External Attack Surface Management

See what attackers see — before they do.

One-time audits of your public attack surface, brand & email security, and shadow cloud infrastructure. Plain English. Real remediation. Every finding mapped to NIST, MITRE ATT&CK and CISA KEV. No agents, no meetings, no consultants.

Improve accuracy — optional organization details

One per line. Everything here is optional — it widens what we look for and keeps your own assets out of the impersonation results.

Used to catch impersonation that spells out your name instead of your domain.

Stops your own sites being reported as lookalikes.

Adds them to credential-exposure and email-security checks.

Marketing, support or SSO platforms you intentionally point DNS at.

Free, full-depth report — no card, no paid tier. Free account required, and you'll only scan domains you're authorized to assess.

The cheapest security control you can buy

Nearly every intrusion starts with something reachable from the public internet. Attackers enumerate that surface continuously — most companies have never enumerated it once. Discovery comes before patching, pen-testing and insurance questionnaires, because all of them assume you already know what you own.

What one report tells you

Two focused sections. Every finding is scored, evidenced, and mapped to a fix and to the control frameworks you report against.

Section 1

Brand, Identity & Email Security

  • SPF, DKIM & DMARC posture
  • Registered lookalike / typosquat domains
  • Lookalike pages inspected for logo, color and typography cloning plus credential harvesting — with your uploaded logo files used to verify a copied mark rather than infer one
  • Clones found by brand name on unrelated domains, not only on mis-spellings of your address
  • Screenshot evidence captured for every impersonation match, bundled into a takedown pack with a ready-to-send abuse report
  • Hostile typo domains that attack or monetize your users' mis-types — fake alerts, forced downloads, adult, gambling and affiliate traffic brokering — with block and sinkhole guidance
  • Rotating redirect chains detected by sampling each live typo domain repeatedly, so every destination it sells your mis-typed traffic to is listed, not just the first one
  • An AI reader judges what each live lookalike page actually does to a visitor, so novel and paraphrased scam pages are caught and pages that merely mention scams are not flagged
  • Breached corporate credential exposure
  • Sensitive documents indexed by search engines
  • Public web exposure history & malicious verdicts
Section 2

Perimeter & Cloud Infrastructure

  • Subdomain and shadow-host inventory
  • Exposed services & known CVE matching
  • Cloud/TLS asset intelligence
  • Dangling DNS, orphaned nameservers & domain-expiry takeover risk
  • Leaked credentials, API keys and config files in public code repositories
  • Shadow IT & forgotten dev/staging hosts
  • Deep OSINT sweep across 100+ sources

Every finding speaks compliance

Each risk is labeled with the control frameworks your auditors, insurers and board already use — so nobody on your side has to translate a scanner result into a control reference.

NIST

CSF 2.0 + SP 800-53

Findings map to the CSF function and category they answer — an inventory of active corporate subdomains lands under asset identification — so the report drops straight into a gap assessment instead of starting one.

MITRE

ATT&CK techniques

Each exposure carries the technique an attacker would actually use against it, so a finding reads as an attack path your team can reason about — not as another scanner line item.

CISA

Known Exploited Vulnerabilities

Every CVE we surface is checked against the live CISA KEV catalog. A match is escalated to Critical automatically, so anything being exploited in the wild right now rises to the top of your list.

A report-level coverage roll-up shows which framework functions the audit touched, and the alignment travels with you into the PDF and HTML exports you hand to auditors.

Free for everyone

Every check, every finding, every export — free with an account. No paid tier, no locked report, no sales call. The project runs on voluntary contributions from the people it helps.

The whole platform
$0
Free account, no card

Full-depth audit: brand impersonation, credential exposure, perimeter and cloud intelligence, source-code exposure, framework alignment, playbook and exports.

Fair use
1 / week
4 per 30 days, 1 per domain per day

Caps keep third-party lookup costs survivable. They are not an upsell — nothing is held back from a free account.

Supporters
From $5
One-time or monthly

Contributions cover the lookups and hosting, and unlock continuous coverage: weekly checks, monthly re-audits, change detection and trends.

Ready to see your surface?

Run a full audit now — it takes about a minute, costs nothing, and the whole report is yours.