---
title: "What can be scanned with Cynergy?"
canonical: "https://kb.cynergy.app/space/GS/901808175/What%20can%20be%20scanned%20with%20Cynergy%3F"
format: markdown
---
#### Cynergy has multiple automated scanning modules which allow you to scan many things:

1. Infrastructure Assets such as IPs and Subdomains - Open vulnerable and exploitable services
  1. Including IPV4 and IPV6 Ip addresses
  2. Including all TCP ports
2. Cloud Assets Instances and Buckets - Misconfigurations and exposed assets
  1. Supporting additional accurate scans after integration
3. Web applications - for OWASP vulnerabilities, vulnerable 3rd party technologies, and much more
4. Employee leaks- identify the credentials that were leaked and verify that they can’t be reused.
5. Sensitive data leaks in Paste sites, and identified assets

#### What we don’t scan:

- Kubernetes pods or instances.
- APIs - Not something we are good at since it is super complex to describe the API schema and conduct a meaningful scan without the context of correct requests.
- Single Page Applications - Browsing via SPAs is not in our core capabilities.


Want to learn more? [schedule a meeting](https://www.cynergy.app/demo-request/) with us to show you our capabilities