AfnRiskScan

Never say “we did not know” in the next audit.

AfnRiskScan makes real risk visible across internal network, external surface, AD, M365, firewall, and backup layers in one assessment flow.

68+Named security controls
30Authenticated audit modules
65,535Ports per host
.NET 8Windows WPF platform
AfnRiskScan / live assessment
SSL-VPN brutePhishingSMB exploitRDP brute forcePort scan0-day exploit
AfnRiskScan
6 attack vectors blockedReal-time alert to IT
Risk queue
CRITInternet-facing firewall admin
CRITPrivileged accounts without MFA
HIGHBroad critical share permissions
HIGHBackup immutability gap

Board-ready: security score + critical risk chain

Evidence: IP, service, asset family, audit record

Coverage: internal network + external surface + M365

Outcome: what is risky, why it matters, how to fix it

Why Different?

AfnRiskScan is not an IP scanner

Basic network scanners mostly produce host, port, and banner lists. AfnRiskScan combines that signal with authenticated audits, external surface review, Microsoft 365 checks, passive controls, evidence bundles, AI interpretation, and verifiable action planning.

Basic scan

What is open?

An IP range is scanned, ports are listed, and sometimes service banners are shown. The output stays technical and prioritization is often left to the user.

  • Host and port list
  • Limited service context
  • Manual interpretation required
AfnRiskScan method

Why is it risky?

Asset family, service, authenticated audit result, passive security signal, external exposure, and customer profile are connected in the same risk record.

  • Device and service classification
  • Authenticated + passive correlation
  • Evidence, severity, and coverage gaps
Outcome

How is it fixed?

The AI and reporting layer is structured to produce executive summaries, attack scenarios, prioritized actions, command/click paths, and verification methods.

  • Prioritized remediation list
  • Platform-specific steps
  • Post-fix verification
Comparison

How it differs from classic tools

AfnRiskScan does not stop at raw port lists or isolated vulnerability output. It produces evidence, context, priority, and action inside an authorized assessment scope.

CapabilityClassic IP scannerAfnRiskScan
Asset discoveryHost and port listHost, service, asset family, AD seed, MAC vendor, and customer profile
Authenticated auditUsually absentAD, Windows, SQL, FortiGate, Palo Alto, VMware, Veeam, NAS, M365
AI outputNone or free-form textStrict JSON schema, attack timeline, businessImpact, priorityActions
ReportingTechnical listHTML presentation, PDF, CSV/Excel, executive summary, evidence book
ActionInterpretation left to the userPlatform-specific command/click-path and verification method
Proof

Real remediation output from the platform

Sample findings ship in production reports with platform-specific commands, CLI steps, or Entra click-paths. Expand a card to see an example fix.

Capabilities

Not just a scanner. A proof-driven risk platform.

The site now mirrors the actual product architecture: AfnRiskScan discovers assets, gathers evidence, creates risk context, and converts technical output into decision-ready reporting.

Internal discovery

Builds an asset map with ICMP, TCP fallback, AD seeds, MAC vendor lookup, and service classification.

Authenticated audits

Runs approved checks across AD, Windows, SQL, firewall, hypervisor, backup, and storage layers.

External surface

Combines DNS, subdomain, web header, TLS, mail posture, and internet port visibility.

Passive security checks

Measures SMBv1, RDP NLA, default credentials, banner-to-CVE, and exposure signals without exploit attempts.

Evidence bundles

Turns findings into reportable packages with IP, device, proof, severity, and business context.

Executive reporting

Delivers technical reports, HTML presentation reports, PDF, CSV/Excel, and historical scan outputs.

Module Coverage

Deep checks by device family

Module coverage is aligned with the current README and device risk catalog.

AD / Windows / M365

Kerberoasting, AS-REP, delegation, stale accounts, local admins, macro policy, Graph API, and Conditional Access checks.

  • Domain admin visibility
  • MFA and legacy auth
  • Hardening gap analysis

Firewall / UTM

FortiGate, Palo Alto, MikroTik, and generic firewall audits expose management-plane and policy risk.

  • Firmware and CVE alignment
  • Trusted source and admin exposure
  • SSL-VPN and rule posture

VMware / Hyper-V / Veeam

Hypervisor and backup checks cover lockdown, snapshots, syslog, encryption, immutability, and backup freshness.

