<?xml version='1.0' encoding='UTF-8'?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>

<title>ShadowTrackr.com Blog</title>
<link>https://shadowtrackr.com/blog</link>
<atom:link href="https://shadowtrackr.com/rss" rel="self" type="application/rss+xml" />
<description>Updates on ShadowTrackr development</description>
<language>en-us</language>
<item>
<title>Post-quantum cryptography report and new weekly PDF</title>
<link>https://shadowtrackr.com/blog/post_quantum-cryptography-report-and-new-weekly-pdf</link>
<guid>https://shadowtrackr.com/blog/post_quantum-cryptography-report-and-new-weekly-pdf</guid>
<description>Two things this time: a new compliance report for post-quantum cryptography, and a redesigned weekly PDF report.

Post-quantum cryptography readiness report

Attackers can record encrypted traffic today and decrypt it once quantum computers are powerful enough. This is called "harvest now, decrypt later", and it is the reason quantum-safe encryption matters now, not in ten years. The new Post-Quantum Cryptography Readiness report shows for each of your servers whether its encryption is quantum-safe.

We check web encryption (TLS) and remote login (SSH) on every server. Each server gets one of five statuses: Quantum-safe, Partly quantum-safe, Outdated version, Not quantum-safe, or Not checked yet. It also gets a score from A+ to F. Those scores are averaged into one score for your organisation.

Addresses behind a service like Cloudflare show that service's settings, not your own server's. The report marks these, and gives a separate score for your own servers, so a CDN doesn't hide (or inflate) your real position.

You can get the report with the query $post_quantum_cryptography_report, or activate it from the report library. More details are in the documentation.

A new weekly PDF format

The weekly PDF report that lands in your inbox on Monday morning has a new format. It now includes a summary of:


  the NCSC TLS guidelines report
  the post-quantum cryptography report
  the supplier dependency report (enterprise customers only)


The goal is a more actionable report with better insight into how to reduce your risk. The previous format had too many long rows of results, which for some of you made it hard to see where to start. The new format gives you the overview first. The full detail is still one click away in ShadowTrackr, and you can still use the individual reports to get every row.

The weekly PDF is still the only report that is emailed by default, and you can add as many recipients as you like. They don't need a ShadowTrackr account.

Please let us know what you think. If something is missing, unclear or just not useful, send us feedback. We use it to decide what to improve next.</description>
<pubDate>Mon, 05 Oct 2026 00:00:00 +0000</pubDate>
</item>
<item>
<title>NCSC TLS guidelines report</title>
<link>https://shadowtrackr.com/blog/ncsc-tls-guidelines-report</link>
<guid>https://shadowtrackr.com/blog/ncsc-tls-guidelines-report</guid>
<description>We have a new compliance report available based on the Dutch NCSC TLS Guidelines.
The TLS guidelines are a  strict baseline for Dutch government organizations and vital sectors, and specify what cryptography to use for TLS settings like protocols, ciphers suites and keys.

Everything is categorized in four groups: Good, Sufficient, Phase out and Insufficient. You can use the query $ncsc_tls_report to get the report, or just get if from the report library
The results, including advice on what to improve, are also visible on all certificate pages.

There is also a big UX upgrade for the GUI, so things should be easier to find and understand.</description>
<pubDate>Mon, 28 Sep 2026 00:00:00 +0000</pubDate>
</item>
<item>
<title>Improved internet standards index</title>
<link>https://shadowtrackr.com/blog/improved-internet-standards-index</link>
<guid>https://shadowtrackr.com/blog/improved-internet-standards-index</guid>
<description>Until now, all of the internet.nl-style checks (IPv6, DNSSEC, TLS, HTTP security headers, RPKI, and so on) only lived inside the $internet_standards_report overview. That was fine for a weekly summary, but it meant you couldn't query or alert on a single check without pulling the whole report.

