Dettack
Built by attackers, made for defenders

Welcome to Dettack

Dettack is an attack surface management platform. It maps everything you have exposed to the internet, scans it for vulnerabilities, and runs incident checks that sweep the public web for signs your sites have already been hacked. It works from the outside, the way an attacker would, with no agents, no credentials, and nothing to install.

Detect the attack. Check what attackers do.
Vulnerability scans plus incident checks. No noise. No card required, live in minutes, built in Indonesia.
14,000+
Active detection rules
4,000+
CVEs covered
30+
Incident signatures
A to F
Security grades
app.dettack.com/dashboard
Attack Surface Overview
Total Assets
128
+6 this week
Open Vulns
17
3 critical
Open Incidents
4
1 critical
Rating
D
Needs work

A preview of the Dashboard, rendered in the same theme and layout as the live console.

Two checks, kept separate

Dettack runs two kinds of check on the same footing. A vulnerability scan finds weaknesses in your software: known CVEs, misconfigurations, and exposures. An incident check sweeps the public web for signs a site has already been compromised, such as defacement, gambling injection, and hidden SEO spam. The two run on their own tracks and land in separate queues and views, so neither gets buried under the other.

Vulnerabilities and Incidents stay separate. Always.

What Dettack does

One scan, five stages

Every Dettack scan runs the same chain, in the same order, every time. The vulnerability workflow and the Incident Check run on their own tracks so their results never blur together.

  1. Discover Find every subdomain, using three passive sources.
  2. Probe Check what is alive, with HTTP fingerprinting.
  3. Capture Screenshot every host for visual evidence.
  4. Scan vulns Raise vulnerabilities, one per match, against 14,101 templates.
  5. Incident check Sweep for defacement and gambling injection, against 30 signatures.

How this documentation is organized

  • Getting started takes you from sign-up to your first scan.
  • Core workflow covers the Dashboard, Asset Groups, running scans, and reading results.
  • Findings explains Vulnerabilities, Incidents, resolving issues, reports, and activity.
  • Intelligence covers the security rating, AI insights, and alerts.
  • Account covers plans, upgrading, and your profile.
  • Live playground lets you run a simulated Full Scan right inside these docs.
New here?

Jump straight to the Quickstart, or open the Live playground to watch a scan run end to end.

Getting started

Quickstart

From a fresh account to your first full set of results in about five clicks. A Full Scan runs both the vulnerability workflow and the incident check on one domain, and usually takes 25 to 40 minutes. You can close the tab while it works.

Authorized targets only

Only scan domains you own or are explicitly authorized to test under a bug bounty, a vulnerability disclosure program, or a written pentest engagement. Dettack asks you to confirm this before you can scan.

  1. Create your account and verify your email.

    Sign up with an email and password, click the verification link, then accept the authorized-use Terms. See Accounts & sign-up.

    app.dettack.com/signup
    Check your email
    We sent a verification link to you@example.com. It expires in 24 hours.
  2. Open the Add menu.

    In the sidebar, click Add to reveal the three scan options.

    app.dettack.com/dashboard
    Add
    Full Scan
    Vulnerability Scan
    Incident Check
  3. Start a Full Scan.

    Pick Full Scan and enter a domain such as example.com. Press Enter to begin. Dettack creates an asset group for that root domain automatically.

    app.dettack.com/scan/new
    Run a full scan
    We will run both scans on this domain. This usually takes 25 to 40 minutes.
    Scan options · Port scan: Quick · Auto-rescan: Off
  4. Watch it run.

    The live scan page streams each stage as it happens: discovery, fingerprinting, port scan, screenshots, vulnerability analysis, and then the incident check.

    app.dettack.com/scans/a7f3c1
    Running48% · 9m elapsed
    Asset Discovery
    complete
    Vulnerability Analysis
    running
  5. Read your results.