  • ESXi/vCenter hardening
  • Backup recovery readiness
  • Privileged backup admin risk

NAS / Switch / Camera / VoIP

Synology, QNAP, switch SSH, printer, IP camera, SIP, and test/dev exposure checks reveal forgotten surfaces.

  • Guest/public share risk
  • Management-plane visibility
  • RTSP/ONVIF and SIP signals

SQL / Database

SQL authenticated audit and passive exposure review mixed mode, sa, xp_cmdshell, TLS, and privilege mapping.

  • Dangerous feature review
  • Encryption posture
  • Service account correlation

DNS / Mail / Web

Email security, DNS health, TLS certificates, web headers, cookies, and subdomains are tied to business impact.

  • SPF/DKIM/DMARC posture
  • TLS and certificate hygiene
  • Web security headers
68+ Controls

68+ security controls listed one by one

This list is derived from the current audit, passive security, external surface, Microsoft 365, and reporting capabilities. We do not show controls or references that are not present in the product.

AD and Identity

  • Kerberoasting signals
  • AS-REP roasting signals
  • Unconstrained delegation
  • Stale domain admin accounts
  • Stale computer accounts
  • Nested group path analysis
  • Domain admin inventory
  • Account lockout threshold
  • Minimum password length
  • KRBTGT age check
  • Anonymous LDAP bind
  • GPP cpassword detection

Windows and Endpoint

  • WMI OS/hotfix visibility
  • Local admin inventory
  • Everyone-accessible shares
  • RDP NLA check
  • WDigest cleartext risk
  • PowerShell logging
  • Process command-line logging
  • LSA Protection RunAsPPL
  • Credential Guard
  • Office macro policy

Microsoft 365

  • Secure Score visibility
  • MFA enforcement
  • Conditional Access
  • Legacy authentication
  • Global admin count
  • Mailbox audit
  • Risk-based sign-in policy
  • Guest/sharing posture

Firewall and Network

  • FortiGate firmware/CVE
  • FortiGate SSL-VPN posture
  • Firewall admin exposure
  • Trusted host/source restriction
  • Risky policy/rule patterns
  • Palo Alto audit
  • MikroTik audit
  • Generic firewall management
  • Telnet management exposure
  • SNMP community risk

VMware, Veeam and Storage

  • VMware version/CVE
  • ESXi SSH status
  • ESXi lockdown mode
  • Snapshot risk
  • NTP/syslog posture
  • Hyper-V audit
  • Veeam encryption
  • Veeam immutability
  • Offsite backup copy
  • Failed backup jobs
  • Backup freshness
  • NAS guest/public share

Web, DNS and External Surface

  • DNS zone transfer
  • SPF record
  • DKIM record
  • DMARC policy
  • MTA-STS
  • TLS-RPT
  • TLS 1.0/1.1
  • Expired certificate
  • Self-signed certificate
  • Weak signature algorithm
  • HTTP security headers
  • Server banner disclosure
  • X-Powered-By disclosure
  • Sensitive path discovery
  • External port exposure
  • Subdomain discovery

Passive Exposure

  • Anonymous FTP
  • SMBv1
  • SMB null session
  • MS17-010 signal
  • Default credential signals
  • Banner-to-CVE matching
  • IP camera CVE
  • RTSP/ONVIF surface
  • VoIP/SIP exposure
  • Industrial protocol exposure
  • Docker daemon 2375
  • Kubernetes API exposure
  • Portainer exposure
  • Database exposure
Demo Flow

Demo flow in 3 minutes

The first product journey for IT teams is simple: define scope, run the assessment, let AI interpret the evidence, and share the report.

01

Scope

Define IP/CIDR, domain, external surface, AD/M365/firewall/backup scope, and customer profile.

02

Assess

Discovery, authenticated audits, and passive checks run within the authorized scope.

03

AI analysis

Evidence bundles are converted into business impact and action through structured output rules.

04

Report

HTML presentation, technical report, PDF, and CSV/Excel outputs are shared.

Free trial path

Try the first scan with AfnRiskScan CE on GitHub

Community Edition is the free edition published for quick preliminary assessment on networks you are authorized to test. It does not replace the Pro platform; it helps IT teams experience the AfnRiskScan approach, report format, and baseline risk visibility quickly.

