What is web scanning?¶
Web scanning searches for pages, files, technologies, versions, administrative endpoints or vulnerabilities. It is reconnaissance, not proof that the scanner authenticated, exploited a weakness or accessed data.
Read the request sequence¶
Preserve source route, paths, timestamps, user agent or tool markers, responses, sizes and authentication attempts. Broad repeated probes can show automated internet-wide scanning; changed requests after one informative response can support focused target selection.
A successful status code may return a generic page, and repeated failure can still show preparation. Retain enough response context to establish what the scanner actually learned.
Compare with authorised and routine scanners¶
Security teams, researchers, search engines and monitoring providers perform similar activity. Check penetration-test windows, vulnerability platforms, indexing and provider services.
The source may be a cloud scanner, proxy or compromised host and does not identify an offender. Follow any later authentication or exploit event separately rather than treating discovery as access.
Key takeaway
Treat web scanning as evidence of what was searched for and learned, distinguishing broad automation, focused follow-up and any later successful access.