Threat Surface
Discovers external domains and subdomains and scans for DNS, email, TLS, web, exposed services, and CVE-related misconfigurations with 50+ automated checks
The product is a cloud-based external attack surface management platform that discovers domains and subdomains and runs 50+ automated checks for DNS, email authentication, TLS, web application, exposed services, and CVE-aware misconfigurations to reduce breach risk from forgotten assets. It sells to IT generalists, developers, SMB owners, MSPs, and lean security teams in small to mid-size businesses that lack a dedicated security department. It is positioned as an affordable alternative to six-figure ASM contracts, delivered as a hosted service with transparent scan-token pricing and no hardware or scanner fleet to maintain.
Key features
- Attack surface discovery via CT and DNS
- DNSSEC and zone transfer checks
- SPF DKIM DMARC validation
- MTA-STS and TLS-RPT checks
- TLS protocol and cipher analysis
- Certificate transparency monitoring
- Security headers and CSP analysis
- Open redirect and mixed content checks
- CMS and framework fingerprinting
- CVE matching with CVSS scoring
- TCP port and service detection
- Sensitive path exposure probing
- Cloud storage exposure signals
- DNS blocklist reputation checks
- OAuth OIDC discovery exposure check
- PDF executive reports with risk scores
- No social media activity detected
- No GTM activity detected
- IT teams
- Security teams
- SMB owners