Cybersecurity Services
External Attack Surface Management
Continuous discovery of everything you expose to the internet (including the domains, hosts and cloud resources that are not on anyone's asset list) with each one tested rather than merely catalogued.

- 30–40%
- Of Discovered Assets Are Unknown To IT
- Daily
- Perimeter Re-Discovery And Change Detection
- Tested
- Every Asset Assessed, Not Just Inventoried
- Discovery Cadence
- Continuous, Daily Sweep
- Seed Input
- One Domain Is Enough
- Sources
- DNS, CT Logs, ASN, Cloud Ranges
- Shadow IT
- Found And Attributed
- Validation
- Exposure Exploited Safely
Problem
- The Issue
- Impact
Discovery that starts from one domain and stops when the graph does
Ownership attributed before anything is actively tested
Every attributed asset assessed and validated, not just listed
You cannot defend the part of the perimeter nobody knows about
Attackers do not work from your CMDB. They start with your domain name and expand outward through DNS, certificate transparency, ASN data, cloud ranges and public sources.
AIPTx runs that same discovery process continuously, and then does the thing an inventory tool does not: it tests what it finds.
Why Map It
- Key Benefits
The problem: the perimeter is never what you think it is
Every organisation's external footprint grows faster than its ability to record it, and the fastest-growing parts are the least governed.
Attackers' interest goes straight to the assets that look forgotten, because forgotten assets run unpatched software behind no monitoring.
- Inventories record only the governedAn asset inventory holds what went through the provisioning process, so anything stood up outside that process is absent from it by construction. The part of the perimeter nobody recorded is exactly the part nobody is defending.
- Shadow IT resolves the day it existsA team can register a subdomain and put a host behind it in an afternoon, and it is publicly resolvable from that moment. Nothing about it waits for the asset list to catch up.
- Forgotten staging hosts go unpatchedStaging, demo and migration hosts outlive the project that created them and drop out of every patch cycle, so they keep running the versions they shipped with. They stay reachable from the internet long after anyone is watching them.
- Dangling DNS records stay claimableWhen a cloud resource is deprovisioned and its CNAME is left pointing at the vacated name, whoever registers that name next inherits the record. Until the record is removed, the takeover is available to anyone who notices it first.
- Cloud perimeters outpace quarterly scansBuckets, load balancers, managed databases and orphaned resources appear and disappear across accounts and regions between scheduled sweeps. A quarterly scan describes a perimeter that has already changed by the time its results are read.
- Discovery without risk contextMost discovery tools return a longer list of hostnames and stop there, leaving the question of which assets are genuinely exposed unanswered. Without validation every entry looks equally urgent, so the list gets triaged by whoever has time rather than by risk.
Key Benefits
Why attack surface management is a must for every business
Find What Is Not On The List
First-run discovery typically surfaces a third of the estate no existing inventory contained.
Alerted Within A Day
A newly opened port or newly resolvable host is flagged next day, not next quarter.
Exposure Proven, Not Observed
Perimeter findings that matter are exploited safely, so the urgent list is short and real.
Every Asset Has An Owner
Assets mapped to business units, subsidiaries and acquisitions, so alerts reach someone who can act.
Takeovers Caught Early
Dangling DNS records are found and confirmed claimable while you can still fix them for free.
Testing Follows Discovery
A new asset enters the assessment scope without anyone updating a target list.
How It Works
- Approach
- Workflow
How AIPTx maps and tests your perimeter
Discovery, attribution, assessment, validation and monitoring, the sequence that turns a hostname list into a ranked exposure picture.
- 01
Seed & Expand
One domain expands through DNS, CT logs, ASN, WHOIS, passive DNS and archives until the graph stops.
- 02
Attribute Ownership
Candidates scored by registration, certificate identity, hosting and content; ambiguous ones queued.
- 03
Fingerprint & Profile
Ports, services, versions, TLS and certificate detail, plus what each asset appears to be for.
- 04
Assess & Validate
CVE correlation, misconfiguration and dangling-record checks, with safe exploitation where warranted.
- 05
Monitor For Change
Daily re-discovery, with alerts on new hosts, new ports, DNS and certificate changes.
| Asset Type | What We Assess |
|---|---|
| Domains & Subdomains | CT Log Monitoring, Passive DNS, Lookalike Registrations |
| Hosts & Services | Open Ports, Service Fingerprinting, Version Accuracy |
| Cloud Resources | Public Buckets, Orphaned Resources, Multi-Account View |
| DNS Records | Dangling CNAMEs, Provider State, Claimability Proof |
| TLS & Email | Expiry, Cipher & Protocol Posture, SPF, DKIM, DMARC |
| Exposed Interfaces | Admin Consoles, Indexed Staging, Leaked Secrets & Backups |
What We Cover
- Scope
What EASM covers
Discovery is the entry point. The value is in attribution, validation and the alerting that keeps the picture current.
