Attack Surface datasheet
Continuous discovery of external assets, ports, services, mobile apps, and cloud exposures — prioritised by exploitability.
One page, no preamble
Every internet-facing asset, every change, before the attacker finds it.
ShadowMap rediscovers your external attack surface every 24 hours — domains, subdomains, ports, services, mobile binaries, certificate changes, cloud exposures — and ranks each finding by what an attacker can actually do with it. No agents, no allowlists, no cooperation from the asset owner required.
Everything in the datasheet is on this page and on the Attack Surface capability page. The PDF exists because procurement asks for one, not because it says anything the site does not.
Attack Surface datasheet (PDF)
We'll email you a confirmation link. Click it and the PDF downloads — no waiting on a sales call.
Check your inbox
We've emailed you a link to download Attack Surface datasheet (PDF).
The link expires in 48 hours. If it hasn't arrived in a few minutes, check your spam folder.
We couldn't send the download link. Please try again, or contact us and we'll email you Attack Surface datasheet (PDF).
Prefer to skip the form? Everything here is on the capability page, ungated.
The capability list
What Attack Surface discovers
| Capability | What it does |
|---|---|
| Subdomain + DNS discovery | Passive + active enumeration across registrar, DNS, certificate transparency, and reverse-DNS sources. Catches the orphan subdomain marketing spun up last quarter. |
| Open ports + service banners | Daily port-scan with banner grabbing across the discovered surface. New service appearing on a known host = same-day alert. |
| Web app + API fingerprinting | Tech-stack detection on every web property. Knowing it's WordPress 6.2 vs 6.7 changes which CVEs matter. |
| Mobile app inventory | Continuous monitoring of Play Store, App Store, and side-loaded marketplaces for legitimate and impersonating apps that carry your name. |
| Cloud-storage exposures | Misconfigured S3, GCS, Azure Blob, and DigitalOcean Spaces buckets that match your attributed inventory. |
| Certificate + TLS posture | Expired, weak, or wildcard-leaking certificates flagged with renewal and remediation guidance. |
| Exploitability scoring | Each finding ranked by the joint signal of severity × exploit availability × your asset criticality. Makes triage finite. |
| Change diffing | Daily diffs surface the exact thing that changed — new port, new subdomain, new TLS cert — so you don't re-read yesterday's noise. |
Every capability in the Attack Surface module, as printed in the datasheet
Subdomain + DNS discovery
- What it does
- Passive + active enumeration across registrar, DNS, certificate transparency, and reverse-DNS sources. Catches the orphan subdomain marketing spun up last quarter.
Open ports + service banners
- What it does
- Daily port-scan with banner grabbing across the discovered surface. New service appearing on a known host = same-day alert.
Web app + API fingerprinting
- What it does
- Tech-stack detection on every web property. Knowing it's WordPress 6.2 vs 6.7 changes which CVEs matter.
Mobile app inventory
- What it does
- Continuous monitoring of Play Store, App Store, and side-loaded marketplaces for legitimate and impersonating apps that carry your name.
Cloud-storage exposures
- What it does
- Misconfigured S3, GCS, Azure Blob, and DigitalOcean Spaces buckets that match your attributed inventory.
Certificate + TLS posture
- What it does
- Expired, weak, or wildcard-leaking certificates flagged with renewal and remediation guidance.
Exploitability scoring
- What it does
- Each finding ranked by the joint signal of severity × exploit availability × your asset criticality. Makes triage finite.
Change diffing
- What it does
- Daily diffs surface the exact thing that changed — new port, new subdomain, new TLS cert — so you don't re-read yesterday's noise.
How it works
Seed → Map → Score → Notify
Seed
Start from your apex domain(s); ShadowMap fans out via passive + active discovery sources.
Map
Build a typed inventory: domains → hosts → services → web apps → APIs → mobile apps → cloud resources.
Score
Each asset + finding scored by severity, exploit availability, and your business-context criticality.
Notify
New + changed exposures route to Slack, Jira, ServiceNow, Splunk, or whatever ticketing you already live in.
What changes
More assets surfaced vs. internal inventory
Customers typically discover 30–60% more external assets in the first scan than they had inventoried internally — including a few that turn out to be legacy, forgotten, and exploitable.
In the Platform
Composes with
ShadowMap works from one correlated exposure model. The signals from this capability sharpen — and are sharpened by — the ones below.
Data Exposure
Code repositories, cloud buckets, paste sites, and document leaks — surfaced with secret scanning and ownership attribution.
BRP-01 · ExposureBrand Protection
Domain spoofs, social impersonation, phishing kits, and look-alike apps — detected and taken down before customers are hit.
VAL-01 · ValidationCART
Continuous Automated Red-Teaming — exposures discovered upstream are tested rather than asserted, wherever it is safe and authorised to do so.