    When it finishes, open the asset group to see discovered assets, Vulnerabilities, Incidents, and, on paid plans, your A to F security rating.

    app.dettack.com/groups/example-com
    Assets
    40
    Open Vulns
    9
    Rating
    D
    Critical
    Subdomain takeover on dangling CNAME
    legacy.example.com · Exposure

Every plan, including Free, runs the entire scan workflow. What the paid plans add is more root domains, unlimited asset results, reports, continuous rescans, the security rating, and AI insights. See Plans & upgrading.

Getting started

Accounts & sign-up

Every account gets its own private scan workspace. Your assets, findings, and reports are visible only to you. Getting in takes three steps: sign up, verify your email, and accept the Terms.

1. Sign up

On the sign-up page you provide an email, an optional display name, and a password of at least 8 characters, which you confirm. Click Create account. Dettack does not sign you in automatically. Instead it sends a verification email, and the form is replaced by a "Check your email" panel. The verification link expires after 24 hours, and you can resend it.

app.dettack.com/signup
Create your account

2. Verify your email

Open the email and click the link. The verify page confirms your account automatically and shows "Your account is now active." You can then sign in.

app.dettack.com/verify-email
Email verified
Your account is now active. You can sign in.

3. Sign in

On the login page, enter your email and password. There is a Keep me signed in for 7 days checkbox. Leave it off and you will be signed out as soon as you close the browser. Turn it on to stay signed in on a trusted device. If you forget your password, the Forgot password? link emails you a reset link that is valid for one hour.

app.dettack.com/login
Sign in

4. Accept the Terms

The first time you sign in, Dettack shows a full-screen gate titled Scan responsibly. You must tick two boxes to continue:

  • You agree to the Terms of Service and Privacy Policy.
  • You confirm you will only scan targets you own or are authorized to test.

Once both are ticked, Accept and continue takes you to the Dashboard. Unauthorized scanning can violate laws including Indonesia's UU ITE and UU PDP, the EU GDPR, and the US CFAA, so this consent is not optional.

app.dettack.com/terms/accept
Scan responsibly
One last step before you can scan.
Roles

An account can hold an admin role (can launch scans, delete groups, resolve findings, and run bulk actions) or a view-only role (read access, no scanning). View-only accounts see a "view-only" badge in the sidebar.

Core workflow

Dashboard

The Dashboard is your command center, an Attack Surface Overview that summarizes every asset, open vulnerability, open incident, and your posture across all groups. It refreshes on its own every 60 seconds and shows when it last updated.

app.dettack.com/dashboard

3 critical exposures need attention. View all open findings.

Total Assets
128
+6 this week
Asset Groups
7
Open Vulns
17
3 critical
Open Incidents
4
1 critical
Scans / week
21

The status banner, then a row of clickable KPI cards.

Status banner

A single colored line at the top tells you where you stand at a glance. Green means no critical or high-severity findings are open. Amber flags high-severity exposures, and red flags critical ones. Clicking it opens the full findings queue.

KPI cards

Five cards, each clickable, take you to the underlying view: Total Assets, Asset Groups, Open Vulnerabilities, Open Incidents, and Scans This Week. The vulnerability and incident cards turn red or amber to match your worst open severity.

Security rating block

On paid plans, two grade cards show your org-wide Vulnerability Rating and Incident Rating, from A to F. Below them, a "Groups by Security Rating" table lists your worst groups first, each with its grade pills, root domain, and asset count. Free plans see an upgrade card here instead. From this block you can also Generate report.

Breakdown charts and recent tables

Severity bars break down open Vulnerabilities and open Incidents, and category charts group them by type (CVE, Exposure, Misconfig, Weak Creds, SSL/TLS, DNS, Defacement, Gambling, SEO Spam, and Other). Two tables, Recent Vulnerabilities and Recent Incidents, list the latest items with severity, title, host, category, age, and status. Rows click through to the detail page.

Info-severity findings are hidden everywhere in Dettack. The queues you see only include critical, high, medium, and low.

Core workflow

Asset Groups

An asset group represents one root domain and holds everything Dettack discovered for it: subdomains and hosts, findings, incidents, screenshots, and scan history. You do not create groups by hand. Scan a domain and its group appears.

app.dettack.com/groups
example.com
40 assets · last scan 2h ago
3 critical9 findings
shop.example.net
12 assets · last scan 1d ago
Secure

Each group is a card showing its root domain, asset count, and status badges.

