External attack surface monitoring
Your perimeter changes without anyone telling you. A developer publishes a test environment, a campaign spins up a subdomain, a certificate lapses. Attackers notice these things because they are watching for them.
Nobody has an accurate asset list
Every organisation we work with believes it knows what it has facing the internet, and almost none of them do. The gap is not incompetence. It is that publishing something is easy, decommissioning it is nobody's job, and the person who set it up has moved on.
What turns up is consistent: a staging site indexed by search engines, an old marketing microsite on an unpatched platform, a management interface exposed because a firewall rule was temporary in 2023, storage left readable, a subdomain still pointing at a cloud service that has been cancelled and can be claimed by somebody else.
What we track
- Domains and subdomains, including those discovered through certificate transparency logs rather than supplied by you. Certificates are published the moment they are issued, which means your own certificate log is frequently the best inventory of infrastructure you forgot about.
- Hosts, open ports and running services, with the software and version where it is visible, and the change flagged when a new one appears.
- Exposed interfaces: remote access, administrative panels, file transfer, database ports, and development tooling that was never meant to be reachable.
- Cloud storage and endpoints attached to your organisation, including those created outside the main cloud account.
- Certificates and DNS: expiry, weak configuration, and dangling records that point at services no longer under your control.
Monitoring, not a one-off scan
A point-in-time review tells you what was exposed on the day somebody looked. The value is in the delta: a new host, a newly opened port, a service that changed version, a subdomain that appeared last night. Most of those changes are legitimate and uninteresting. The ones that are not tend to be very interesting indeed, and they are invisible unless something is keeping a record.
Passive by default
Discovery works from public sources: DNS, certificate transparency, public scanning data and search engine indexes. Nothing is touched on your systems and no permission is needed to establish what is already public, which is exactly why an attacker can do the same thing without you ever seeing it. Where we move on to active checks against confirmed assets, that is scoped and authorised with you in writing first.
Start with a free review
We will map what your organisation currently exposes and send you the findings, with the issues that matter flagged, at no cost and with no obligation. It is the same discovery work described above, run once, and it is the most straightforward way to find out whether continuous monitoring is worth paying for. Ask us for a review and we will get it back to you within a few working days.
Common questions
How is this different from vulnerability scanning?
Scanning tests assets you already know about. Attack surface monitoring works out what the assets are, which is the step that keeps getting skipped. In practice the forgotten host is rarely in the scan scope, which is precisely why it is still running an unpatched version of something.
Do you touch our systems?
Discovery is passive and uses only public sources, so nothing is sent to your infrastructure. Any active checking is scoped and authorised in writing before it happens.
How do you find assets we have forgotten about?
Mostly through certificate transparency logs and public DNS data. Every publicly trusted certificate issued for your domains is logged publicly, so infrastructure that nobody documented still leaves a permanent, searchable record.
How often does it run?
Continuously for the lightweight checks, with a fuller sweep weekly and alerting on change in between. The cadence matters more than the depth, because the risk in a new exposure is proportional to how long it sits there unnoticed.
What do we do with what you find?
Most findings resolve to a decision rather than a fix: decommission it, restrict it, or accept it and monitor it. We give you the recommendation with each one, and where something needs proper testing rather than triage we will say so.
Related
Ready to talk?
Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.