Reg. No. 40203410806VAT LV40203410806

Theme

Book a consultationBook

1.05Security testing

Attack Surface Management

Continuous discovery, inventory and validation of domains, subdomains, services, cloud assets and other externally accessible systems.

New subdomains, development environments, cloud services and third-party systems can appear between periodic assessments. External attack-surface management maintains an up-to-date inventory and monitors material changes from an external perspective.

Automated discovery is combined with manual validation of relevant exposures. This reduces noise and helps distinguish an informational asset change from a weakness that can be exploited or combined with other findings.

The result is a prioritised view of external exposure, including newly discovered assets, ownership, exploitability and remediation status. It complements point-in-time penetration testing by monitoring changes between tests.

How it works

  1. 01

    Seed & discovery

    Establish known assets and continuously discover the unknown internet-facing estate.

  2. 02

    Scope & prioritise

    Map exposures to business-critical assets and rank by exploitability and impact.

  3. 03

    Validate

    Security-testing specialists validate which exposed weaknesses can be exploited, reducing false positives.

  4. 04

    Mobilise & monitor

    Assign remediation ownership, track closure and continuously alert on new exposures.

Packages

Essential
Baseline external attack-surface discovery and validated exposure report.
ComprehensivePopular
Continuous monitoring with validated prioritisation and change alerting.
Enterprise
Full CTEM program with ongoing validation and remediation governance.

Supported by our own threat-intelligence platform

ASM is only as good as the data behind it. We run yours on our own platform — so discovery, validation and monitoring are included, not subcontracted.

Experience this scenario interactively

A hands-on 3D simulation of this threat, followed by an explanation of how we test it in a real engagement.

Helpful tools

Credited findings

Public disclosures and field research where this work produced citable, verifiable results.

SeverityFindingAdvisoryYear
J@IL-GPT: an infostealer in a fake ChatGPT toolWindows workstations · malicious AI installer2026-09-06
UpdraftPlus: PHP backdoor delivery attempts via CVE-2026-10795WordPress · UpdraftPlus remote management and plugin installationCVE-2026-10795 (opens in a new tab)2026-09-06
The honeypot that gets robbed: a fifth of all honeypot traffic is toll fraud, not intrusionInternet-facing VoIP / SIP (Asterisk PBX)2026
A password is a fingerprint: what the internet's brute force is really typingInternet-facing services (Telnet, SSH, SMB, RDP, VNC, SIP, databases)2026
A connection is not an exploit: what 27 days of honeypot traffic actually containedInternet-facing services (RDP, SMB, SSH, web, VoIP)2026
threat-finder – open-source runtime CVE scannerOffSeq open-source tools2025

All services

Scope a test

Direct access to a senior specialist · Reply within 24 hours · NDA available on request