New: Active Pentest Package — Try it free
BreakMesh shield BreakMesh – Vulnerability Simulator & Cyber Range

Compliance evidence mapping

PCI-DSS v4.0 evidence mapping

BreakMesh maps each safe scan finding to the PCI-DSS v4.0 requirement it supports, helping teams that handle cardholder data gather clear evidence for their assessors without disruptive testing.

102 checks mapped 9 PCI-DSS requirements Non-destructive scans

BreakMesh helps you gather audit evidence and reduce risk. It maps findings to control evidence to support your assessment — it does not by itself make your organization compliant or certified.

How the mapping works

Every safe check BreakMesh runs on a verified target is linked to the PCI-DSS v4.0 PCI-DSS requirements it produces evidence for. When a scan completes you get a report that groups findings and passed checks by PCI-DSS requirements, with severity, evidence, and remediation guidance you can hand straight to an assessor or auditor.

PCI-DSS v4.0 coverage

1.2.1

  • DNS Basics
  • DNSSEC Review
  • WHOIS and Domain Expiry
  • Mail/DNS Hardening (MTA-STS / TLS-RPT / CAA)
  • Origin Exposure Check
  • Open Risky Ports
  • Subdomain Discovery (Certificate Transparency)
  • Subdomain Takeover Risk

1.3.1

  • AWS CloudTrail Logging Disabled
  • AWS Default Encryption Gaps
  • AWS IAM Stale Access Keys
  • AWS Open Security Group Ingress
  • AWS Overly-Permissive IAM Policies
  • AWS Public S3 Storage Exposure
  • Azure Open NSG Ingress Rules
  • Azure Public Blob Storage Exposure
  • GCP Open VPC Firewall Ingress
  • GCP Public Cloud Storage Exposure

11.3.1

  • Business Logic — Price Manipulation
  • Web Cache Poisoning Readiness
  • Command Injection (Timing)
  • File Upload Bypass
  • Header Injection
  • Insecure Deserialization (Timing)
  • Open Redirect
  • Open Redirect (Active)
  • HTTP Parameter Pollution (HPP)
  • Path Traversal
  • Harmless Reflected XSS Indicators
  • HTTP Request Smuggling / Desync Readiness
  • Safe SQL Injection Indicators
  • SQL Injection (Boolean-Blind)
  • SQL Injection (Error-Based)
  • SSRF (Callback)
  • SSTI Template Injection Indicator
  • XSS — Reflected
  • XSS — Stored
  • XXE Injection

4.2.1

  • HSTS Strength
  • HTTP/2 and HTTP/3 Support
  • HTTPS Redirect
  • Mixed Content Detection
  • TLS Certificate
  • TLS Chain and Expiry Depth
  • TLS Protocol and Cipher Review

6.2.4

  • API Documentation Exposure
  • API Third-Party Dependency Inventory
  • Business Logic — Price Manipulation
  • Web Cache Poisoning Readiness
  • Command Injection (Timing)
  • Cookie Security
  • CORS Edge Cases (null origin / preflight)
  • CORS Policy
  • CSP Quality Review
  • Deprecated Browser APIs
  • Directory Listing
  • Sitemap and Robots Exposure
  • Error Disclosure
  • Excessive API CORS Checks
  • Error Disclosure Expansion
  • File Upload Bypass
  • GraphQL DoS Readiness (Batching / Alias / Depth)
  • GraphQL Introspection Exposure
  • Header Injection
  • HTTP Method Exposure
  • Insecure Deserialization (Timing)
  • JWT Weakness Detection
  • Open Redirect
  • Open Redirect (Active)
  • HTTP Parameter Pollution (HPP)
  • Path Traversal
  • Harmless Reflected XSS Indicators
  • HTTP Request Smuggling / Desync Readiness
  • Secrets in JavaScript Bundles
  • Security Headers
  • Sensitive Files
  • Sensitive Response Pattern Detection
  • Server Header Disclosure
  • Session Cookie Scope
  • Shadow API Discovery
  • Source Map Exposure
  • Safe SQL Injection Indicators
  • SQL Injection (Boolean-Blind)
  • SQL Injection (Error-Based)
  • Subresource Integrity (SRI) Missing
  • SSRF (Callback)
  • SSTI Template Injection Indicator
  • Trusted Types Signal
  • Versioned Endpoint Discovery
  • WebSocket Security Check
  • XSS — Reflected
  • XSS — Stored
  • XXE Injection

6.3.1

  • Dependency CVE Matching (SBOM)
  • Drive-by Download / Malicious Redirect Chain
  • Mobile App Static Analysis (APK/IPA)
  • Service/Version CVE Hints (Advisory)

6.4.1

  • API Rate-Limit Readiness
  • Availability Status Evidence
  • Bot Protection Detection
  • DDoS Readiness Evidence
  • Rate-Limit Readiness
  • WAF/CDN Detection
  • WAF Harmless Canary Probe

7.2.1

  • Account Enumeration Indicators
  • Auth Bypass Probes
  • AWS CloudTrail Logging Disabled
  • AWS Default Encryption Gaps
  • AWS IAM Stale Access Keys
  • AWS Open Security Group Ingress
  • AWS Overly-Permissive IAM Policies
  • AWS Public S3 Storage Exposure
  • Azure Open NSG Ingress Rules
  • Azure Public Blob Storage Exposure
  • Broken Function Auth (Active)
  • BFLA Privilege Escalation Probe
  • BOLA / IDOR Two-Account Comparison
  • Credentialed Test-Account Checks
  • CSRF Protection Enforcement
  • Endpoint Auth Indicators
  • GCP Open VPC Firewall Ingress
  • GCP Public Cloud Storage Exposure
  • IDOR (Two-Account)
  • Login Rate-Limit Simulation
  • Login Surface Controls
  • API Mass Assignment
  • MFA Configuration Indicators
  • OAuth 2.0 / OIDC Security Checks
  • Password Reset Flow Checks
  • Password Spray Indicator
  • Session Fixation Check
  • Weak Password Policy Review

8.3.1

  • Account Enumeration Indicators
  • Auth Bypass Probes
  • Broken Function Auth (Active)
  • BFLA Privilege Escalation Probe
  • BOLA / IDOR Two-Account Comparison
  • Credentialed Test-Account Checks
  • CSRF Protection Enforcement
  • Endpoint Auth Indicators
  • IDOR (Two-Account)
  • Login Rate-Limit Simulation
  • Login Surface Controls
  • API Mass Assignment
  • MFA Configuration Indicators
  • OAuth 2.0 / OIDC Security Checks
  • Password Reset Flow Checks
  • Password Spray Indicator
  • Session Fixation Check
  • Weak Password Policy Review