New · ThreatWorx Platform SKU

Know what the internet can see — before an attacker does

ThreatWorx EASM discovers your entire internet-facing footprint from the outside in — starting from nothing more than a domain name — and watches it continuously for the changes that create risk.

These are the assets that get breached — precisely because no one is looking at them.

  • Forgotten staging boxes and expired SaaS CNAMEs
  • A microsite on someone's personal cloud account
  • A subdomain still pointing at a de-provisioned bucket
  • An API key baked into a JavaScript bundle
0
passive discovery sources, each failure‑tolerant
0
vetted resolvers, tested for NXDOMAIN honesty
0
cloud & CDN providers attributed by prefix
0
agents on assets, daemons, or paid API keys required
The Gap

Your real perimeter is larger than the one you maintain

Asset inventories describe what you built on purpose. Attackers enumerate what actually answers on the internet — including everything acquired, spun up for a campaign, inherited from a merger, or left behind by a team that has since moved on.

ThreatWorx EASM closes that gap continuously, and puts what it finds in the same inventory as the rest of your estate — so external exposure is prioritised against your hosts, cloud accounts, containers, and code, not in a separate tool with a separate backlog.

How It Works

One seed in. Your whole surface out.

Seed a domain, hostname, IP, CIDR, or ASN — auto-classified — and the pipeline does the rest, on every scheduled run.

01 / Seed

Start from a name

Domain, hostname, IP, CIDR, or ASN — single or bulk, from a seed file.

02 / Expand

Enumerate outward

Passive and active subdomain discovery, ASN/CIDR expansion, reverse-WHOIS and reverse-IP pivots.

03 / Resolve

Separate real from noise

A vetted multi-resolver pool resolves candidates; wildcard-only responses are subtracted.

04 / Attribute

Know who owns the IP

Cloud/CDN provider, region and service tags — or flagged as likely target-owned.

05 / Assess

Test what's exposed

Tech and versions, panels, headers, cookies, methods, JS bundles, ports; DNS and email hygiene, takeover, buckets, typosquats.

06 / Prioritise

Rank by exploitation

CISA KEV and FIRST.org EPSS escalate CVE-linked findings and re-sort each asset worst-first.

07 / Report

Land in one inventory

Assets, tags, and config issues flow into the ThreatWorx platform alongside everything else you own.

08 / Watch

Catch what changed

Incremental Certificate-Transparency polling surfaces new and look-alike certificates on every run.

Capabilities

Discovery depth of a dedicated EASM vendor

Discovery & enumeration

  • Passive subdomain enumeration from 10 independent sources — CT logs, passive DNS, urlscan, Wayback, Common Crawl and more
  • Bounded active brute force with tiered wordlists (~130 / ~5k / ~20k) and wildcard-DNS fingerprinting
  • Permutation scanning across environment tokens — dev, stage, qa, uat
  • Org-ASN derivation and full reverse-DNS sweeps of announced prefixes
  • Reverse-WHOIS, reverse-IP and virtual-host discovery, including apps reachable with no current DNS
  • Optional recursive discovery into related domains, tapering by depth

Attribution & context

  • Cloud and CDN attribution across AWS, GCP, Azure, Microsoft 365, Oracle OCI, Cloudflare, Fastly, DigitalOcean, Linode, Vultr, GitHub and Rackspace
  • Provider, region and service tags on every IP — and an explicit unattributed label for likely target-owned space
  • Discovery provenance on every asset: which seed and which sources found it
  • Technology and product fingerprinting with version recovery probes

Risk detection

  • Subdomain and dangling-DNS takeover, fingerprinted against the community can-i-take-over-xyz set
  • Cloud storage bucket discovery across S3, GCS and Azure Blob — public listing and claimed-namespace risk
  • JavaScript bundle analysis: 14 secret patterns, API paths, internal hostnames, exposed source maps
  • DNS hygiene and email posture — SPF, DKIM alignment, DMARC strength, zone transfer, open resolvers
  • Typosquat and look-alike domain detection with ongoing CT watch
  • Netblock port sweeps with risky-port labelling; exposed panels, directory listings, dangerous methods, open redirects, missing headers

Continuous monitoring

  • Incremental Certificate-Transparency polling with a persisted per-domain cursor, plus a time-window fallback for cold starts
  • New-subdomain and look-alike-certificate findings on every run, with a status heartbeat
  • Built for scheduled invocation — hourly, daily, or per CI run — with no long-lived daemon
  • Cached lookups shared across runs, so repeat scans stay cheap
Prioritisation
“Patch this” should mean “this one is being exploited”

Every CVE-linked finding is enriched against CISA KEV and FIRST.org EPSS. Ratings escalate — never downgrade — and each asset's issues are re-sorted worst-first, with an exploitation-prioritised summary per asset. No 900-row CVSS spreadsheet, and no paid add-on.

Coverage is reported honestly too: IPs that match no known provider prefix are labelled unattributed, so “we don't know” never masquerades as “it's fine”.

CRITICAL
Live cloud credential or private key in a public JS bundle
HIGH
Subdomain takeover on a vulnerable service; publicly listable storage bucket; high-value secret exposure
MEDIUM
Edge-case takeover; look-alike certificate issued; virtual host with no current DNS; weak email authentication
LOW
New subdomain observed; private bucket under org naming; exposed source map; historical sensitive path now live
INFO
Inventory: co-hosted hostnames, discovered subdomains, PTR-named hosts, tech stack, provenance, CT status
Deployment

Two ways to run the scans. One place for the results.

Option A · CLI

The open twigs collector

Run an assessment ad hoc from a workstation, container, or CI job. Open source, auditable line by line.

twigs easm --fqdn example.com
github.com/threatworx/twigs →
Option B · Scheduled

The discovery app

Deploy once to keep your external attack surface under continuous, scheduled assessment — no daemon babysitting.

twigs easm --seed_file surface.txt \ --asn_sweep
github.com/threatworx/discovery_app →

Requirements

  • No agent on the target assets; no inbound access
  • Outbound HTTPS and DNS is enough for core discovery
  • Optional masscan or naabu for faster port sweeps
  • No paid API keys required for core features
  • Every active module has an opt-out; scan rate and wordlist tier are tunable
One Platform

External surface in the same graph as everything else you own

ThreatWorx already inventories hosts, cloud accounts, containers, Kubernetes, code repositories and SBOMs. EASM adds the outside view — correlated, prioritised, alerted, and pushed into the same remediation workflow. One console, one severity model, one backlog.

ThreatWorx Console
EASM Inventory + Prioritised Findings

Common questions

Do we need to install anything on our assets?

No. Discovery is entirely external, and needs no agent on the assets and no inbound access to your network.

How noisy is the scanning?

Discovery is passive-first. Active probing is bounded and rate-aware, and every active module can be switched off individually.

How often does it run?

As often as you schedule it — hourly, daily, or per CI run. Incremental CT polling means each run reports what actually changed.

Can we start from just one domain?

Yes. A single domain is a complete starting point; hostnames, IPs, CIDRs, ASNs and seed files are all supported as you scale up.

Attackers enumerate your surface whether you do or not

Bring a domain to a 30-minute session and see what ThreatWorx EASM finds on your own perimeter.