Skip to main content

Cybersecurity Services

External Attack Surface Management

Continuous discovery of everything you expose to the internet (including the domains, hosts and cloud resources that are not on anyone's asset list) with each one tested rather than merely catalogued.

An internet-facing estate (web applications, cloud services, remote access systems and IoT devices) above the five-step loop that works it: discover assets, add context, prioritise, test, mitigate.
30–40%
Of Discovered Assets Are Unknown To IT
Daily
Perimeter Re-Discovery And Change Detection
Tested
Every Asset Assessed, Not Just Inventoried
Perimeter Snapshot
Discovery Cadence
Continuous, Daily Sweep
Seed Input
One Domain Is Enough
Sources
DNS, CT Logs, ASN, Cloud Ranges
Shadow IT
Found And Attributed
Validation
Exposure Exploited Safely
01Problem
  • Discovery that starts from one domain and stops when the graph does

  • Ownership attributed before anything is actively tested

  • Every attributed asset assessed and validated, not just listed

You cannot defend the part of the perimeter nobody knows about

Attackers do not work from your CMDB. They start with your domain name and expand outward through DNS, certificate transparency, ASN data, cloud ranges and public sources.

AIPTx runs that same discovery process continuously, and then does the thing an inventory tool does not: it tests what it finds.

02Why Map It

The problem: the perimeter is never what you think it is

Every organisation's external footprint grows faster than its ability to record it, and the fastest-growing parts are the least governed.

Attackers' interest goes straight to the assets that look forgotten, because forgotten assets run unpatched software behind no monitoring.
  1. Inventories record only the governedAn asset inventory holds what went through the provisioning process, so anything stood up outside that process is absent from it by construction. The part of the perimeter nobody recorded is exactly the part nobody is defending.
  2. Shadow IT resolves the day it existsA team can register a subdomain and put a host behind it in an afternoon, and it is publicly resolvable from that moment. Nothing about it waits for the asset list to catch up.
  3. Forgotten staging hosts go unpatchedStaging, demo and migration hosts outlive the project that created them and drop out of every patch cycle, so they keep running the versions they shipped with. They stay reachable from the internet long after anyone is watching them.
  4. Dangling DNS records stay claimableWhen a cloud resource is deprovisioned and its CNAME is left pointing at the vacated name, whoever registers that name next inherits the record. Until the record is removed, the takeover is available to anyone who notices it first.
  5. Cloud perimeters outpace quarterly scansBuckets, load balancers, managed databases and orphaned resources appear and disappear across accounts and regions between scheduled sweeps. A quarterly scan describes a perimeter that has already changed by the time its results are read.
  6. Discovery without risk contextMost discovery tools return a longer list of hostnames and stop there, leaving the question of which assets are genuinely exposed unanswered. Without validation every entry looks equally urgent, so the list gets triaged by whoever has time rather than by risk.
03Key Benefits

Why attack surface management is a must for every business

Find What Is Not On The List

First-run discovery typically surfaces a third of the estate no existing inventory contained.

Alerted Within A Day

A newly opened port or newly resolvable host is flagged next day, not next quarter.

Exposure Proven, Not Observed

Perimeter findings that matter are exploited safely, so the urgent list is short and real.

Every Asset Has An Owner

Assets mapped to business units, subsidiaries and acquisitions, so alerts reach someone who can act.

Takeovers Caught Early

Dangling DNS records are found and confirmed claimable while you can still fix them for free.

Testing Follows Discovery

A new asset enters the assessment scope without anyone updating a target list.

04How It Works

How AIPTx maps and tests your perimeter

Discovery, attribution, assessment, validation and monitoring, the sequence that turns a hostname list into a ranked exposure picture.

The engagement
  1. 01

    Seed & Expand

    One domain expands through DNS, CT logs, ASN, WHOIS, passive DNS and archives until the graph stops.

  2. 02

    Attribute Ownership

    Candidates scored by registration, certificate identity, hosting and content; ambiguous ones queued.

  3. 03

    Fingerprint & Profile

    Ports, services, versions, TLS and certificate detail, plus what each asset appears to be for.

  4. 04

    Assess & Validate

    CVE correlation, misconfiguration and dangling-record checks, with safe exploitation where warranted.

  5. 05

    Monitor For Change

    Daily re-discovery, with alerts on new hosts, new ports, DNS and certificate changes.