Sample run with PowerShell 7pwsh -ExecutionPolicy Bypass -File .\AfnRiskScan.ps1

CE

  • Ping sweep network discovery
  • Top 100 / Top 1000 / custom port scanning
  • Service guessing and banner grabbing
  • 8 local Windows security checks
  • Turkish / English HTML and CSV reports
  • MIT-licensed open-source usage

Pro

  • 30 authenticated audit modules
  • 68+ security control families
  • Active Directory, M365, firewall, and Veeam audits
  • AI-assisted executive report and remediation steps

Use only on systems where you have explicit authorization. CE generates HTML and CSV reports; Pro demo is recommended for enterprise deep assessment.

Use Cases

Use cases by sector

AfnRiskScan answers the same question across different organizations: which evidence-backed risks exist on my critical assets, and what should I fix first?

MSP / consultant

Fast scoping, repeatable reports, and executive-ready output across multiple customers.

Manufacturing

Firewall, industrial protocol, camera, switch, and backup risks in one view.

Finance

MFA, privileged identity, logging, external surface, and data-risk prioritization.

Healthcare

Legacy Windows, broad shares, NAS, printer, and segmented network risk visibility.

Public sector

External surface, email security, AD, and backup posture across distributed locations.

Holding

Standardized risk language across different companies and network segments.

Solution Pages

Search-focused solution pages

These pages are designed for real search intent without making the main navigation crowded.

AI does more than summarize; it turns evidence into action

AfnRiskScan supports Claude, OpenAI Direct, and OpenAI Backend modes. On the backend path, the API key is not held by the desktop client; the WPF application sends the system prompt and evidence-bundle prompt to the configured backend URL. The backend requests strict JSON schema output through the OpenAI Responses API.

Executive summaries and attack narrativesRisk ranking by exploitability and business impactEvidence and remediation steps for technical teamsParser-friendly structured output
AI report preview

The environment has 42 assets, 6 critical findings, and 14 high findings. The most urgent chain is internet-reachable firewall administration, privileged identity MFA gaps, and a broadly accessible finance share.

Evidence sent to AI

  • Customer profile, industry, and critical asset notes
  • Internal scan, external surface, and M365 audit results when available
  • Findings, audit records, and coverage gaps
  • IP, service, asset family, severity, and proof context

Rules applied by AI

  • Return valid JSON only
  • Do not invent CVEs without version or evidence
  • Reflect missing scope in missingEvidence
  • Prioritize by industry, critical assets, and exploitability

Professional outputs

  • executiveSummary and securityScoreCommentary
  • businessImpact, topRisks, and assetAnalyses
  • attackScenarios, attackTimeline, and whatIfIgnored
  • priorityActions and missingEvidence

Remediation depth

  • PowerShell, FortiGate CLI, or Entra ID click-path examples
  • Which setting changes on which platform
  • How remediation is verified
  • Separate readability for executives and technical teams
Report Model

Reporting is more than a PDF export

AfnRiskScan reports are designed as decision files rather than scan dumps. Technical teams see exactly what to fix while leadership can read the risk chain, business impact, and priority order in the same assessment.

Executive narrative

Critical risk chains, attack scenarios, business impact, and what-if-ignored outcomes are presented in clear management language.

Technical evidence book

Each finding can be tied to asset, port/service, audit record, proof, severity, recommended action, and verification method.

HTML / PDF / CSV-Excel

Presentation-oriented HTML, shareable PDF, and table-based CSV/Excel outputs for operations teams can be generated from the same assessment.

History and trends

Scan history and trend outputs help track whether risk decreases over time and which control families improve.

Sample Report

HTML presentation report preview

The frame below shows a real sample HTML presentation report generated by AfnRiskScan.

Live sample HTML presentation report previewOpen full screen

Real HTML presentation report

The image below is captured from a real HTML presentation report generated by AfnRiskScan. The sample report combines internal network, external surface, security score, executive summary, attack timeline, priority actions, and asset-level findings in one presentation file.

  • Internal and external surface in one report
  • Overall score and severity distribution
  • Executive summary and attack timeline
  • Priority actions and asset-level evidence
Real HTML presentation reportAfnRiskScan HTML presentation report screenshot
Short demo video

Settings and controlled operating model

The product separates authorized scope, customer profile, platform accounts, and AI backend settings. The report therefore shows not only findings, but also where evidence is strong and where coverage is missing.

