Attack Surface Management

Know your attack surface before attackers do.

You cannot defend what you have not found. Most organisations are exposed by something nobody remembered owning - a forgotten subdomain, a supplier's login page, a certificate issued for a name that looks almost like yours. CA/CR® ReconX maps everything you expose to the internet, tests it the way an attacker would, and follows every finding through to a verified fix.

Domain MappingDiscoveryVulnerabilityWeb AuditReputation3rd-Party RiskIdentityInternal PostureReports
Why attack surface management

The estate is always larger than the inventory

Nobody sets out to leave a management interface facing the internet. It happens because estates grow by addition and shrink by nobody - a marketing campaign registers a domain, a supplier stands up a portal in your name, a developer publishes a staging environment for one afternoon in 2021. None of it appears in a spreadsheet, and all of it is reachable.

Find it

Start from a single company name. ReconX works outwards through registrations, DNS, certificates and network ownership until it has the whole namespace - including the parts that were never written down, and the subsidiaries acquired before anyone thought about security.

Test it

Active, evidence-led testing rather than a questionnaire. Every finding carries what was observed, where, and when - so it can be reproduced, argued with, and closed. Nothing is scored on inference alone.

Prove it is fixed

A finding is only closed when the next scan cannot find it. If a fix quietly reverts, ReconX raises it again as a regression rather than leaving a resolved ticket that stopped being true.

Nine modules, one surface

What ReconX looks at

Each module answers a question a CISO is asked and usually cannot evidence. They run on their own schedules against a shared, continuously reconciled inventory, and they roll up into one score per entity - and one score for the group.

Domain Mapping

The authoritative picture of your namespace, established before anything is scanned. Ownership, registrar and expiry tracking - including domains you depend on but never registered. DNS resolved against every authoritative nameserver rather than a recursive one, so you see what the internet sees. Certificate Transparency, network ownership, and email security posture - SPF, DKIM, DMARC, DNSSEC, STARTTLS - each with a failing since date.

Discovery

Names turned into a live asset inventory. Host resolution across the full namespace, structural subdomain discovery, tiered port scanning and per-hostname web application fingerprinting. Shared SaaS and CDN infrastructure is excluded from your score - a finding on a Microsoft or Cloudflare front end describes their posture, not yours. Inventory stays separate from scan eligibility, so everything resolved remains visible.

Vulnerability

Active testing across web, network and service surfaces, with version-derived matching for software that advertises itself. Every finding arrives enriched with CVSS, EPSS exploit probability, CISA KEV status, CWE class and an SSVC decision priority - so the question stops being how bad is this and becomes act now, next sprint, or not at all.

Web Audit

Around 44 checks across everything you publish: security headers, CORS, cookie flags, exposed .git and .env files, debug modes, published source maps, secrets left in served content and RFC 9116 security.txt. Each check knows whether it describes the server or the published site, so an error page is still assessed for headers and secrets but never told it is missing a sitemap. Audits deduplicate by response, not hostname.

Reputation

How the outside world sees you, and who is pretending to be you. Blocklist and DNSBL monitoring across 16 sources, with a control probe so a list that is refusing queries is never reported as clean. Look-alike and typosquat detection backed by Certificate Transparency - an impersonating domain surfaces the moment a certificate is issued - with automated screenshots and brand-reference detection.

3rd-Party Risk

Independent, evidence-based supplier scorecards - not a questionnaire your vendor fills in about themselves. Vendor estates are assessed in isolation, weighted so a large supplier cannot dilute a serious finding, and deduplicated globally so a vendor shared across your group is assessed once. A vendor with no measurable surface is reported as exactly that.

Identity

Corporate credentials already circulating outside your estate - from breaches, combolists and infostealer logs, with the infected-host context that tells you whether a personal device is involved. Executive correlation, detection of corporate credentials reused on external services, and severity dated from when the credential was stolen rather than when we happened to find it.

Internal Posture

The inside view, from a signed lightweight agent on your Linux estate. Distribution-aware patch status - a backported fix is recognised as a fix. Failed services, reboot state, unsupported releases, per-mount resource thresholds with trend history, file integrity by hash, SSH key inventory and security log review. A check the agent could not run is reported as a finding in its own right, never allowed to pass silently as clean.

Reports

On-demand and scheduled PDF reporting per entity, with distribution lists and time-limited external sharing for stakeholders who should not need an account. Weekly posture snapshots give auditors, boards and insurers what they actually ask for: not a point-in-time score, but evidence that the surface is measurably shrinking.

External + internal

Both sides of the perimeter

External scanning tells you what an attacker can reach. It cannot tell you whether the server behind it is patched, whether a service is failing, or whether a file changed last night. Most ASM products stop at the perimeter and most vulnerability scanners never look at it. ReconX does both, and correlates them - so a version banner visible from outside can be checked against what is actually installed inside.

Outside-in

What an attacker sees

No agent, no access, no cooperation required - the same position an attacker starts from. This is also the only way to assess a supplier, an acquisition during due diligence, or a subsidiary whose IT you do not yet control.

  • Namespace, DNS and certificate posture
  • Live hosts, open services and web applications
  • Exploitable software and configuration weaknesses
  • Impersonating domains and reputation damage
  • Credentials already exposed elsewhere
  • Supplier estates, assessed independently
Inside-out

What the host knows

A signed agent, deliberately minimal in what it collects and what it is permitted to see. It reports state, not content - and it is explicit about the difference.

  • Patch and security-update status, distribution-aware
  • Failed services, reboot state, unsupported releases
  • Disk, memory and CPU thresholds with trend history
  • File integrity by hash - never file contents
  • Process monitoring by name - never command lines
  • Security log review - no raw log line leaves the host
How we build it

Rules we hold ourselves to

Every ASM vendor claims coverage. These are the commitments that are harder to make - and the ones worth asking any vendor about, including us.

A check we could not run is never a pass

If a collector is disabled, unconsented or unavailable, that is reported as a finding. A dashboard that shows green because it failed to ask the question is worse than no dashboard.

No grade without evidence

An asset or supplier with nothing measurable is reported as unmeasured. An A awarded because we found nothing to test is not a good result - it is a broken one.

Secrets stay inside

No password, masked or in clear, ever leaves the platform in an alert, a ticket or a report. Log review returns what happened, never the log line, the username or the command.

Assets are named, not numbered

Findings are reported against the hostname recorded when we saw them, with the address alongside. Reverse DNS is shown as context and never promoted to an asset name - it is as often somebody else's infrastructure as yours.

Not your problem is not your score

Findings on shared SaaS and CDN infrastructure describe that provider's posture, not yours. They are excluded from your grade and never raised as your ticket.

A fix that reverts is a new finding

Closure requires the next scan to be unable to reproduce it. When something comes back it is raised as a regression - a distinct event, not a quietly reopened ticket nobody notices.

How ReconX is delivered

A platform is not a service

Buying a scanner gives you findings. What most organisations lack is not detection but the capacity to act on it - somebody to decide what matters this week, chase the supplier who owns the portal, and confirm the fix actually landed. ReconX is delivered inside the Pro CISO® SOC Service, where analysts triage what it finds alongside your Microsoft 365 and identity signals, and correlate across all of them.

See your own attack surface, not a demo tenant

Give us your domain names and we will show you what ReconX finds - the assets, the exposures and the impersonating domains you did not know about. No agent, no access, no obligation.

Request a demo →