Coverage
How AIPTx maps and tests your perimeter: coverage by asset type
Asset TypeWhat We Assess
Domains & SubdomainsCT Log Monitoring, Passive DNS, Lookalike Registrations
Hosts & ServicesOpen Ports, Service Fingerprinting, Version Accuracy
Cloud ResourcesPublic Buckets, Orphaned Resources, Multi-Account View
DNS RecordsDangling CNAMEs, Provider State, Claimability Proof
TLS & EmailExpiry, Cipher & Protocol Posture, SPF, DKIM, DMARC
Exposed InterfacesAdmin Consoles, Indexed Staging, Leaked Secrets & Backups
05What We Cover

What EASM covers

Discovery is the entry point. The value is in attribution, validation and the alerting that keeps the picture current.

Domain & Subdomain Enumeration

Passive and active enumeration across DNS, CT logs and archives, including lookalike registrations.

Host, Port & Service Discovery

ASN and cloud ranges swept for open ports, with fingerprinting precise enough for CVE correlation.

Cloud Asset Discovery

Buckets, load balancers, managed databases, registries and orphaned resources across AWS, Azure and GCP.

Subdomain Takeover Detection

Records pointing at deprovisioned resources identified and confirmed claimable before anyone else does.

TLS, Certificate & DNS Posture

Expiry and misissuance, weak ciphers, deprecated protocols, CAA, SPF, DKIM, DMARC and zone exposure.

Exposed Interfaces & Data

Admin consoles, database ports, VPN portals, indexed staging, directory listings and leaked keys.

06Proven Impact

What continuous discovery changes

The point of EASM is not a bigger inventory. It is a shorter distance between something becoming exposed and someone knowing about it.

30–40%
Assets found that were not on the list
< 24 hrs
From new exposure to routed alert
Validated
Exposure proven, not just observed
Attributed
Every asset mapped to an owner
Pre-emptive
Takeovers caught before they happen
One scope
Testing follows discovery automatically
07Where It Fits

Where EASM is the right starting point

Across industries. Across environments. For every modern business.

Large Enterprise

One current perimeter picture across business units, with unclaimed assets triaged for decommissioning.

Post-Acquisition

Quantify an inherited internet footprint within days of the deal closing.

Cloud-Native Engineering

Reconcile external reachability against account inventory daily, across every account and region.

Brand Protection

Surface vendor-hosted properties and lookalikes carrying your name but not your controls.

Financial Services

Keep a regulated perimeter evidenced and current rather than described once a quarter.

Government & Public Sector

Maintain an authoritative record of citizen-facing exposure across departments and agencies.

FAQ

External attack surface management questions

What do you need to start discovery?

One domain name is enough. From there, expansion runs through DNS, certificate transparency, ASN and WHOIS data, passive DNS, cloud provider ranges and public sources until the asset graph stops growing. Known IP ranges, subsidiary names and cloud account identifiers make attribution faster, but none are required to begin.

How do you avoid claiming assets that are not ours?

Attribution is scored rather than assumed, using registration data, certificate identity, hosting relationships and content fingerprints. High-confidence matches are added automatically; ambiguous ones are queued for your confirmation. Nothing is actively tested until ownership is established.

Is this just discovery, or does it test what it finds?

Both, and the testing is the point. Every asset AIPTx attributes to you is fingerprinted, assessed for CVEs and misconfiguration, and (where it warrants it and can be done safely) exploited to establish whether the exposure is real. Findings arrive ranked by proven risk.

Will scanning our perimeter cause disruption?

Discovery is overwhelmingly passive: DNS, certificate logs and public data sources generate no traffic to your systems at all. Active checks are rate limited to a level you configure, destructive actions are disabled, and specific hosts can be excluded from active testing while staying in the inventory.

How are alerts kept useful rather than noisy?

Alerts fire on changes in state (a new asset, a newly opened service, a certificate or DNS change, or newly validated exposure) rather than on the existence of known findings. Thresholds are configurable per business unit and severity, and alerts route to the owning team.

How often does discovery re-run?

Continuously. Passive sources (DNS, certificate transparency, ASN and WHOIS data) are polled on a schedule measured in hours, since that is how quickly a new certificate or a new subdomain becomes public. Active fingerprinting of attributed assets runs on its own cadence, and anything that changes state moves to the front of the queue rather than waiting for the next full pass.

Not covered here? Scoping questions get a same-day answer from the team that runs the assessments. Talk to an expert

See your perimeter the way an attacker enumerates it

Give AIPTx one domain and it will map everything reachable that belongs to you (including the assets nobody remembers), then test each one and tell you which are genuinely dangerous.