# Panoptic Scans > Panoptic Scans is a comprehensive vulnerability scanning platform that provides continuous monitoring of external attack surfaces through advanced port scanning, network vulnerability assessment, web application security testing, and template-based vulnerability detection. The platform combines industry-standard open-source tools (Nmap, OpenVAS, ZAP, and Nuclei) with detailed attack narratives to deliver actionable security insights for SOC2 compliance and penetration testing. Panoptic Scans features a modern web interface for scheduling scans, managing vulnerabilities, and generating professional reports with custom branding and detailed attack scenarios. Key capabilities include: - **Network Vulnerability Scanning**: OpenVAS-powered comprehensive network security assessments for both external and internal networks - **Internal Network Vulnerability Scanning**: Run OpenVAS scans on internal networks from your own VM using the provided local scan script, with results uploaded to the Panoptic platform for centralized vulnerability management - **Web Application Security Testing**: ZAP integration for DAST vulnerability scanning, including authenticated scanning behind login pages - **Authenticated ZAP Scanning**: Scan behind login pages using Selenium-based authentication scripts that replay login flows before ZAP spiders and scans the target application - **Port Scanning & Discovery**: Nmap-based network reconnaissance and service enumeration - **Template-Based Vulnerability Detection**: Nuclei-powered scanning with community-maintained templates - **Detailed Attack Narratives**: AI-generated analysis of how vulnerabilities can be chained together in real-world attack scenarios - **Compliance Reporting**: SOC2 and HIPAA-aligned vulnerability reports - **Scheduled Scanning**: Automated recurring scans with email notifications - **Multi-tenant SaaS**: Role-based access with subscription tiers (trial, basic, premium, pro) ## Scanning Capabilities - [OpenVAS Network Scanning](https://panopticscans.com/soc2-network-vulnerability-scanning): Comprehensive network vulnerability assessment for SOC2 compliance, supporting both cloud-hosted external scans and self-hosted internal network scans - [ZAP Web Application Scanning](https://panopticscans.com/dast-application-vulnerability-scanning): Dynamic application security testing for web applications, with support for authenticated scanning behind login pages using Selenium-based login scripts - [External Attack Surface Monitoring](https://panopticscans.com/external-attack-surface-monitoring): Continuous monitoring of internet-facing assets and security posture - [Internal Network Vulnerability Scanning](https://panopticscans.com/openvas-vulnerability-scan): Run OpenVAS vulnerability scans on internal networks using a self-hosted script on your own VM, with results uploaded to Panoptic for centralized management and reporting - [Vulnerability Scanning for MSPs](https://panopticscans.com/vulnerability-scanning-for-msps): Affordable vulnerability assessment and security visibility for managed service providers and their customers ## Tool-Specific Pages - [OpenVAS Vulnerability Scanner](https://panopticscans.com/openvas-vulnerability-scan): Hosted OpenVAS scanning service for network security assessments - [Nmap Port Scanner](https://panopticscans.com/nmap-port-scanning): Advanced network discovery and port scanning capabilities - [ZAP Web Scanner](https://panopticscans.com/zap-vulnerability-scan): ZAP web application security testing service - [Nuclei Vulnerability Scanner](https://panopticscans.com/nuclei-vulnerability-scan): Fast template-based vulnerability detection with community-powered templates ## Platform Features - [Vulnerability Management](https://panopticscans.com/dashboard): Web-based dashboard for tracking vulnerabilities, managing scans, and viewing reports - [Detailed Attack Narratives](https://panopticscans.com/#features): Analysis explaining how vulnerabilities can be exploited in attack chains ## Report Formats - **Multiple Export Options**: PDF, CSV, HTML, TXT and XML report formats for comprehensive vulnerability documentation - **Professional Reporting**: Custom branding and compliance-aligned reports for enterprise use - **Historical Tracking**: Scan history and trend analysis across multiple scan runs ## Platform Capabilities - **RESTful API**: Full-featured API for programmatic scan management, vulnerability tracking, report generation, and internal scan result uploads - **Authenticated Web Scanning**: ZAP scans can authenticate behind login pages using user-provided Selenium Python scripts, enabling full DAST coverage of protected web applications - **Internal Network Scanning**: Self-hosted OpenVAS scanning via a downloadable script (`openvas_local_scan.sh`) that