What this covers
See the organisation an attacker sees—not the inventory you hope is complete.
External discovery is useful only when assets are attributed, changes are understood and meaningful exposure is validated.
01Observe the outside-in surface
- Discover domains, subdomains, certificates, addresses, services and cloud-hosted edges.
- Fingerprint technologies and control signals without assuming a single discovery source is complete.
- Retain first-seen and last-changed history.
02Attribute before alerting
- Connect observations to brands, cloud accounts, repositories, certificates and known services.
- Represent attribution confidence and the evidence supporting it.
- Separate owned exposure from third-party infrastructure and false associations.
03Find the change that matters
- Detect new services, certificate changes, technology drift and reopened endpoints.
- Enrich change with ownership, vulnerability and API context.
- Validate whether the change introduces a usable attack path.
04Evidence delivered
- A reviewable asset record with provenance.
- Change history and accountable owner.
- Validated priority instead of a larger inventory.