logout effectiveness.
Provide an API endpoint that returns user-specific data. We will test whether changing the ID parameter grants access to other users' records.
By default, we test common login endpoints. Add custom endpoints below (one per line) to test specific routes.
Scan History
All scans run from your account are saved here.
System Scan
Scan your local machine for threats, misconfigurations, and vulnerabilities.
Desktop Scanner Required
The following agents require local system access and run through the CRUCiBLE desktop scanner application.
These agents scan running processes, file systems, network connections, and system configurations that cannot be accessed remotely.
Download Desktop ScannerAccount Settings
Manage your profile and subscription.
Profile
Subscription
Two-factor authentication (2FA)
Add a TOTP authenticator app (Google Authenticator, 1Password, Authy) for a second login factor. Strongly recommended for admin accounts.
Danger Zone
Watch — Continuous Monitoring
Add domains to monitor. The Monitor Agent re-scans on a schedule and the Alert Pipeline notifies you on a posture regression.
Watch a domain
Your targets
Alert channels
Slack/Discord use an incoming-webhook URL. Telegram uses a bot token + chat id. Email uses an address.
DNS Security Suite
Check DMARC / SPF / DKIM / CAA and copy the records to paste at your DNS host.
WordPress Hardening Pack
Detect WordPress and check common exposures; get a copy-paste hardening recipe.
Canary Tokens
Generate a tracking token. When opened by an unauthorized party it phones home and fires an alert.
Desktop scans
Link the desktop scanner app with an API token (Settings → Account in the desktop app). Synced scans appear here.
Monitors — 24/7 Continuous Monitoring
More than a scan. Crucible Security watches your sites around the clock and alerts you the moment something changes: uptime & downtime, TLS certificate expiry, homepage defacement / unexpected changes, DNS hijack detection, plus a re-run of the full security scan with score-drop & new-finding alerts.
Add a domain to monitor
Your monitored domains
Recent changes & alerts
User Activity — Live
Real user activity across every CRUCiBLE platform — live visitors, traffic trend, top platforms & pages, an activity feed, and screen recordings you can replay. Data is live from analytics; nothing here is simulated.
Pageviews — last 14 days
Top platforms (7d)
Top pages (7d)
Screen recordings
Replay real user sessions. Opens the recording in PostHog.
Recent activity feed
Security Ops
Live agents: Threat Hunter (statistical anomaly detection), Auto-Response (SOAR IP blocklist), and Forensics (hash-chained immutable audit log).
🧭 Threat Hunter — anomalies
Robust (median/MAD) anomaly detection over ecosystem exceptions, rage-clicks, traffic, and scan-score drops. Runs every 6h.
🛡️ Auto-Response — IP blocklist
Hostile IPs (canary triggers auto-block here). Platforms poll /api/blocklist?ip=… or pull nginx deny rules.