Skip to main content
Exposure · Module ASI-01 · PDF

Attack Surface datasheet

Continuous discovery of external assets, ports, services, mobile apps, and cloud exposures — prioritised by exploitability.

One page, no preamble

Every internet-facing asset, every change, before the attacker finds it.

ShadowMap rediscovers your external attack surface every 24 hours — domains, subdomains, ports, services, mobile binaries, certificate changes, cloud exposures — and ranks each finding by what an attacker can actually do with it. No agents, no allowlists, no cooperation from the asset owner required.

Everything in the datasheet is on this page and on the Attack Surface capability page. The PDF exists because procurement asks for one, not because it says anything the site does not.

Attack Surface datasheet (PDF)

We'll email you a confirmation link. Click it and the PDF downloads — no waiting on a sales call.

By downloading, you agree to receive relevant communications. We respect your privacy.

Prefer to skip the form? Everything here is on the capability page, ungated.

The capability list

What Attack Surface discovers

Every capability in the Attack Surface module, as printed in the datasheet
CapabilityWhat it does
Subdomain + DNS discovery Passive + active enumeration across registrar, DNS, certificate transparency, and reverse-DNS sources. Catches the orphan subdomain marketing spun up last quarter.
Open ports + service banners Daily port-scan with banner grabbing across the discovered surface. New service appearing on a known host = same-day alert.
Web app + API fingerprinting Tech-stack detection on every web property. Knowing it's WordPress 6.2 vs 6.7 changes which CVEs matter.
Mobile app inventory Continuous monitoring of Play Store, App Store, and side-loaded marketplaces for legitimate and impersonating apps that carry your name.
Cloud-storage exposures Misconfigured S3, GCS, Azure Blob, and DigitalOcean Spaces buckets that match your attributed inventory.
Certificate + TLS posture Expired, weak, or wildcard-leaking certificates flagged with renewal and remediation guidance.
Exploitability scoring Each finding ranked by the joint signal of severity × exploit availability × your asset criticality. Makes triage finite.
Change diffing Daily diffs surface the exact thing that changed — new port, new subdomain, new TLS cert — so you don't re-read yesterday's noise.

Every capability in the Attack Surface module, as printed in the datasheet

Subdomain + DNS discovery

What it does
Passive + active enumeration across registrar, DNS, certificate transparency, and reverse-DNS sources. Catches the orphan subdomain marketing spun up last quarter.

Open ports + service banners

What it does
Daily port-scan with banner grabbing across the discovered surface. New service appearing on a known host = same-day alert.

Web app + API fingerprinting

What it does
Tech-stack detection on every web property. Knowing it's WordPress 6.2 vs 6.7 changes which CVEs matter.

Mobile app inventory

What it does
Continuous monitoring of Play Store, App Store, and side-loaded marketplaces for legitimate and impersonating apps that carry your name.

Cloud-storage exposures

What it does
Misconfigured S3, GCS, Azure Blob, and DigitalOcean Spaces buckets that match your attributed inventory.

Certificate + TLS posture

What it does
Expired, weak, or wildcard-leaking certificates flagged with renewal and remediation guidance.

Exploitability scoring

What it does
Each finding ranked by the joint signal of severity × exploit availability × your asset criticality. Makes triage finite.

Change diffing

What it does
Daily diffs surface the exact thing that changed — new port, new subdomain, new TLS cert — so you don't re-read yesterday's noise.

How it works

Seed → Map → Score → Notify

1

Seed

Start from your apex domain(s); ShadowMap fans out via passive + active discovery sources.

2

Map

Build a typed inventory: domains → hosts → services → web apps → APIs → mobile apps → cloud resources.

3

Score

Each asset + finding scored by severity, exploit availability, and your business-context criticality.

4

Notify

New + changed exposures route to Slack, Jira, ServiceNow, Splunk, or whatever ticketing you already live in.

30–60%

What changes

More assets surfaced vs. internal inventory

Customers typically discover 30–60% more external assets in the first scan than they had inventoried internally — including a few that turn out to be legacy, forgotten, and exploitable.