External Attack Surface Assessment
Continuous-view discovery of your internet-facing exposure — known and unknown.
What it is
Organisations accumulate forgotten subdomains, exposed services, shadow IT and leaked credentials. An external attack-surface assessment discovers your internet-facing footprint from an attacker’s perspective — without credentials or internal access — and identifies what is exposed, outdated or misconfigured.
Coverage
- Domain, subdomain and certificate footprint
- Exposed services, ports and applications
- Cloud storage and code exposure
- Technology fingerprinting and outdated components
- Email security posture (SPF, DMARC alignment signals)
- Credential exposure signals
How we deliver
- Scope — seed domains and rules of engagement agreed in writing.
- Discovery — passive and active footprinting.
- Analysis — classify exposure by exploitability and sensitivity.
- Validation — confirm high-risk exposures.
- Reporting — prioritised exposure register with remediation.
Outcomes
- Complete external footprint inventory
- Unknown and forgotten assets surfaced
- Quick-win exposure closures
- Basis for continuous attack-surface monitoring