Attack Surface datasheet
Continuous discovery of external assets, ports, services, mobile apps, and cloud exposures — prioritised by exploitability.
What's in it
One page, no preamble
ShadowMap rediscovers your external attack surface every 24 hours — domains, subdomains, ports, services, mobile binaries, certificate changes, cloud exposures — and ranks each finding by what an attacker can actually do with it. No agents, no allowlists, no cooperation from the asset owner required.
- Every capability the module ships, with what each one actually does
- The four-step mechanic — Seed → Map → Score → Notify
- What changes once it is running, and how Attack Surface composes with the rest of the platform
Everything in the datasheet is also on the Attack Surface capability page. The PDF exists because procurement asks for one, not because it says anything the site does not.
Attack Surface datasheet (PDF)
We'll email you a confirmation link. Click it and the PDF downloads — no waiting on a sales call.
Check your inbox
We've emailed you a link to download Attack Surface datasheet (PDF).
The link expires in 48 hours. If it hasn't arrived in a few minutes, check your spam folder.
Something went wrong. Please try again.
Prefer to skip the form? Everything here is on the capability page, ungated.
In the Platform
Composes with
ShadowMap works from one correlated exposure model. The signals from this capability sharpen — and are sharpened by — the ones below.
Data Exposure
Code repositories, cloud buckets, paste sites, and document leaks — surfaced with secret scanning and ownership attribution.
BRP-01 · ExposureBrand Protection
Domain spoofs, social impersonation, phishing kits, and look-alike apps — detected and taken down before customers are hit.
VAL-01 · ValidationCART
Continuous Automated Red-Teaming — exposures discovered upstream are tested rather than asserted, wherever it is safe and authorised to do so.