Security Posture Analysis Tool — by Antibody Cyber Technology, LLC
SPAT is an automated external security assessment tool that evaluates the public-facing security posture of a domain. Developed by Antibody Cyber Technology, LLC, a specialized cybersecurity company based out of Huntsville, Alabama, the scanner probes from an outside network perspective to identify common web, DNS, TLS, and exposed-service weaknesses before they become easier to exploit.
The online scanner operates against the domain name itself — not a specific URL path. SPAT queries public DNS, makes direct TLS/socket connections, issues HTTP requests, checks selected high-risk ports, and optionally checks domain reputation through VirusTotal when threat-intelligence access is configured. Scans use the bare hostname, such as example.com.
Each scan starts at 100 points. Points are deducted by severity: CRITICAL: 25pts, HIGH: 12pts, MEDIUM: 6pts, LOW: 2pts, and INFO: 0pts. Grades range from A (90+) to F (<50), with D and E used for the middle bands. Any unresolved CRITICAL finding caps the score at 59, and inconclusive or scanner-error results are reported separately without reducing the score.
SPAT CLI is an optional command-line tool we run on our cloud-based servers that extends standard website-scanning capabilities. It performs 17 total checks (15 external + 2 SSH), adding TLS Cipher Suite analysis, CSP quality inspection, Cookie security, CORS policy, Email security (DKIM/DMARC/SPF), DNSSEC validation, URLhaus malware check, and SSH server hardening. Reports can be generated as HTML. The scan report is available for a one-time payment of $4.99, with no subscription or account required. View a sample CLI report.