What are the scan types and when should I use each?
S4E offers different scan types for different needs — from fast checks to full, continuous security monitoring. Here’s a simple breakdown:
Light Scan
Quick and limited.
→ Use for fast, low-impact checks.
Covers:
- SSL & DNS controls
- Misconfigurations (default passwords, backup files, etc.)
- Product-based network vulnerabilities
Good for: Routine or frequent basic scans
Limitations: No web crawling, limited depth, manual only
Full Scan
Comprehensive and detailed.
→ Use when you need full visibility across your asset.
Covers everything in Light Scan, plus:
- Web vulnerabilities (with crawling)
- Network vulnerabilities
- Product-based web vulnerabilities
- Exposed panels
- Information scans (tech detection, leaked data, etc.)
Good for: Full security assessments
Limitations: Manual only, no automatic rescan
Continuous Scan
Continuous scan that runs automatically.
→ Use for ongoing protection of critical assets.
Same coverage as Full Scan
Runs on a schedule, no manual action needed
Crawl-Only Scan
Discovers URLs and input fields — no vulnerability testing.
→ Use to map out web structure.
Good for: Planning future scans
Limitations: No security checks
Single Scan
Manual, one-time scan on a selected asset.
→ Use when you need to test something specific on demand.