The groups list

Each group card shows the root domain, an external-link button, the asset count and last-scan time, and status badges: red for critical counts, amber for other findings, orange for incidents, or a green Secure pill when everything is clean. A group scanned as a single host carries a single host badge, meaning only the typed hostname was scanned and subdomain discovery was skipped.

Root-domain quota

Your plan sets how many distinct root domains you can hold. Free includes 1, Starter includes 3, Professional includes 10, and Enterprise is unlimited. Deleting an asset group frees its slot again.

Group detail

Opening a group shows its rating cards, a finding summary with clickable filter chips (SSL/TLS, live hosts, hosts behind a CDN, hosts with vulnerabilities, unique technologies), a severity chip row, and an open-ports card. Five tabs organize the rest:

  • Assets: every discovered host, searchable and filterable, with screenshot, hostname, HTTP status, ports, technology, TLS state, open-finding count, and a per-host grade.
  • Status: the workflow indicator for the latest scan, with a live progress readout.
  • Vulnerabilities: open vulnerabilities in this group, by severity, title, host, category, and age.
  • Incidents: incident tiles with screenshot thumbnails and a "how to validate" advisory.
  • History: a timeline of completed scans with new and resolved counts, duration, status, and a report download.

Asset detail

Each asset has its own page: a full-page screenshot, hostname, HTTP status and page title, technology chips, an overview card (IP addresses, CDN, server, TLS, first and last seen), its vulnerabilities, and an open-ports card that lists each port with its protocol, service, and version fingerprint.

Bulk actions and exclusions

In the asset table, admins can enter Select mode to act on many hosts at once: rescan findings or incidents, resolve, mark false positive, or exclude from scans. An excluded host (for example a honeypot) is skipped at every stage, with no packets sent, and is hidden until you toggle Show excluded.

Free result cap

Free scans map your whole attack surface but reveal only the first 20 asset results per root domain. The rest are blurred behind a lock that still shows how many hidden critical and high findings exist. Upgrade to Starter to reveal every subdomain.

Core workflow

Running scans

Dettack has three scan entry points, all reached from the Add menu in the sidebar. Scans run one at a time per account, in the order you start them.

The three scan modes

Full Scan

Runs the vulnerability workflow and the incident check on one domain, from a single input. Subdomain discovery is always on. Best default.

Vulnerability Scan

Discovers subdomains, fingerprints technology, captures screenshots, then analyzes for vulnerabilities. Adds a single-host scope toggle.

Incident Check

Searches the public web for defacement and injection signatures, then verifies each hit on the live page.

Starting a scan

Type a domain into the input and press Enter. A collapsible Scan options section lets you tune the run:

  • Scope (Vulnerability Scan only): Discover subdomains enumerates and scans every live host, or Single host only scans just the hostname you typed.
  • Port scan intensity (Full Scan): Quick covers common web and sensitive ports and suits most runs, Deep covers the top 1000 plus curated high-value ports, and Stealth uses a small port set at a very low send rate.
  • Auto-rescan cadence: Off, Daily, Weekly, or Monthly, with an hour-of-day in your local time. This is a paid feature.
app.dettack.com/scan/full
What do you want to scan?
Scope
Discover subdomainsSingle host only
Port scan intensity
QuickDeepStealth
Auto-rescan
OffDailyWeeklyMonthly

The five-stage workflow

A vulnerability scan always runs the same five stages in order:

  1. Discover Enumerate subdomains using Subfinder plus public sources like Certificate Transparency and HackerTarget.
  2. Probe Fingerprint each host: HTTP metadata, status, page title, and technology stack.
  3. Port scan Sweep for open ports, at the intensity you chose.
  4. Capture Take a full-page screenshot of each live host with headless Chromium.
  5. Scan vulns Match every host against 14,000+ detection rules, including dangling-subdomain takeovers, tiered by severity.

