Attackers do not start from your asset inventory. They start from certificate logs, DNS history, code repositories and breach dumps, and they usually find a system that nobody remembers: a staging copy, a marketing site from three years ago, an administrative panel on a forgotten subdomain.
We do the same work first. Discovery relies on public sources and does not touch your systems. What we find is presented to you, you confirm what is yours, and only the confirmed assets are examined actively.
01Scope
What we test
Domains and subdomains, including historic records and certificate transparency logs
Address space, cloud resources and content delivery configurations
Exposed services: administrative interfaces, databases, remote access, development tools
Subdomain takeover and dangling DNS records
Public code repositories, package registries and container images
Leaked credentials in public breach data and paste sites
Mail configuration: SPF, DKIM, DMARC and exposure to spoofing
Third-party services that host your data or act in your name
02Approach
How the work is done
01
Passive discovery
Assets are collected from public sources only. Nothing is sent to your systems at this stage.
02
Ownership confirmation
You receive the list and mark what belongs to you. Assets of third parties are excluded unless their operator consents.
03
Active verification
Confirmed assets are examined: services identified, versions checked, exposures verified by hand.
04
Prioritisation
Each exposure is rated by what an attacker could do with it and by how likely exploitation is, using CVSS and EPSS where they apply.
No. The assessment is performed from the position of an outsider. You only confirm which of the discovered assets are yours.
How do you handle leaked credentials that you find?
We record where they were found and check whether they follow your current password policy. They are not used to log in unless the rules of engagement allow it explicitly. The list is delivered through a secure channel and destroyed after hand-over.
Can this run continuously?
Yes. The attack surface changes with every deployment. Repeated discovery with verification of new assets is part of continuous penetration testing.