That's changed. internet_standards is now its own index, with one row per url and one field per check. Each check comes back as good, failed, recommended, optional, error or not_tested, so you can search or alert on any individual check directly, for example:

index=internet_standards dnssec_valid=failed

index=internet_standards tls_version=failed OR tls_ciphers=failed

index=internet_standards hsts!=good

That last one is handy if you want to catch anything that isn't fully green, not just outright failures, since recommended and optional verdicts won't show up as failed. You can also alert on the overall score dropping:

index=internet_standards score&lt;70

Note that urls where nothing could be tested at all (dead domain, no webserver) don't appear in this index, since it only holds scan results, not every url you track. See Internet Standards for the full field list, including the points_* fields if you want to see exactly how a partial score was earned.

The $internet_standards_report magic query is still there and works exactly as before, it's still the easiest way to get a full overview across all your assets, and it now pulls from this same index under the hood, so the two stay in sync.

New: dnssec_chains index

Alongside this, there's a dnssec_chains index. Where internet_standards just gives you a pass/fail on dnssec_exists and dnssec_valid, dnssec_chains runs a full validating resolve and records the actual chain of trust, so you can see exactly where it breaks instead of just getting a red X:

index=dnssec_chains status=bogus

index=dnssec_chains status=indeterminate

The status field is one of secure, insecure, partial, bogus or indeterminate, and raw_error fills in with the resolver error when a check can't be completed at all. DNSSec chains are monitored for all your urls by default. Full details at DNSSEC Chains.</description>
<pubDate>Mon, 21 Sep 2026 00:00:00 +0000</pubDate>
</item>
<item>
<title>Updated GUI</title>
<link>https://shadowtrackr.com/blog/updated-gui</link>
<guid>https://shadowtrackr.com/blog/updated-gui</guid>
<description>Last week was tech debt week. There were a few things waiting for a big refactor and they are all done now. On of the most visible is a more consistent GUI style, with better contrast. There might still be some tweaks coming.

In the backend, which none of you see, we now have nice workflows to keep track of operational work like maintaining supplier mappings, discovery settings and lists, and other reviews. Internal service alerts have moved to Matrix, a European messaging system gaining traction in some North-West European countries.</description>
<pubDate>Mon, 07 Sep 2026 00:00:00 +0000</pubDate>
</item>
<item>
<title>GUI and API performance upgrade</title>
<link>https://shadowtrackr.com/blog/gui-and-api-performance-upgrade</link>
<guid>https://shadowtrackr.com/blog/gui-and-api-performance-upgrade</guid>
<description>The two last updates have been a bit bumpy, but they succeeded and opened the door new functionality and a big performance upgrade.

The code that actually provides the performance update has gone live yesterday and should be very noticeable. </description>
<pubDate>Mon, 31 Aug 2026 00:00:00 +0000</pubDate>
</item>
<item>
<title>Parked assets and website security score</title>
<link>https://shadowtrackr.com/blog/parked-assets-and-website-security-score</link>
<guid>https://shadowtrackr.com/blog/parked-assets-and-website-security-score</guid>
<description>Last week’s update had two unforeseen effects.

The first is that the discovery algorithm update caused ShadowTrackr to discover a lot more assets in some cases. We expected to find a little more, and that happened on most accounts. However, some accounts have public IP ranges where DNS records have been enumerated for every IP address. These were all added as assets.

For two multi-tenant accounts, this resulted in tens of thousands of extra assets that only added noise. These extra assets are rarely accessible from the internet (or are not even up).

ShadowTrackr now recognizes these types of assets and puts them under “parked URLs” and “parked hosts”. Parked assets do not count towards your total assets, so you are not paying for them. They are checked randomly every 10–20 days, and if they are found to be up, they are moved to your regular monitored assets.



The second effect was that the new, faster website security checks also included a change in scoring. This was done to keep the scoring in line with the Mozilla Observatory scores. The scoring has become stricter, so some sites that had a decent score before now have lower scores. As usual, the website pages show a breakdown of the scoring and provide tips on how to improve your grade.



