CidraOpen the platform

WEBSITE TESTING · PASSIVE LIVE

Useful website evidence before active DAST.

Submit an authorised public URL. Cidra observes transport, browser security policy, cookies and limited page signals under a hard request budget—then writes the observations into the same remediation ledger.

PASSIVE PROFILE4 requests maximum10-second timeout512 KB inspectedHTTP/HTTPS · ports 80/443 · workspace rate limit

THE LIVE EXPERIENCE

A baseline you can run without disguising it as a penetration test.

The result shows exactly which checks passed, failed or need context, together with the final URL, redirect count and finding changes.

CCidraNorthwind / Website testingREPRESENTATIVE DEMO
PASSIVE WEBSITE BASELINE

Assess a public website

Lead/operator authorization and a workspace interlock are required.

Operational
https://shop.example.testAssess website
71/100
Assessment complete1 failed · 1 warning · 1 passed · 2 requests
PASSHTTPS transportFinal response uses HTTPSWSTG
FAILContent Security PolicyNo CSP header was returnedWSTG
WARNSession cookie attributesSameSite was not explicitWSTG
4-request maximum · 10-second timeout · 512 KB inspected
Representative passive website assessment. It observes one submitted page and bounded redirects; it does not crawl or send attack payloads.

SAFETY ARCHITECTURE

Every redirect earns authorization again.

A public hostname that turns into a private address is an SSRF path, not a website target. The target guard is applied before the first request and before every redirect.

01Authorised

A lead or operator attests target authority. A workspace lead releases the passive-only interlock.

02Public only

Credentials, query strings, alternate ports and private, local or reserved DNS answers are rejected.

03Pinned DNS

Resolved public addresses are pinned to the request socket and every redirect is revalidated.

04Bounded

One submitted page, at most three redirects, a 10-second timeout and 512 KB of inspected response data.

WHAT IT OBSERVES

Browser-facing controls with useful remediation.

Transport

HTTPS use, redirect outcome and bounded TLS connection details.

Headers

CSP, framing, content-type, referrer and permissions policies.

Cookies

Secure, HttpOnly and SameSite attributes on returned cookies.

Page signals

Mixed content and password-form transport in the inspected HTML.

Boundary

Not executed by this module

  • No crawling or path enumeration
  • No form submission or JavaScript execution
  • No attack payloads, API fuzzing or exploitation
  • No network service or port scanning

Those capabilities require verified ownership, vault-backed test identities, isolated runners, cancellation and cyber-range validation.

NEXT ON THE GATED ROADMAP

Passive crawl first. Active techniques one at a time.

The next runtime layer is an isolated browser/API runner with authenticated crawl coverage and immediate cancellation. Active payload classes remain disabled until each technique passes its own authorization and containment gate.