The Incident Check runs on a separate track: it queries search engines for defacement and SEO-spam signatures, then fetches and verifies each candidate page before raising an incident. A Full Scan runs the vulnerability chain, then the incident chain, as one continuous pipeline.

Want to see this happen live? Open the Live playground and run a simulated Full Scan through all six stages.

Core workflow

Scan results

The live scan page shows everything as it happens, then becomes the final result. It streams over a live connection and falls back to polling, so you can leave and come back at any time.

app.dettack.com/scans/a7f3c1
FULL ASM Running 62% · 14m elapsed
Asset Discovery
complete
Vulnerability Analysis
running

The live scan header: mode badge, run status, percent and elapsed time, and a Stop control for admins.

What the page shows

  • A mode badge (Full ASM, Vulnerability Scan, Incident Check, or Asset Discovery), the run status, overall percent, and elapsed and estimated time.
  • A workflow overview of numbered step cards, and a stage chain where each pill shows running, complete, or pending.
  • A live asset table that fills in as hosts are found, and a live findings list sorted by severity.
  • For incident checks, a live page checks feed tags each candidate URL as a match or clean, with a reason.
  • A right-hand summary rail with counts for candidates, live hosts, screenshots, and vulnerabilities or incidents.

When it finishes

A completion callout shows one of three outcomes: Scan fully completed in green, Scan was not completed in amber (cancelled, with partial results kept), or Scan failed in red. On paid plans a per-scan security rating card appears. If every incident candidate came back clean, you get an all-clear panel confirming no defacement, gambling injection, or SEO spam was found on indexed pages. A View asset group button takes you to the full results.

Findings

Understanding findings

Everything Dettack surfaces is a finding. The product splits findings into two kinds based on what they are: Vulnerabilities and Incidents. A vulnerability is a weakness that could be exploited. An incident is a live page that has already been compromised.

Severity levels

Each finding carries one severity, shown as an uppercase pill. Info-severity is stripped out and never shown.

Critical High Medium Low

What a finding detail shows

Opening a finding shows its severity, title, host, category, a kind pill (vulnerability or incident), a status pill (open, resolved, or false positive), and when it was last seen. Below that, each of these blocks appears when it has content: a description, a note, a search snippet, remediation guidance, a response excerpt, references, and when it was first seen. Incidents also show a screenshot. An AI Analysis panel sits at the bottom.

app.dettack.com/vulnerabilities/3b9e
Critical vulnerability open
Subdomain takeover on dangling CNAME
legacy.example.com · Exposure

A vulnerability detail with its status pills and admin actions.

Actions you can take

Admins can act on a finding:

  • Rescan (incidents): re-fetch the URL and re-run the classifier. If it no longer matches, the incident auto-resolves.
  • Mark as resolved: moves it to Resolved. It will reopen if a future scan detects it again.
  • Mark as false positive: moves it to the closed view and will not reopen on rescan, even if the pattern recurs.
  • Delete: permanent, and for incidents also removes the screenshot.

The list views also offer bulk Select mode so you can resolve or mark false positive on many findings at once.

Findings

Vulnerabilities

A vulnerability is a detected weakness or exposure: a known CVE, an exposed file or service, a misconfiguration, a weak TLS setup, or a dangling subdomain that could be taken over. These come from the Vulnerability Scan.

Two ways to browse

The sidebar gives you two surfaces:

  • All Findings is a single cross-group table of every open vulnerability and incident. It is your open work queue. Filter by severity or by kind (both, vulnerabilities, or incidents), and sort by severity or by last seen.
  • Vulnerabilities starts with a group picker, then shows one group's vulnerabilities as cards, each with a severity chip, title, an optional New badge for items first seen in the latest scan, and expandable detail.
app.dettack.com/issues
All 21Critical 3High 9Medium 6Low 3
SevTitleHostCategoryLast seen
CritSubdomain takeoverlegacy.example.comExposure2h ago
HighApache RCE (CVE-2021-41773)legacy.example.comCVE2h ago
HighExposed .git directorystaging.example.comExposure2h ago
MedWeak TLS ciphers acceptedmail.example.comSSL/TLS2h ago
LowServer version disclosed in bannerapi.example.comMisconfig2h ago
Pick a severity above to filter the table.