This week, we’ll be doing a major refactor of the events index. Our goal is to provide you with more useful events and alerts, but to get there and be able to scale up further, we need to go through this first. You should not notice anything during the migration, as it will run in the background.</description>
<pubDate>Mon, 24 Aug 2026 00:00:00 +0000</pubDate>
</item>
<item>
<title>NCSC NL vulnerabilities report</title>
<link>https://shadowtrackr.com/blog/ncsc-nl-vulnerabilities-report</link>
<guid>https://shadowtrackr.com/blog/ncsc-nl-vulnerabilities-report</guid>
<description>This week's update is actually a big update on a lot of scanner node modules. This is a quality improvement, but not one that will stand out particularly if you are using the GUI. You'll just have better quality results.

What does stand out to end users is the new $ncsc_vulnerabilities_report. Since we track all advisories from the Dutch NCSC now, we can provide reports on the CVE numbers in those reports that are relevant for the software we have detected on your assets. Will the most pressure to resolve these CVEs is on government and public organizations, it is a good idea for everyone to prioritise these. These vulnerabilities have been picked out of the bulk for a good reason.</description>
<pubDate>Mon, 17 Aug 2026 00:00:00 +0000</pubDate>
</item>
<item>
<title>Single Sign-On (SSO) now available</title>
<link>https://shadowtrackr.com/blog/single-sign_on-(sso)-now-available</link>
<guid>https://shadowtrackr.com/blog/single-sign_on-(sso)-now-available</guid>
<description>Short post today, but one with impact. ShadowTrackr now supports Single Sign-On from Microsoft Azure AD/Entra ID, Okta and any generic OIDC (like Keycloak). 

The option is available for enterprise accounts and up under Settings->Security.</description>
<pubDate>Mon, 10 Aug 2026 00:00:00 +0000</pubDate>
</item>
<item>
<title>Central tracking of resolved vulnerabilities</title>
<link>https://shadowtrackr.com/blog/central-tracking-of-resolved-vulnerabilities</link>
<guid>https://shadowtrackr.com/blog/central-tracking-of-resolved-vulnerabilities</guid>
<description>Vulnerabilities can go away for several reasons. The software can be patched, the CVE can be withdrawn, it might have been flagged as a false positive. So far, this information would be spread throughout ShadowTrackr indexes.

This week's update is a major overhaul of the cves_assets index. It now tracks what happened to all your vulnerabilities. There are three new fields available: resolved, resolved_at and resolved_reason. it might take a few days for all states to settle in their new values. 

You can easily get an overview of recent resolved cves with this query:

index=cves_assets resolved=true resolved_at>-7d


There is a report available for this in our Report Library
Along with this change we cleaned up the false positives registration. It now only contains the things you explicitly marked as false positives. The automaticly flagged false positives are gone from the GUI. For larger organizations this only generated a lot of noise and was not useful. </description>
<pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate>
</item>
<item>
<title>New vulnerabilities matching algorithm</title>
<link>https://shadowtrackr.com/blog/new-vulnerabilities-matching-algorithm</link>
<guid>https://shadowtrackr.com/blog/new-vulnerabilities-matching-algorithm</guid>
<description>The ShadowTrackr internal CVE database has been updated and augmented with new information. This allows us to better track and help you prioritise your risks from vulnerabilities. Check out our new Vulnerability management documentation to learn more.

A big part of the update is the ShadowTrackr CVSS Score. It is a CVSS v4 score, but unlike like the MITRE and NVD score we keep the threat group value (Exploit maturity) included in the final score.  If a PoC exists or active attacks are known, the score will be higher. If not, it will be lower. We track a lot of sources for exploit status to keep the score accurate.

If you want, you can query our internal cves index for specific fields in the CVSS v4 vectorstring, or you can check our logs of changes to a CVE (when was an exploit found, when did CISA include it in the KEV, etc.). These options are also avaible for your  cves_assets index.