Scope

IP/CIDR, domain, external surface, and platforms to audit are defined explicitly.

Customer profile

Industry, critical assets, and business context are used for AI prioritization.

Credential scope

Authenticated audits run only on authorized platforms with approved accounts.

AI backend

The backend URL setting routes analysis to the service; model and API key are managed in backend configuration.

Coverage gaps

Evidence that cannot be collected or is out of scope is reflected as missing evidence in the report.

Architecture Flow

Technical architecture flow

AfnRiskScan is structured to produce evidence at every step from discovery to reporting. The output is not only a scan result, but a verifiable risk file.

01DiscoveryDiscovery02Auth AuditAuthenticated audit03PassivePassive checks04EvidenceEvidence bundle05AIAI analysis06ReportExecutive report
01

Discovery

IP/CIDR, AD seeds, TCP fallback, service, and device-family visibility.

02

Authenticated Audit

Approved audits for AD, Windows, SQL, firewall, M365, VMware, Veeam, and NAS.

03

Passive Checks

SMBv1, RDP NLA, TLS, DNS, mail, camera, container, and exposure signals.

04

Evidence Bundle

Findings, assets, proof, customer profile, coverage gaps, and business context are merged.

05

AI Analysis

Strict JSON, attack timeline, businessImpact, priorityActions, and missingEvidence outputs.

06

Executive Report

Executive summary, technical evidence, remediation plan, PDF/HTML/CSV, and trend output.

Pipeline

Assessment pipeline

The product flow is aligned with the current architecture documented in the application repository.

01

Discover

Assets are found through IP/CIDR scope, AD seeds, and customer profiles.

02

Classify

Port, service, banner, vendor, and profile signals identify device families.

03

Audit

Authenticated and passive modules run within the approved scope.

04

Risk engine

Findings are combined with evidence and severity in the rule-based risk engine.

05

AI + report

Executive summaries, technical reports, HTML/PDF/CSV, and trend outputs are generated.

A local cybersecurity assessment product by AFN Teknoloji

AFN Teknoloji brings enterprise infrastructure, security, backup, Microsoft ecosystem, and consulting experience into AfnRiskScan. The goal is to make technical findings understandable, evidence-based, and action-oriented.

Clarify your environment risk with us

Request a demo and see which modules create value for your network, firewall, AD, M365, and backup layers.

Request Free Demo
FAQ

Frequently asked questions

Key questions IT teams ask before a demo or purchase.

Is AfnRiskScan for unauthorized scanning?

No. It must be used only on explicitly authorized enterprise systems and approved scope.

What is sent to AI?

The evidence bundle can include customer profile, findings, audit records, internal/external surface results, and coverage gaps.

Is the API key stored in the desktop client?

In backend mode, the API key is not held by the WPF client; analysis runs through the configured backend URL.

Can the report become a PDF?

Yes. The HTML presentation report can be opened in a browser and printed to PDF; technical and table outputs are also supported.

How is credential use managed?

Authenticated audits are planned to run only on authorized platforms with approved accounts.

What is the difference between CE and Pro?

CE provides baseline discovery, port scanning, 8 Windows checks, and HTML/CSV reports. Pro adds enterprise deep assessment across AD, M365, firewall, Veeam, VMware, NAS, 68+ controls, and AI-assisted executive reporting.

What data is sent to AI?

Authorized findings, evidence, customer profile, and coverage gaps can be sent. Prompt rules ask the model not to invent CVEs without evidence and to state missing scope explicitly.

Can it run offline?

Discovery and some local assessment workflows can be reviewed without internet. M365, external surface, fresh CVE/AI, and email delivery flows may require connectivity or a backend.

Contact

For AfnRiskScan demos, deployment, licensing, or reporting questions, contact the AFN Teknoloji team.

CompanyAFN Teknoloji Bilişim Destek ve Danışmanlık Hizmetleri Tic. Ltd. Şti.

AddressZümrütevler Mah. Hanımeli Cad. Tuna İş Merkezi No:13 K:3 D:6 Maltepe / İstanbul 34852

Phone+90 216 572 50 40

Emailsatis@afnteknoloji.com

Webafnteknoloji.com / zafiyettarama.com.tr