Domain & Subdomain Enumeration
Passive and active enumeration across DNS, CT logs and archives, including lookalike registrations.
Host, Port & Service Discovery
ASN and cloud ranges swept for open ports, with fingerprinting precise enough for CVE correlation.
Cloud Asset Discovery
Buckets, load balancers, managed databases, registries and orphaned resources across AWS, Azure and GCP.
Subdomain Takeover Detection
Records pointing at deprovisioned resources identified and confirmed claimable before anyone else does.
TLS, Certificate & DNS Posture
Expiry and misissuance, weak ciphers, deprecated protocols, CAA, SPF, DKIM, DMARC and zone exposure.
Exposed Interfaces & Data
Admin consoles, database ports, VPN portals, indexed staging, directory listings and leaked keys.
Proven Impact
- Outcomes
What continuous discovery changes
The point of EASM is not a bigger inventory. It is a shorter distance between something becoming exposed and someone knowing about it.
- 30–40%
- Assets found that were not on the list
- < 24 hrs
- From new exposure to routed alert
- Validated
- Exposure proven, not just observed
- Attributed
- Every asset mapped to an owner
- Pre-emptive
- Takeovers caught before they happen
- One scope
- Testing follows discovery automatically
Where It Fits
- Use Cases
Where EASM is the right starting point
Across industries. Across environments. For every modern business.
Large Enterprise
One current perimeter picture across business units, with unclaimed assets triaged for decommissioning.
Post-Acquisition
Quantify an inherited internet footprint within days of the deal closing.
Cloud-Native Engineering
Reconcile external reachability against account inventory daily, across every account and region.
Brand Protection
Surface vendor-hosted properties and lookalikes carrying your name but not your controls.
Financial Services
Keep a regulated perimeter evidenced and current rather than described once a quarter.
Government & Public Sector
Maintain an authoritative record of citizen-facing exposure across departments and agencies.
FAQ
External attack surface management questions
What do you need to start discovery?
One domain name is enough. From there, expansion runs through DNS, certificate transparency, ASN and WHOIS data, passive DNS, cloud provider ranges and public sources until the asset graph stops growing. Known IP ranges, subsidiary names and cloud account identifiers make attribution faster, but none are required to begin.
How do you avoid claiming assets that are not ours?
Attribution is scored rather than assumed, using registration data, certificate identity, hosting relationships and content fingerprints. High-confidence matches are added automatically; ambiguous ones are queued for your confirmation. Nothing is actively tested until ownership is established.
Is this just discovery, or does it test what it finds?
Both, and the testing is the point. Every asset AIPTx attributes to you is fingerprinted, assessed for CVEs and misconfiguration, and (where it warrants it and can be done safely) exploited to establish whether the exposure is real. Findings arrive ranked by proven risk.
Will scanning our perimeter cause disruption?
Discovery is overwhelmingly passive: DNS, certificate logs and public data sources generate no traffic to your systems at all. Active checks are rate limited to a level you configure, destructive actions are disabled, and specific hosts can be excluded from active testing while staying in the inventory.
How are alerts kept useful rather than noisy?
Alerts fire on changes in state (a new asset, a newly opened service, a certificate or DNS change, or newly validated exposure) rather than on the existence of known findings. Thresholds are configurable per business unit and severity, and alerts route to the owning team.
How often does discovery re-run?
Continuously. Passive sources (DNS, certificate transparency, ASN and WHOIS data) are polled on a schedule measured in hours, since that is how quickly a new certificate or a new subdomain becomes public. Active fingerprinting of attributed assets runs on its own cadence, and anything that changes state moves to the front of the queue rather than waiting for the next full pass.
See your perimeter the way an attacker enumerates it
Give AIPTx one domain and it will map everything reachable that belongs to you (including the assets nobody remembers), then test each one and tell you which are genuinely dangerous.
Explore other services
Exposure Management
Run one prioritised queue across every risk source.
Vulnerability Assessment
Find, rank and fix weaknesses across the whole estate.
AI Penetration Testing
Simulate real-world attacks to test your defences.
Vulnerability Discovery
What gets tested once an asset is found, and how findings are classified.