DiscoveryExternal Asset Discovery
Continuously discover internet-facing domains, subdomains, IPs, services and web applications attackers can see.
Evidence traceApproved scopeTarget-aware testing
Capability architecture
Discover the surface with evidence of why it belongs to you.
ThreatCanary correlates external signals and organisational context instead of silently turning every association into an owned asset.
01Why it matters
- Unknown assets often sit outside CMDBs, ownership models and normal security testing.
- External exposure changes constantly as cloud, SaaS, DNS and development teams move quickly.
- Discovery is the foundation for every later validation workflow.
02ThreatCanary approach
- Enumerate subdomains, resolve assets, identify services and model DNS and network relationships.
- Apply scope rules before testing and preserve raw discovery evidence for audit.
- Link discovered assets to technologies, APIs, owners, findings and attack-path relationships.
03What it validates or reveals
- New or changed external assets.
- Forgotten, unmanaged or unauthorised internet-facing systems.
- Assets that deserve deeper fingerprinting, API discovery or validation.
04Evidence produced
- Asset observation and attribution sources.
- Confidence, first-seen and change history.
- Owner disposition and unresolved attribution queue.