One-Click Cyber Risk Assessment
AFN RiskScan, developed by AFN Teknoloji, scans your enterprise network from both inside and outside in hours; produces an AI-powered Turkish executive report, MITRE ATT&CK threat actor mapping, and ready-to-run PowerShell remediation scripts.
AFN RiskScan — Detailed Demo
Watch a step-by-step walkthrough of how it works and what it detects.
How are we different from classic scanners?
An integrated platform that not only lists CVEs, but maps threats to real actors, benchmarks against industry, and generates remediation scripts.
WAN + LAN + DMZ Comprehensive Scan
WAN IPs auto-discovered via FortiGate; internal, external and DMZ scanned in one pass. Both the externally visible surface and internal vulnerabilities in a single report.
AI-Powered Executive Report
OpenAI / Anthropic / Gemini integration converts findings into executive summary, action plan, and GDPR / ISO 27001 compliance analysis.
Threat Actor Attribution (MITRE ATT&CK)
Findings mapped to TTPs of 8+ ransomware/APT groups: Conti, LockBit 3.0, BlackCat/ALPHV, FIN7, Volt Typhoon, Lazarus. 'This environment matches Conti's attack pattern by %X.'
Industry Benchmark Comparison
Positioning against Critical/High/Total finding averages for 15+ Turkish SMB sectors: finance, healthcare, manufacturing, education, government, retail, IT.
Automated PowerShell Fix Scripts
Ready-to-run .ps1 fix scripts for 12+ findings: PrintNightmare, SMB1, WDigest, LM Hash, LDAP Signing, TLS 1.0, Office Macro, KRBTGT rotate.
Ransomware Readiness Score
Combines backup isolation, KRBTGT rotation, MFA, EDR presence, SMB1 status and more into a single ransomware readiness score.
Which ransomware group targets you?
AFN RiskScan maps findings via MITRE ATT&CK to the tactics, techniques, and procedures (TTPs) of 8+ known ransomware and APT groups. You see, as a percentage, how closely your environment matches each group's attack pattern.
- Conti / Wizard Spider (G0102)
- LockBit 3.0 (G1015)
- BlackCat / ALPHV (G1068)
- FIN7 / Carbanak (G0046)
- Volt Typhoon (G1017)
- Lazarus Group (G0032)
- EsxiArgs
- DeadBolt (QNAP NAS)
{
"actor": "LockBit 3.0",
"mitre": "G1015",
"match": 78,
"hits": [
"FortiGate SSL VPN",
"RDP Exposed",
"Stale Admin",
"PsExec",
"Backup Veeam"
],
"verdict": "🚨 High match"
}32+ Audit Modules
From network hardware to cloud services, Active Directory to web applications — every layer covered.
Active Directory & Kerberoasting
DCSync, KRBTGT age, AS-REP roastable, Unconstrained Delegation, Stale Admin, Ghost Devices, password policy audit.
Switch & Mikrotik (SSH/SNMP)
Cisco, Zyxel, HPE/Aruba, Mikrotik firmware/CVE, default credentials, VLAN, STP, port-security and logging audit.
FortiGate / Sophos / Firewall API
FortiGate REST API audit: policy, NAT, SSL-VPN, IPS, web filter, certificate and admin profile. WAN IPs captured for DMZ scanning.
ESXi / vCenter / Veeam
ESXi version, OpenSLP, lockdown mode, Veeam backup job status, immutability and repository isolation audit (incl. CVE-2021-21974).
Microsoft 365 (Graph API)
Conditional Access, MFA enforcement, Legacy Auth, Global Admin count, Secure Score, mailbox audit, and risk-based sign-in policy review.
Web Pentest & Sensitive File Discovery
Detection of .git/HEAD, .env, web.config, backup.zip; soft-404 baseline protection against false positives; SQLi/XSS/CORS probing.
Device Fingerprinting
Identifies HPE iLO, Dell iDRAC, Synology DSM, QNAP QTS, IP cameras, printers, and switches by model + firmware level; misclassifications eliminated.
Hyper-V / VMware / Backup Isolation
Virtualization host configuration, snapshot/backup network isolation, immutability and LSASS protection audit.
5-Step Risk Assessment
The entire process completes in half a day at the customer site.
Environment Profile
Company, industry, employee count, critical assets and domain information collected.
Automated Discovery
All network devices, FortiGate WAN IPs, AD, M365, ESXi, Veeam discovered in one click.
Authenticated Audit
32+ modules and 68+ control points run via WMI / LDAP / SSH / REST APIs.
AI Analysis + Report
Findings converted via AI into executive report, MITRE mapping, and action plan.
Automated Remediation
PowerShell auto-fix script generated; environment hardened in hours.
Reporting & Outputs
Not just a vulnerability list — board-ready, actionable outputs.
Executive PDF
Color-coded priority table, heatmap, MITRE ATT&CK mapping, industry comparison, and 30/60/90-day action plan.
PowerShell .ps1 Auto-Fix
Customer-specific PowerShell remediation script auto-generated after each scan.
CSV / HTML / JSON Export
Machine-readable formats for SIEM, SOAR, and ticketing systems.
GDPR / ISO 27001 / NIST CSF / CIS
Each finding mapped to relevant control items; evidence set for compliance audits.
Compliance Frameworks
Each finding is mapped to relevant control items.
AFN RiskScan Community Edition
Free, single-file PowerShell scanner: network discovery, port scanning, 8 Windows security checks, bilingual HTML/CSV reports. Inspect, modify, share — no installation, runs with one line.
See hidden risks in your environment in one day
Have AFN Teknoloji experts run a custom pilot scan of your organization. Delivered with AI-powered executive report and remediation plan.