The All Findings queue, filtered by severity and kind.

Categories

Vulnerabilities are grouped by category, including CVE, Exposure, Misconfig, Weak Creds, SSL/TLS, and DNS. The Dashboard and group pages chart your open counts by category so you can see where your exposure concentrates.

Findings

Incidents

An incident is a live page that has already been compromised. The Incident Check sweeps public search results for three kinds of signature and then verifies each hit on the real page. Because an incident is a confirmed compromise, it weighs more heavily on your grade than a vulnerability of the same severity.

What the Incident Check looks for

  • Defacement: hacked-by pages, "pwned" and "greetz" markers, and replaced content.
  • Gambling injection: injected keywords like "slot gacor", "maxwin", "judi online", and "togel".
  • SEO spam: hidden backlinks, doorway pages, and keyword hacks, including links hidden off-screen or with visibility turned off.
app.dettack.com/incidents
HACKED BY
x-Ghost-Team
your security is our art
Critical
Defacement detected
www.example.com · Defacement
SLOT GACOR
MAXWIN x500
DAFTAR JUDI ONLINE - BONUS 100%
Critical
Gambling injection detected
staging.example.com · Gambling
cheap-loans-online · buy-followers · casino-bonus-2026 · replica-watches · payday-advance · discount-pharma · seo-backlinks-cheap
High
Hidden SEO spam backlinks
legacy.example.com · SEO Spam
Illustrative captures of the three incident types. Real customer URLs stay private.

Incidents render as tiles with a screenshot, severity, and matched host.

Browsing incidents

Like vulnerabilities, incidents open from a group picker, then show one group's incidents as tiles with a screenshot thumbnail, the matched URL, and a "first seen" time. Each incident has its own detail page with the affected URL, a screenshot, and the search snippet that matched. Admins can rescan an incident to reconfirm it, or resolve it.

How to validate

Some injected SEO links are hidden in the page source rather than visible on screen. To confirm one, open the page source and look for the matched keyword shown in the incident's search snippet.

Findings

Resolved & false positives

Once you have dealt with a finding, it moves out of the open queue into the Resolved view. Dettack keeps two closed states, and they behave differently on the next scan.

Resolved vs false positive

Resolved

You fixed the issue. It moves out of the queue but will reopen if a future scan detects it again, so you always know if a fix regressed.

False positive

The detection was wrong or the issue is known and accepted. It will not reopen on rescan, even if the same pattern recurs.

The Resolved view

The Resolved page has two tabs. By group shows a group picker, then that group's closed findings with sub-tabs for All, Resolved, and False positive. False positives is a flat cross-group table of every item you have dismissed. In both, admins can Restore to open (which counts toward your grade again) or Delete permanently.

app.dettack.com/resolved
AllResolvedFalse positive
SevTitleHostStatus
HighExposed .git directorystaging.example.comResolved
MedWeak TLS ciphers acceptedmail.example.comResolved
LowServer banner disclosedapi.example.comFalse positive

Not sure which findings are noise? The AI Triage panel on a group can flag likely false positives with a confidence level and a reason, so you can clear them faster.

Findings

Reports

Dettack turns any view into a shareable report. Reports are built in your browser and saved to a history so you can download the exact same report again later. Reports are a paid feature.

Generating a report

Click Generate report on the Dashboard, an asset group, or a findings view. You get up to three formats:

  • Color PDF: a full-color report, best for screen.
  • Print-friendly PDF: a white-background version that saves color ink.
  • CSV: one row per item, for sorting and filtering in a spreadsheet. Offered where a flat table makes sense.