runs on the user's own VM and uploads results to Panoptic for centralized vulnerability management - **Free Trial Scans**: No-cost vulnerability scans for new users to evaluate the platform - **Google OAuth Integration**: Streamlined authentication via Google accounts for easy onboarding - **Vanta Integration**: Direct compliance workflow integration for automated evidence collection ([Learn More](https://panopticscans.com/vanta-vulnerability-scanning)) - **Email Notifications**: Automated scan completion alerts and vulnerability summaries - **Hybrid Deployment**: Cloud-delivered external scanning with no agents required, plus optional self-hosted internal network scanning for comprehensive coverage ## Compliance & Integrations - [Vanta Vulnerability Scanning](https://panopticscans.com/vanta-vulnerability-scanning): Purpose-built for Vanta customers who need quarterly vulnerability scanning, auditor-ready evidence, and zero infrastructure management. Satisfies SOC 2 (CC7.1, CC7.2, CC7.3) and ISO 27001 (A.12.6.1) control requirements with clean evidence uploads directly to Vanta. ## API Documentation Panoptic Scans offers a comprehensive RESTful API for automation and integration: - [Interactive API Documentation](https://panopticscans.com/api-docs): Full API reference with live testing capabilities and authentication - [OpenAPI Specification (YAML)](https://panopticscans.com/openapi.yaml): Industry-standard OpenAPI 3.0 specification for SDK generation - [OpenAPI Specification (JSON)](https://panopticscans.com/openapi.json): JSON format specification for tool import (Postman, Insomnia, etc.) ### API Capabilities - **Scan Management**: Create, update, delete, and monitor security scans programmatically, including authenticated ZAP scans and internal OpenVAS scans - **Internal Scan Results Upload**: Upload OpenVAS scan results from self-hosted internal network scans via `POST /api/scans/{uuid}/results` - **Vulnerability Tracking**: List, filter, sort, and manage vulnerabilities with status updates - **Target Management**: Organize and track scan targets with vulnerability counts - **Report Downloads**: Retrieve scan reports in multiple formats (PDF, CSV, HTML, TXT, XML) - **Run History**: Access historical scan runs and their associated reports - **Authentication**: JWT-based Bearer token authentication with token refresh - **Pagination**: Efficient data retrieval with configurable pagination (up to 100 items per page) - **Filtering & Sorting**: Advanced query capabilities for vulnerabilities and targets - **Export Functions**: CSV export for vulnerabilities with customizable filters ## Free Tools & Trial - [Free Trial Scans](https://panopticscans.com/register): Complimentary vulnerability assessments for new users - [HTML Encoder/Decoder](https://panopticscans.com/html-encoder-decoder): Free web development utility tool for encoding and decoding HTML content ## Business Information - [Pricing](https://panopticscans.com/pricing): Subscription plans and trial options for different organizational needs - [Privacy Policy](https://panopticscans.com/privacy): Data handling and privacy practices for customer information - [Terms of Service](https://panopticscans.com/terms): Platform usage terms and conditions - [Refund Policy](https://panopticscans.com/refund): Subscription cancellation and refund procedures ## Competitive Analysis - [Panoptic Scans vs Nessus](https://panopticscans.com/compare/nessus-versus-panoptic-scans): Comparison highlighting detailed reporting and simplified user experience - [Panoptic Scans vs Qualys](https://panopticscans.com/compare/qualys-versus-panoptic-scans): Open-source tools advantage and compliance-aligned reporting - [Panoptic Scans vs Rapid7](https://panopticscans.com/compare/rapid7-versus-panoptic-scans): Agility and simplicity in vulnerability management - [Panoptic Scans vs Intruder](https://panopticscans.com/compare/intruder-versus-panoptic-scans): Detailed attack narratives and integrated open-source tools ## Support & Contact - **Support**: Available through dashboard for registered users with dedicated customer success - **Integration Questions**: Vanta and API integration assistance for enterprise customers - **Trial Support**: Help getting started with free scans and platform evaluation ## Optional - [OpenVAS Documentation](https://www.openvas.org/): Open-source vulnerability scanner documentation and configuration guides - [ZAP Documentation](https://www.zaproxy.org/docs/): Web application security scanner documentation and API reference - [Nmap Documentation](https://nmap.org/docs.html): Network discovery and security auditing tool documentation - [Nuclei Documentation](https://docs.projectdiscovery.io/tools/nuclei/overview): Fast and customizable vulnerability scanner documentation and template reference