The algorithm matching your software against vulnerabilities has also improved. It can find more complex matches and has less false positives. You might notice a different number of CVEs found in this weeks reports.</description>
<pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate>
</item>
<item>
<title>Branded PDF reports</title>
<link>https://shadowtrackr.com/blog/branded-pdf-reports</link>
<guid>https://shadowtrackr.com/blog/branded-pdf-reports</guid>
<description>The option to customize all pdf reports that ShadowTrackr sends is now available by default for all multi-tenant accounts. Look under Group settings in the left hand menu, and you'll find Branding

You can set your own logo instead of the ShadowTrackr logo, and even change the default ShadowTrackr color in the pdf to match your brand. This is especially useful for MSSPs.</description>
<pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
</item>
<item>
<title>Revamped alerts GUI</title>
<link>https://shadowtrackr.com/blog/revamped-alerts-gui</link>
<guid>https://shadowtrackr.com/blog/revamped-alerts-gui</guid>
<description>The alerts GUI has undergone a major UX upgrade. While working on a query for an alert, you can now see the live results. This will make it easier to fine tune it. 

The actions to take (send emails, call webhooks) have moved to a second tab to clear up the screen. You can still send alerts to any email account, even if they are not ShadowTrackr users.

There is also a third tab where you can select the fields you want to include in the results that are sent. The default fields are preselected. It was possible to do this before with advanced query syntax, but seeing which fields are available and ticking the boxes for the ones you want is just much easier.

The email format has changed a bit and should allow you to better interpret the alert context. 

Some of these improvements, like the email format and third tab to select output fields, have been added to the reports GUI as well.</description>
<pubDate>Mon, 29 Jun 2026 00:00:00 +0000</pubDate>
</item>
<item>
<title>Alerts for Multi-tenant accounts</title>
<link>https://shadowtrackr.com/blog/alerts-for-multi_tenant-accounts</link>
<guid>https://shadowtrackr.com/blog/alerts-for-multi_tenant-accounts</guid>
<description>This week's update is a major one. The pricing structure has changed so that resellers, MSSPs and others that need a multi-tenant account can now register for online credit card subscription. It's still possible to work with purchase orders, but for those that want simplicity and speed there now is a better option. 

Also, since we're fully European now prices are in Euros instead of in Dollars. The numbers are the same, which means a slight increase in price. This covers our increased costs. All existing accounts, including the current online credit card subscriptions, will stay on the old price levels for now.

Since multi-tenant use is increasing we also put more development in multi-tenant features. Alerts and the alert library are now available on the group level in multi-tenant accounts. This means you can set an alert for a specific event happening in any of the organizations in your group account.

Please note that there still is a lot in the development pipeline for alerts. Some of you handed in wishlists with useful request for alerts, and we intent to support all of them.

</description>
<pubDate>Mon, 15 Jun 2026 00:00:00 +0000</pubDate>
</item>
<item>
<title>New: Supplier Dependency Report</title>
<link>https://shadowtrackr.com/blog/new:-supplier-dependency-report</link>
<guid>https://shadowtrackr.com/blog/new:-supplier-dependency-report</guid>
<description>ShadowTrackr has been gathering supplier information for your assets for while now, and we've been expanding that. For each supplier, we now track where the corporate seat is and if it is Sovereign European (focused on having EU only dependencies), Fully European (no outside EU control), a European Subsidiary (non-European controlling party), or Non-European. 

Given the current drive in Europe to achieve more independence from Non-European countries, the new Supplier Dependency Report might be of help. It shows a worldmap with the countries where the suppliers of your assets, and allows you to drill down on details.

Here are some example queries to see results for your organization:

$supplier_dependency_report country="united states"

$supplier_dependency_report control="Non-European" 
    or "European subsidiary"




</description>
<pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate>
</item>
<item>
<title>Set Custom IDs for assets</title>
<link>https://shadowtrackr.com/blog/set-custom-ids-for-assets</link>
<guid>https://shadowtrackr.com/blog/set-custom-ids-for-assets</guid>
<description>If you have an internal asset management system or CMDB that has its own IDs, you can now add those as custom IDs to ShadowTrackr through the API. The IDs will come back with API results and can be used to select in queries. If set they are also shown in the GUI (but you cannot set them there at the moment).

