Scanning
Run AI-powered penetration tests on your verified domains
Scanning
PreBreach scans are automated penetration tests powered by AI. Once a domain is verified, you can launch a scan that combines industry-standard security tools with specialized AI agents to find vulnerabilities a human pen tester would look for.
Scan Types
PreBreach offers a full-featured security assessment included with your subscription plan. Each scan consumes one scan credit from your plan's monthly allowance and provides complete coverage across all five scan phases.
How to Start a Scan
- Navigate to the Domains page and ensure your target domain shows a Verified status.
- Click on the verified domain to open its detail page.
- Click the Start Scan button.
- Confirm the scan.
- The scan will begin immediately and you will be redirected to the scan progress page.
Each scan typically takes 30 to 60 minutes to complete, depending on the size and complexity of the target application.
Scan Phases Overview
Every scan progresses through five sequential phases. Each phase builds on the results of the previous one, creating a comprehensive security picture.
| Phase | Name | Progress | What Happens |
|---|---|---|---|
| 1 | Reconnaissance | 0 - 20% | Discovers subdomains, fingerprints technologies, scans ports, and crawls the web application. |
| 2 | Scanning | 20 - 40% | Runs 24 custom vulnerability templates and performs SSL/TLS analysis. |
| 3 | AI Analysis | 40 - 70% | Eight specialized AI agents analyze the application for complex vulnerability classes. |
| 4 | Validation | 70 - 85% | Multi-model consensus validates findings, generates proof-of-concept exploits, and captures evidence. |
| 5 | Reporting | 85 - 100% | Calculates CVSS scores, assigns a security grade, and generates downloadable reports. |
For a detailed breakdown of each phase, see Scan Phases.
Real-Time Progress Tracking
PreBreach streams scan progress to your browser in real time using Server-Sent Events (SSE). While a scan is running, you will see:
- A progress bar showing the overall percentage complete.
- The current phase name and a description of what the scanner is doing.
- Live tool output as each security tool completes its work.
- Timestamps for when each phase started and finished.
You do not need to keep the browser tab open for the scan to continue. Scans run entirely on PreBreach's infrastructure. If you navigate away and return later, the progress page will reconnect and display the current state.
Cancelling a Scan
You can cancel a scan at any time while it is in progress by clicking the Cancel Scan button on the scan progress page. When you cancel:
- All running tools and AI agents are stopped immediately.
- Partial results from completed phases are preserved.
- A partial report may be generated depending on how far the scan progressed.
- The scan credit is still consumed.
Cancellation is irreversible. If you need a complete assessment, start a new scan.
Scan Credits
How scan credits are consumed depends on your plan:
| Plan | Monthly Credits | Overage |
|---|---|---|
| Starter | Included with plan | Purchase additional scans individually |
| Pro | Included with plan | Purchase additional scans individually |
| Agency | Custom allowance | Contact sales for overage pricing |
Credits reset at the beginning of each billing cycle. Unused credits do not roll over.
Scan History
All completed and cancelled scans are stored in your scan history. From the Scans page you can:
- View the status and result of every past scan.
- Open the detailed report for any completed scan.
- Filter scans by domain, date, or status.
- Re-scan a domain with one click.
Next Steps
- Understand each scan phase in detail to know exactly what PreBreach tests for.
- Read about reports to learn how findings are presented.
- Add more domains to expand your scanning coverage.