External Attack Surface Management

Every asset an attacker can see — and every way in.

Give us a domain. We map your entire internet-facing footprint — subdomains, live web apps, IP addresses, TLS certificates and exposed cloud assets — then test every one of them for vulnerabilities, and keep watching for change.

Authorized use only · operator-approved · every scan logged for traceability

discovery · example.com live
$ mapping attack surface for example.com
subdomains discovered128
resolved & live94
web applications51
IP addresses37
TLS certificates46
cloud assets exposed3
$ testing 51 live assets
vulnerabilities found27
critical / high6
6
asset types mapped
11
vulnerability categories tested
One scan
discovery + assessment together
Continuous
re-scan & change tracking

What we do

Most breaches start with an asset nobody remembered owning — a forgotten subdomain, an expired cert, a public bucket, an API key left in a JavaScript bundle. We find those before someone else does, then test each one the way an attacker would — from the outside in, using only the domain you give us.

Discover

Enumerate the full subdomain and asset footprint from 40+ passive sources, certificate transparency and active resolution.

Test

Every live asset is checked for known CVEs, exposed services, leaked credentials, takeover risk and spoofable email — in the same scan, automatically.

Prioritise

Findings are ranked by real-world risk, not raw severity — so you know what to fix first, and every one arrives with the fix attached.

Monitor

Re-scan on a schedule and get told what's new, what changed and what disappeared — before it becomes an incident.

Everything we find

One domain in — a complete, categorized asset inventory out. Each category is its own tab in your dashboard.

Subdomains

Every name under your domain, resolved and de-duplicated — we surface only the live ones.

Web Applications

Live HTTP services with status, title, server and detected technologies — your real app inventory.

IP Addresses

The addresses your assets resolve to, with hosting and network context.

TLS Certificates

Issuers, validity windows and SANs — catch expiring, self-signed or rogue certificates early.

Cloud Assets

Buckets and storage endpoints referenced by your apps — flagged when publicly exposed.

Vulnerabilities

In every scan

Prioritized findings per asset — CVEs, exposed services, leaked keys, takeovers, spoofable email and lookalike domains, each with the fix.

Every scan tests for
Web application flaws Exposed ports & services Cloud storage exposure Email spoofing DNS security Sensitive file exposure Leaked credentials Subdomain takeover Lookalike domains Reputation & blocklists Post-quantum readiness

Simple, usage-matched pricing

Start free with basic visibility. Pay once for full visibility, or go continuous for scheduled, always-fresh scanning.

Free

$0

Subdomain & web-app visibility, on demand.

  • 1 domain
  • Subdomains & live web apps
  • Manual, one-off scans
  • See how many findings you have, and where
  • Read the findings & remediation
  • Scheduled scanning
Start free
Most popular

Pro

$9 one-time

One-time — read every finding, forever

  • Monitor up to 4 domains
  • Read all 11 vulnerability categories in full
  • Severity, affected asset, evidence and the fix for every finding
  • Complete asset inventory across every category
  • Applies instantly to all current and future scans
  • One-time payment, no recurring charge
Get Pro

Continuous

$29/30d

Renew every 30 days — everything in Pro, plus scheduled scanning

  • Everything in Pro
  • Monitor up to 25 domains
  • Scheduled / daily automatic scans
  • Always-fresh attack surface data
  • 30-day access — renew anytime before it lapses
Go continuous

How it works

Three steps from a single domain to a full picture of your exposure.

01

Submit your domain

Confirm you're authorized to assess it. Passive discovery never touches your target; active probing waits for the next step.

02

We map it, then test it

Once approved, ephemeral workers spin up, discover every asset, assess each one for vulnerabilities, and tear themselves down. Time-boxed, rate-limited and cost-capped.

03

Fix what matters

Your dashboard opens on the highest-risk findings, with the affected asset, the evidence and the remediation. Assets and findings are browsable by category, live as the scan runs.

Built responsibly

Authorized, controlled, accountable

Active scanning sends real traffic to real targets. We treat that seriously: nothing runs without authorization and operator approval, and every action is attributed and logged.

Create your account

Ready to see your attack surface?

Create an account, submit a domain you own, and get a full inventory of what the internet can see.