Reports can be scoped to your whole organization, one asset group, your vulnerabilities, your incidents, or a single scan. The audit-ready PDF is designed to work as ISO 27001 evidence.

app.dettack.com/dashboard
Color PDF
Print-friendly PDF
CSV

Report History

The Report History page lists every report you have generated, newest first, with its scope, kind, item count, date, format badge, and a Download button that rebuilds it exactly. You can filter by asset group, vulnerabilities, or incidents.

app.dettack.com/reports
ScopeKindItemsDateFormat
example.comAsset group402h agoPDF
OrganizationVulnerabilities171d agoCSV
Paid feature

PDF and CSV reports are available on Starter and above. On Free, the Reports button is locked and links to the upgrade page.

Findings

Activity

The Activity feed is the running log of every scan: what is queued, what is live right now, and what has finished. Live rows update every couple of seconds.

app.dettack.com/activity
All 19Live 1Completed 18Failed 0

Filter pills, then one row per scan with a live progress bar.

What each row shows

A status badge (Running, Queued, Fully completed, Warnings, Failed, or Stopped early), a mode icon, the target, optional badges for a single-asset rescan or an auto rescan, the scan type, the group, start and finish times, a live progress bar, and per-side stats for live assets, vulnerabilities, and incidents. Admins can Stop a live scan, Delete a finished record, or View the scan detail.

A Full Scan is really two scans working together (the vulnerability run and the incident check). Activity folds them into one "Full Scan" row that shows both halves and both counts. Stopping or deleting that row acts on both.

Intelligence

Security rating

Dettack grades each asset group from A to F, in two separate categories: a Vulnerability Rating and an Incident Rating. The grade is deliberately driven by your single most serious open issue, not an average, so it reflects real risk rather than being diluted by clean assets.

D
Vulnerability Rating
64% · Needs work
F
Incident Rating
41% · Failing

Two grade cards, side by side, one per category.

The grade bands

GradeScoreMeaning
A90% and upClean
B80 to 89%Good
C70 to 79%Acceptable
D60 to 69%Needs work
FBelow 60%Failing

How the grade works

Your worst single open issue sets the best grade you can reach. One open critical caps you at F, one high at C, one medium at B, and one low still allows an A. An incident hits harder than a vulnerability of the same severity. Adding more issues of the same level pushes the score lower, with the first few counting the most. Clearing your worst issue lifts the grade immediately, and adding clean subdomains never lifts a bad grade.

Paid feature

Free runs the same scans, but the A to F rating, the per-domain scores, and downloadable reports come with Starter and above.

Intelligence

AI insights

Dettack can put a language model to work on your findings. All three AI features are on demand, meaning nothing is generated until you click, and none of them ever change your actual findings. Results are cached and always carry a reminder to verify before acting.

Three AI features

  • Explain this finding: on any finding detail, produces a plain-language AI Analysis of what the issue is and why it matters.
  • Summarize this group: on an asset group, produces an AI Summary, an executive overview of the group's open findings.
  • Triage findings: on an asset group, produces an AI Triage that labels each open finding as "Looks real" or "Likely false positive", with a confidence level, a reason, and a suggested severity when it differs. Likely false positives are sorted to the top.
AI Triage
Likely false positiveconfidence: medium
Server version disclosed in banner
This is informational and low impact on a host already behind a CDN. Suggested severity: low → info
AI-generated, advisory only. Nothing was changed.

AI Triage suggests which findings are likely noise, without touching them.

AI insights appear only when the platform operator has configured a model provider. If a provider is set up but your plan cannot use it, an upgrade prompt shows instead. AI insights are a paid feature.

Intelligence

Telegram & email alerts

Dettack reaches you where you already are. Email keeps you posted on your scans, and Telegram gives you push alerts plus read-only commands scoped to your own assets.

Email notifications

By default you get an email when a scan starts and again with a summary when it finishes or is stopped. You control this from a link in any scan email, on an Email preferences page with three choices:

  • Keep everything: email me when a scan starts and again with the summary.
  • Fewer emails: only when a scan finishes or is stopped, skipping the "started" note.
  • Stop all scan emails: nothing about scans. Your results still appear on the dashboard.

These preferences cover scan notifications only. Account email, such as address verification and payment receipts, is always sent.

app.dettack.com/unsubscribe
Email preferences
Keep everything
Email me on start and again with the summary.
Fewer emails
Only when a scan finishes or is stopped.
Stop all scan emails
Nothing about scans.

