---
title: "Risk Score Indicators"
canonical: "https://kb.cynergy.app/space/GS/912523265/Risk%20Score%20Indicators"
format: markdown
---
![image](media://4da96d42-3fc1-4c41-afa4-07e2607f76e9)

Description of each indicator in the risk score:

![image](media://19fff245-94c2-44b1-b44e-cd361b5c13ee)

**[Hijacking:](https://kb.cynergy.app/space/MD/899416125)**

A subdomain takeover occurs when an attacker gains control over a subdomain of a target domain. Typically, this happens when the subdomain has a canonical name (CNAME) in the Domain Name System (DNS), but no host is providing content for it. This can happen because either a virtual host hasn't been published yet or a virtual host has been removed. An attacker can take over that subdomain by providing their own virtual host and then hosting their own content for it.

As part of the Discovery process, Cynergy will try to identify a Hijackable Subdomain for the domain, If identified it would fail the category. 


**[Email Security:](https://kb.cynergy.app/space/MD/899416249/Email+Security+Vulnerabilities)**

As part of the discovery scan Cynergy conduct various email security scans such as SPF scan, DKIM scan, and DMARC Scan, once there is an issue identified, Cynergy will deduct the score based on the identified misconfiguration. 


**[DNS Security:](https://kb.cynergy.app/space/MD/912850945/DNS+Security+Vulnerabilities)**

As part of the discovery scan, Cynergy conducts several networks and DNS misconfiguration scans such as DNS zone transfer vulnerability scan and Open mail relay scan. once there is an issue identified, Cynergy will deduct the score based on the identified misconfiguration. 


**[Cloud Security:](https://kb.cynergy.app/space/MD/899416165/Cloud+Security+Vulnerabilities)**

As part of the discovery scan, Cynergy enumerates cloud services and storage accounts such as open S3 buckets and blobs, once identified, Cynergy would then inspect the content of the storage for possible sensitive information leakage, once identified, Cynergy will deduct the score based on the identified misconfiguration. 


**[Data Breach:](https://kb.cynergy.app/space/MD/899416380/Data+Leak+Exposure+Mitigations)**

As part of the discovery scan, Cynergy looks for sensitive keys, such as API keys and Credentials leaked in Paste sites and Git repositories, once identified, Cynergy will then deduct the score based on the nature and validity of the leaked Sensitive key. 


**[Compromised Credentials:](https://kb.cynergy.app/space/MD/899416369/Compromised+Employee+Credentials)**

As part of the discovery scan, Cynergy identifies the emails of organization employees and runs a scan to identify if there was a leak of their credentials in visible or darknet, as part of its internal data lake and external API keys, if identified, Cynergy would try to validate the credentials, once validated, Cynergy would either fail the category or deduct score based on the time of the leakage. 


**[Application Security:](https://kb.cynergy.app/space/MD/899416092/Application+Security+Vulnerabilities)**

As part of the discovery scan, Cynergy would try to identify low-hanging web application misconfiguration, such as assets not behind a Web Application Firewall, accessible Administrative Interfaces, etc.

Once identified, Cynergy will deduct the score based on the identified misconfiguration. 


**[3rd party Technologies security:](https://kb.cynergy.app/space/MD/899252687/CVE+Database)**

As part of the discovery scan, Cynergy would use internal scanners and external APIs to enumerate the 3rd party technologies, which include Analytics platforms. Frameworks, CDNs, WAFs, Javascript libraries, Servers, Programming languages, etc. Used as part of an asset. 

Once a technology is identified, Cynergy would try to get its version and correlate it with CVEs for the specific version. Based on the severity and exploitability of the CVE, Cynergy will deduct the score. 


**[Ports and Services Security:](https://kb.cynergy.app/space/MD/899416154/Exposed+Ports+%26+Services)**

As part of the discovery scan, Cynergy would try to identify open and accessible services for the identified assets, based on the type of the service and the associated weight to its exposure, Cynergy would deduct the score or fail the category.