Know what the internet can see — before an attacker does
ThreatWorx EASM discovers your entire internet-facing footprint from the outside in — starting from nothing more than a domain name — and watches it continuously for the changes that create risk.
These are the assets that get breached — precisely because no one is looking at them.
- Forgotten staging boxes and expired SaaS CNAMEs
- A microsite on someone's personal cloud account
- A subdomain still pointing at a de-provisioned bucket
- An API key baked into a JavaScript bundle
Your real perimeter is larger than the one you maintain
Asset inventories describe what you built on purpose. Attackers enumerate what actually answers on the internet — including everything acquired, spun up for a campaign, inherited from a merger, or left behind by a team that has since moved on.
ThreatWorx EASM closes that gap continuously, and puts what it finds in the same inventory as the rest of your estate — so external exposure is prioritised against your hosts, cloud accounts, containers, and code, not in a separate tool with a separate backlog.
One seed in. Your whole surface out.
Seed a domain, hostname, IP, CIDR, or ASN — auto-classified — and the pipeline does the rest, on every scheduled run.
Start from a name
Domain, hostname, IP, CIDR, or ASN — single or bulk, from a seed file.
Enumerate outward
Passive and active subdomain discovery, ASN/CIDR expansion, reverse-WHOIS and reverse-IP pivots.
Separate real from noise
A vetted multi-resolver pool resolves candidates; wildcard-only responses are subtracted.
Know who owns the IP
Cloud/CDN provider, region and service tags — or flagged as likely target-owned.
Test what's exposed
Tech and versions, panels, headers, cookies, methods, JS bundles, ports; DNS and email hygiene, takeover, buckets, typosquats.
Rank by exploitation
CISA KEV and FIRST.org EPSS escalate CVE-linked findings and re-sort each asset worst-first.
Land in one inventory
Assets, tags, and config issues flow into the ThreatWorx platform alongside everything else you own.
Catch what changed
Incremental Certificate-Transparency polling surfaces new and look-alike certificates on every run.
Discovery depth of a dedicated EASM vendor
Discovery & enumeration
- Passive subdomain enumeration from 10 independent sources — CT logs, passive DNS, urlscan, Wayback, Common Crawl and more
- Bounded active brute force with tiered wordlists (~130 / ~5k / ~20k) and wildcard-DNS fingerprinting
- Permutation scanning across environment tokens — dev, stage, qa, uat
- Org-ASN derivation and full reverse-DNS sweeps of announced prefixes
- Reverse-WHOIS, reverse-IP and virtual-host discovery, including apps reachable with no current DNS
- Optional recursive discovery into related domains, tapering by depth
Attribution & context
- Cloud and CDN attribution across AWS, GCP, Azure, Microsoft 365, Oracle OCI, Cloudflare, Fastly, DigitalOcean, Linode, Vultr, GitHub and Rackspace
- Provider, region and service tags on every IP — and an explicit unattributed label for likely target-owned space
- Discovery provenance on every asset: which seed and which sources found it
- Technology and product fingerprinting with version recovery probes
Risk detection
- Subdomain and dangling-DNS takeover, fingerprinted against the community can-i-take-over-xyz set
- Cloud storage bucket discovery across S3, GCS and Azure Blob — public listing and claimed-namespace risk
- JavaScript bundle analysis: 14 secret patterns, API paths, internal hostnames, exposed source maps
- DNS hygiene and email posture — SPF, DKIM alignment, DMARC strength, zone transfer, open resolvers
- Typosquat and look-alike domain detection with ongoing CT watch
- Netblock port sweeps with risky-port labelling; exposed panels, directory listings, dangerous methods, open redirects, missing headers
Continuous monitoring
- Incremental Certificate-Transparency polling with a persisted per-domain cursor, plus a time-window fallback for cold starts
- New-subdomain and look-alike-certificate findings on every run, with a status heartbeat
- Built for scheduled invocation — hourly, daily, or per CI run — with no long-lived daemon
- Cached lookups shared across runs, so repeat scans stay cheap
“Patch this” should mean “this one is being exploited”
Every CVE-linked finding is enriched against CISA KEV and FIRST.org EPSS. Ratings escalate — never downgrade — and each asset's issues are re-sorted worst-first, with an exploitation-prioritised summary per asset. No 900-row CVSS spreadsheet, and no paid add-on.
Coverage is reported honestly too: IPs that match no known provider prefix are labelled unattributed, so “we don't know” never masquerades as “it's fine”.
Two ways to run the scans. One place for the results.
The open twigs collector
Run an assessment ad hoc from a workstation, container, or CI job. Open source, auditable line by line.
The discovery app
Deploy once to keep your external attack surface under continuous, scheduled assessment — no daemon babysitting.
Requirements
- No agent on the target assets; no inbound access
- Outbound HTTPS and DNS is enough for core discovery
- Optional masscan or naabu for faster port sweeps
- No paid API keys required for core features
- Every active module has an opt-out; scan rate and wordlist tier are tunable
External surface in the same graph as everything else you own
ThreatWorx already inventories hosts, cloud accounts, containers, Kubernetes, code repositories and SBOMs. EASM adds the outside view — correlated, prioritised, alerted, and pushed into the same remediation workflow. One console, one severity model, one backlog.
Common questions
Do we need to install anything on our assets?
No. Discovery is entirely external, and needs no agent on the assets and no inbound access to your network.
How noisy is the scanning?
Discovery is passive-first. Active probing is bounded and rate-aware, and every active module can be switched off individually.
How often does it run?
As often as you schedule it — hourly, daily, or per CI run. Incremental CT polling means each run reports what actually changed.
Can we start from just one domain?
Yes. A single domain is a complete starting point; hostnames, IPs, CIDRs, ASNs and seed files are all supported as you scale up.
Attackers enumerate your surface whether you do or not
Bring a domain to a 30-minute session and see what ThreatWorx EASM finds on your own perimeter.