Box
Scans Box enterprise file and folder sharing and collaborations to find public links and over-broad external access.
AttivoTutte le sorgenti che 8200.dev è in grado di analizzare oggi — connettori in sola lettura che mappano chi e cosa può accedere ai suoi dati. Nessuna installazione richiesta, revocabili in qualsiasi momento.
23 connettori, un unico modello di permessi normalizzato.
Scans Box enterprise file and folder sharing and collaborations to find public links and over-broad external access.
AttivoScans Dropbox Business team folders, shared links, and membership to surface external sharing and public-link exposure.
AttivoScans Google Drive files and folders, their sharing settings, and the user directory to map who can access what across your Workspace.
AttivoScans SharePoint / OneDrive sharing, inventories Entra (Azure AD) app registrations, service principals and their consented scopes, and audits the tenant security posture (Security Defaults, Conditional Access, MFA coverage, app consent, admin roles).
AttivoScans workspace page and database sharing, member access, and connected integrations to surface over-broad or public exposure.
AttivoScans channel and file sharing exposure, inventories installed apps, bots, and integrations and their OAuth token scopes (the AI-agent / shadow-AI surface), and audits the workspace security configuration (2FA enforcement, app-install policy, public file sharing, external Slack Connect channels).
AttivoScans AWS IAM users, roles, groups, and policies to map effective permissions and find over-privileged or stale principals.
AttivoAudits your Azure AD (Microsoft Entra ID) directory — MFA coverage and Conditional Access, legacy-auth blocking, privileged-role sprawl (Global Admins, admins without MFA, PIM), over-privileged app identities, guests and external collaboration, Identity Protection risk (at-risk / compromised users), group hygiene, and audit-log retention. Identity-infrastructure posture, read-only — distinct from the Microsoft 365 file/content scan.
AttivoAudits your Google Cloud (GCP) project security posture — project IAM (service-account keys, primitive-role sprawl, inactive and external principals, public bindings), enabled APIs and API-key restrictions, Cloud Audit Log coverage and retention, VPC firewall exposure (SSH/RDP open to the internet), and public Cloud Storage buckets. Read-only.
AttivoScans Okta users, application assignments, and group memberships to map who can sign in to which application.
AttivoScans your Intercom support workspace — the Fin AI Agent and custom bots (their knowledge sources, sensitive-topic answering, external data sources, and human-handover policy), teammates (admins) and 2FA, installed integrations, and Messenger security (identity verification).
AttivoScans your Telegram bots — the identity and capabilities of each bot (including whether it can read all group messages) and its webhook posture: HTTP vs HTTPS, self-signed certificates, data flowing to external AI providers, and unmonitored update backlogs.
AttivoAudits your WhatsApp Business Accounts — 2-Step Verification, phone-number verification and quality, system-user permissions (MANAGE), and connected-app scopes. Read-only; never message contents.
AttivoScans your Zendesk support account — Zendesk AI bots and agent Copilot (sensitive-field and PII access, escalation policy), agents and admins, custom roles with elevated access, installed marketplace apps, and account security (SSO, 2FA enforcement, public ticket sharing, API-token age).
AttivoScans your Anthropic organization: API keys, member roles, workspaces, and the daily usage report — flags inactive-but-unrevoked keys, default-workspace (org-wide) keys, orphaned keys, never-expiring keys, admin sprawl, and usage spikes vs your own 30-day baseline.
AttivoConnects your ChatGPT Enterprise workspace’s Compliance Logs Platform (a separate product from the OpenAI API): exported log windows for conversations metadata, file uploads, admin actions, and auth events become governance evidence — and an empty stream is flagged before the 30-day retention erases it.
AttivoScans your Cursor team via the server-side Admin API: members/roles, per-seat daily activity, and spend — flags owner sprawl, paid seats with zero activity, and uncapped usage-based spend. Client-side telemetry is never used.
AttivoWorks for a personal account or an organization — detected automatically. Scans repository visibility, collaborator access, deploy keys, and installed GitHub Apps and their scopes.
AttivoAudits your Jira Cloud site — public projects and "Anyone on the web" filters/dashboards, admin sprawl and dormant users, permission schemes that grant sensitive actions to everyone, missing issue-security on security-labeled projects, insecure webhooks, unrecognized write-scoped apps, and automation rules that post data externally. Read-only.
AttivoAudits your Linear workspace — admin sprawl, stale and guest access, SAML SSO, authorized OAuth apps and their scopes, webhooks, and public teams that expose security-labeled issues. Read-only.
AttivoScans your Mistral AI organization: API keys (with Mistral’s native last-used signal), member roles, and audit events — flags stale, org-wide, orphaned, and never-expiring keys plus admin-role sprawl.
AttivoScans your OpenAI organization: admin + project API keys (with OpenAI’s native last-used signal), member roles, projects, and audit events — flags stale, org-wide, and orphaned keys, owner sprawl, and audit logging left disabled.
AttivoConnetta la sua prima sorgente in pochi minuti — gratuito, sola lettura, senza chiamata commerciale.