qsa.sh
curl https://qsa.shYou see what the internet sees of your host: open ports, detected services and versions, TLS posture, and CVEs matched to what is actually running.
Start here#
- Run your first scan — the 30 second path from command to findings.
- Reading your scan output — what each section of the stream means.
- How the scan works — the three tools, in order, and what each one contributes.
- Scan tiers — what Free, Full Pro and Deep each cover.
Sections#
- Guides — running scans, reading results, fixing what you find.
- How it works — the pipeline, the tools, the safeguards.
- Pricing — tiers, tokens, and how paid access works without an account.
- Security — retention, authorization rules, acceptable use.
- Reference — FAQ, troubleshooting, glossary.
Why an external scan#
Agent-based scanners see your host from the inside. They know what you configured. An external scan starts from outside your network and reports what an attacker can reach without credentials, which is a different and usually shorter list than your firewall rules suggest.
qsa.sh runs from scanner nodes on our infrastructure, not yours. There is no agent to install and no port to open.
Ground rules#
qsa.sh only ever scans the IP address you connect from. There is no field for typing another target. Known CGNAT ranges, mobile carrier addresses, IPv6 origins, and connections our data flags as proxy, VPN or Tor are refused before a scan starts.
You must be authorized to scan the host you connect from. See Acceptable use.