A custom_id does not have to be unique. You can have a single ID for multiple ip addresses or urls.
</description>
<pubDate>Mon, 11 May 2026 00:00:00 +0000</pubDate>
</item>
<item>
<title>Automatic False Positive detection update</title>
<link>https://shadowtrackr.com/blog/automatic-false-positive-detection-update</link>
<guid>https://shadowtrackr.com/blog/automatic-false-positive-detection-update</guid>
<description>The TLS and SSL tests come up with quite a lot of results for some older vulnerabilities.  These might be a thing for legacy systems, but are almost always fixed in modern systems. That does not always show on the outside and clogs up the vulnerability overviews.

You can of course mark them as false positives, but since there can be quick a lot we changed the default. The following vulnerabilities are now by default marked as false positive:  CVE-2011-3389, CVE-2013-0169, CVE-2013-3587, CVE-2014-0224.</description>
<pubDate>Mon, 11 May 2026 00:00:00 +0000</pubDate>
</item>
<item>
<title>Big UI update for better UX</title>
<link>https://shadowtrackr.com/blog/big-ui-update-for-better-ux</link>
<guid>https://shadowtrackr.com/blog/big-ui-update-for-better-ux</guid>
<description>The Shadowtrackr User Interface has organically grown over the years. This is a nice way of saying that it got a bit inconsistent and at some places rather ugly even.

This weeks update brings consistency back and adds a better overall user experience.</description>
<pubDate>Mon, 04 May 2026 00:00:00 +0000</pubDate>
</item>
<item>
<title>Trouble: It's always DNS :-(</title>
<link>https://shadowtrackr.com/blog/trouble:-it's-always-dns-:_(</link>
<guid>https://shadowtrackr.com/blog/trouble:-it's-always-dns-:_(</guid>
<description>After moving the domain and DNS registry to a European provider, it turns out that new provider doesn't sail as smooth as the old one. 
Some of you might have problems with anycast and DNSSEC for our domain, and I'm not sure the new provider is handling this well.

We might have to move again, apologies for the trouble.
</description>
<pubDate>Tue, 28 Apr 2026 00:00:00 +0000</pubDate>
</item>
<item>
<title>Domain and DNS moved to EU</title>
<link>https://shadowtrackr.com/blog/domain-and-dns-moved-to-eu</link>
<guid>https://shadowtrackr.com/blog/domain-and-dns-moved-to-eu</guid>
<description>Another step in reducing dependencies on providers from outside the EU was completed today. All DNS and Domain records have moved from a US company to Openprovider in The Netherlands.</description>
<pubDate>Mon, 20 Apr 2026 00:00:00 +0000</pubDate>
</item>
<item>
<title>Data model updated, new detections</title>
<link>https://shadowtrackr.com/blog/data-model-updated,-new-detections</link>
<guid>https://shadowtrackr.com/blog/data-model-updated,-new-detections</guid>
<description>After updating the API documentation and magic queries, it was now time to update the data model. You'll find all indexes, fields, their datatypes and descriptions. For some indexes it's straight forward, but an index like DNS has many undescriptive fields (k, t, etc.) derived from the underlying DNS records that can be quite confusing without proper documentation. 

Besides this, a bunch of new and revised detections have gone to production, along with some bug fixes in the GUI.</description>
<pubDate>Mon, 13 Apr 2026 00:00:00 +0000</pubDate>
</item>
<item>
<title>Shadowserver integration updated</title>
<link>https://shadowtrackr.com/blog/shadowserver-integration-updated</link>
<guid>https://shadowtrackr.com/blog/shadowserver-integration-updated</guid>
<description>There is a lot of development going on, but not everything is directly visible. So we'll not bore you with details and stick to the useable stuff.

