Skip to content

Platform / Detect

Attack Surface Management

Daily rediscovery of every asset reachable from the public internet — including the subdomains, staging environments and forgotten cloud buckets nobody told IT about.

Daily

external rediscovery cycle

What you receive

  • Shadow IT and forgotten-subdomain discovery
  • Risk-ranked exposure feed with owner attribution
  • Change alerting when new surface appears
  • Certificate and DNS hygiene monitoring

When you need this

Three situations that call for it. If none of them is yours, it probably is not the right spend.

  • 01

    You have just acquired another company

    Due diligence rarely produces a complete list of the domains, netblocks and cloud accounts you have taken on. Discovery from the outside finds what the seller's own IT could not tell you, and it finds it before the two networks are joined.

  • 02

    Tests keep finding hosts nobody knew existed

    When findings arrive on assets that are not in your CMDB, the problem is inventory, not testing. Continuous rediscovery closes that gap, so a test is spent hardening what you own rather than establishing what you own.

  • 03

    Cloud accounts create surface faster than IT

    A staging environment, a test bucket or a load balancer left running after a demo are reachable from the public internet within minutes of creation. The gap between how fast surface appears and how slowly an annual review finds it is where intrusions start.

How it runs

  1. 01

    Scoping call

    Thirty minutes with an engineer. We establish what you already run, where the gaps actually are, and whether a module earns its place beside your existing tooling.

  2. 02

    Connect and baseline

    We connect the data sources the module reads and spend the first weeks learning what normal looks like in your estate. Tuning against your traffic is what stops the alerts being noise.

  3. 03

    Go live

    The module starts writing to the adversary graph and escalating to you. Escalation routes, thresholds and who gets woken at 03:00 are agreed in writing beforehand.

  4. 04

    Continuous review

    A standing review of what fired, what did not, and what changed in your estate. A detection set that is not revisited decays — the attacks move even when your systems do not.

No lock-in

Scoping costs nothing and carries no obligation. If the answer is that you do not need this, that is a legitimate outcome of the call.

Who turns up

The engineer on your scoping call is on the delivery team. We do not hand you to a different group after signature.

Scope

What this does not cover

  • Discovery stops at the perimeter — internal networks and authenticated scanning belong to Vulnerability Assessment.

  • We report exposure, not proof of exploitation; confirming that a finding is genuinely exploitable is Penetration Testing.

  • Domains impersonating you are somebody else's assets, not yours — those are found and removed under Brand Protection.

Measured against

ISO/IEC 27001:2022 Annex A 5.9
Requires an inventory of information and other associated assets, with owners identified — which presumes you can find them.
CIS Critical Security Controls v8, Control 1
Inventory and control of enterprise assets, on the premise that you cannot defend an asset you have never recorded.
PCI DSS 4.0.1 Req. 12.5.1
An inventory of system components in scope for PCI DSS, with a description of function and use, must be kept current.

If the scope is wrong

Tell us on the call. Re-scoping before we start costs nothing; discovering it at the readout costs you the engagement.

Questions

The ones we are actually asked.

How do you know an asset is actually ours?

Attribution runs from certificate transparency, DNS, registration and hosting records, and it is not infallible in either direction. Every asset arrives with the evidence for the link, so you can reject an assignment we got wrong.

Is this the same thing as vulnerability scanning?

No. Scanning tells you what is wrong with the assets already on your list; this tells you what belongs on the list, which is usually the harder question — an external footprint is assembled by many hands over many years, and the record of it rarely survives the people who made it.

Does continuous discovery just create more work?

It creates a queue, which is why exposures are ranked by reachability and routed to a named owner rather than dumped as a list. The honest answer is that the first cycle surfaces more than anyone expects, and that backlog is the point.

Next step

See what an attacker sees

We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.

30 min

A scoping call, with an engineer rather than a sales rep.

What it costs

Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.

Under attack now?

Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.