Home/Services/Attack surface monitoring

Attack surface monitoring

A standing view of what you have exposed to the internet. Most incidents start with something nobody remembered was running — this is the service that notices it went up.

What gets tested

Hosts and services

What answers on your addresses and domains, on which ports, running what. Including the things stood up for a demo two years ago and never taken down.

Names and certificates

Subdomains as they appear, certificates as they are issued and as they approach expiry, and DNS records pointing at providers you have stopped paying.

Exposed interfaces

Admin panels, dashboards, file shares, databases and management interfaces that answer from the open internet, whether or not anyone meant them to.

Change over time

The point of the service. A single scan is a snapshot; value is in the diff, because what hurts you is usually new rather than newly discovered.

How it runs

  1. 01

    Establish

    We agree what is yours — domains, address ranges, cloud accounts, brands. I map what is currently reachable and we go through it together.

  2. 02

    Baseline

    The first pass almost always turns up things nobody expected. We work out what is meant to be there, what should be taken down, and what needs a closer look.

  3. 03

    Watch

    Recurring checks against the agreed scope. The baseline is what everything after it is compared against.

  4. 04

    Notify

    When something changes, you get a message that says what changed, when, and whether it needs attention today. Silence means nothing changed.

What you get

  • An agreed, written definition of what counts as your attack surface.
  • A baseline you have actually reviewed, rather than a tool’s opinion.
  • Alerts on change, with enough context to judge urgency without logging in anywhere.
  • A named human to ask when an alert is ambiguous.
  • A periodic summary of what moved, for the people who do not want alerts.
  • PERSONALISE: state the check frequency and how alerts arrive — email, chat, ticket — once you have settled it.

What this is not

  • Not a vulnerability scanner subscription. The question here is what is exposed and what changed, not a CVE list per host.
  • Not penetration testing. Finding an exposed interface is not the same as testing what is behind it.
  • Not incident response. Monitoring tells you something changed; if it changed because someone else changed it, that is a different engagement.
  • Not agent software on your machines. This looks at you the way the internet does, from outside.

Common questions

How is this different from a one-off scan?

A scan tells you what is exposed today, and is out of date the next time someone deploys. Monitoring tells you what changed since the last time you looked.

The finding that matters is almost never "this has been open for three years". It is "this opened on Tuesday".

We already have a vulnerability scanner. Do we need this?

They answer different questions. A scanner tells you about weaknesses in assets you already know about. This is about the assets you do not.

If your scanner’s inventory is maintained by hand, the gap between the list and reality is exactly what this covers.

What do you need to get started?

A list of the domains, address ranges and cloud accounts you consider yours, and written authorisation to look at them. Everything else I can usually discover and confirm with you.

Will this set off our own alerting?

Possibly, and that is worth knowing. Tell your team what the traffic looks like and where it comes from, or leave it and treat the first pass as an unannounced test of whether they notice.

How often do alerts arrive?

Rarely, if your environment is stable — which is the point. A monitoring service that pages you weekly gets muted within a month, so the threshold is set to make each message worth reading.

Start a conversation

Tell me what you think you have exposed,
and I will tell you what I can see.

[email protected]

Replies within one working day. Dutch or English.