Telegram alerts

Connect Telegram from your Profile. Dettack pings you when a scan finishes and when new critical or high findings appear on your assets, and it answers read-only chat commands that only ever see your own scans and findings.

  1. Click Connect Telegram. Dettack mints a one-time code and shows a QR code.
  2. Open the bot. Scan the QR with your phone, or open the bot in Telegram and press Start. Send the code if asked.
  3. You are linked. The card flips to Connected on its own and shows your Telegram username. A Disconnect button unlinks it any time.
app.dettack.com/profile
Connect Telegram
Scan with your phone, or open the bot and press Start.
Paid feature

Telegram alerts are available on Starter and above. On Free, the connect button is locked and links to the upgrade page. If a linked account later drops below Starter, alerts pause until you upgrade again.

Account

Plans & upgrading

Every plan runs the full scanning workflow. Upgrading buys more root domains, unlimited asset results, PDF and CSV reports, continuous scanning, the security rating, and AI insights. There are four tiers.

The four tiers

PlanRoot domainsBest for
Free1Trying Dettack on a single domain.
Starter3Unlimited assets, continuous scanning, PDF and CSV exports.
Professional10The same workflow, room for a much wider portfolio.
EnterpriseUnlimitedUnlimited scale with dedicated infrastructure.

What each tier includes

FeatureFreeStarterProfessionalEnterprise
Full scan workflowYesYesYesYes
Vulnerability scan and Incident CheckYesYesYesYes
Asset screenshotsYesYesYesYes
Asset results per root domainFirst 20UnlimitedUnlimitedUnlimited
Historical data7 daysKeptKeptKept
PDF and CSV reportsNoYesYesYes
Continuous scanningNoYesYesYes
Security rating (A to F)NoYesYesYes
Telegram alerts and AI insightsNoYesYesYes
Dedicated scanner node, SLANoNoNoYes
Free retention

Free keeps scan data for 7 days. Asset groups older than that are removed. Upgrade to keep your scan history. Paid plans keep it.

Upgrading

The upgrade page shows a live "root domains used" counter and a monthly or yearly toggle, where yearly gives two months free. Starter and Professional check out through Midtrans, with monthly and annual options. If you have a discount code, expand "Have a discount code?", enter it, and apply. Enterprise is sales-led: use Contact us to open the enquiry form and a specialist will follow up.

Account

Profile & settings

Your Profile page holds your identity and preferences. Each section is its own small form with its own save button, so you can change one thing without touching the rest.

What you can change

  • Display name: shown in your sidebar header and on report covers.
  • Email address: you can sign in with either your username or this email.
  • Password: enter your current password and a new one of at least 8 characters.
  • Telegram alerts: connect or disconnect the bot, as described in Alerts.
  • Scan tier or license: redeem a license key in the form DETK-XXXX-XXXX-XXXX-XXXX to unlock scanning.

Your username is fixed and cannot be changed.

app.dettack.com/profile

Each setting is an independent form with an inline save.

Try it

Live playground

This is a fully interactive, simulated Full Scan running right inside the docs. Enter a domain and press start to watch Dettack move through all six stages, stream in assets, and surface vulnerabilities and incidents. No real network traffic is sent. It is a faithful walkthrough of what the live scan page does.

Idle. Enter a domain and start a scan.0%
0
Assets
0
Vulnerabilities
0
Incidents
-
Grade
Workflow stages
Discovered assets
Vulnerabilities & incidents

Type any domain and press start. The hostnames build from what you enter, while the assets and findings are illustrative sample data. In the real product, run a scan from the Add menu against a domain you are authorized to test.

What you just watched

The playground mirrors the real pipeline: discovery and fingerprinting stream hosts in, the port scan and screenshot stages run, vulnerability analysis raises weaknesses, and finally the incident check confirms compromised pages. In the live console the same page also lets admins stop a scan, shows an estimated finish time, and produces a security rating on completion.