We recently added integration with Shadowserver.org. Up until now, their data was only used for discovery. For multi-tenant users, each organization had to enter the API keys separately resulting in extra work for users and more load on our servers.

This update allows multi-tenant users like MSSPs, Hosters and Network Operators to add the Shadowserver integration on group level. ShadowTrack will check daily, get all assets and events available in Shadowserver, and map these to the organizations you have in your group.

The new integration also uses the Shadowserver data much better. Besides discovery, you can import the device_id data (both IPv4 and IPv6) in to a special index in ShadowTrackr called shadowserver_device_id. The Shadowserver reports are now also parsed and processed as events. So, if one of your servers is connecting to a sinkhole or honeypot the alert for that will show up in your ShadowTrackr events.</description>
<pubDate>Tue, 07 Apr 2026 00:00:00 +0000</pubDate>
</item>
<item>
<title>Updated Magic queries documentation</title>
<link>https://shadowtrackr.com/blog/updated-magic-queries-documentation</link>
<guid>https://shadowtrackr.com/blog/updated-magic-queries-documentation</guid>
<description>As part of a continuing effort to update and improve documentation, the first information on magic queries is now available.

Sometimes you want data from ShadowTrackr that you know is in there, but cannot get out with the query language. A good example is if you want to combine data from two or more indexes. The query language does not support joins. This is where magic queries are used.

All magic queries start with a $. There are a number of existing ones, and they are now listed  in  the documentation. For quick access, just type $ in the search bar in the gui and auto-complete will show you what's available.

If you cannot find the magic query that you need, contact support and we'll try to make a new magic query for your specific needs. </description>
<pubDate>Mon, 30 Mar 2026 00:00:00 +0000</pubDate>
</item>
<item>
<title>Updated scheduling algorithms</title>
<link>https://shadowtrackr.com/blog/updated-scheduling-algorithms</link>
<guid>https://shadowtrackr.com/blog/updated-scheduling-algorithms</guid>
<description>Most scheduling algorithms have been reviewed and updated. The trigger for this was that sometimes an item could drop out or get stuck somewhere and was not properly scanned for a while. That is fixed now, and the resulting backlog of unscanned items was processed over the weekend. </description>
<pubDate>Sun, 29 Mar 2026 00:00:00 +0000</pubDate>
</item>
<item>
<title>API v4 is here, with more data and more options</title>
<link>https://shadowtrackr.com/blog/api-v4-is-here,-with-more-data-and-more-options</link>
<guid>https://shadowtrackr.com/blog/api-v4-is-here,-with-more-data-and-more-options</guid>
<description>ShadowTrackr has been gathering more information on your assets since API v3 was released. There are more indexes, reports and magic queries available too. Not all of those were available in the API yet. Also, version 3 had some inconsistenties that we'd love to get rid of.

Api v4 is now available. The ShadowTrackr python module on github is also updated.

The most significant changes:

The data returned is consistent and proper formatted everywhere
Error messages and result descriptions have improved
API is much better documented, with code examples
Code examples are with cURL, Python and PHP
All endpoints now have the same names in the python module
New endpoints available for suppliers, vulnerabilities and more

If you have specific requests for the API or questions on how to use it, please let us know :-)</description>
<pubDate>Mon, 16 Mar 2026 00:00:00 +0000</pubDate>
</item>
<item>
<title>Scannernodes upgraded</title>
<link>https://shadowtrackr.com/blog/scannernodes-upgraded</link>
<guid>https://shadowtrackr.com/blog/scannernodes-upgraded</guid>
<description>There has been a big upgrade on all scannernodes. Fresh installs with a new OS, better monitoring, and better security. All scannernodes have encryption enabled now. 
Besides software improvements, server capacity had been increased too.</description>
<pubDate>Mon, 09 Mar 2026 00:00:00 +0000</pubDate>
</item>
</channel>
</rss>
