Capability · Enterprise

External attack surface management,
from the attacker’s side of the firewall.

You cannot defend an asset you do not know you own. GuardianGaze discovers your internet-facing estate, assesses it across six modules, and scores it 0–100: without an agent, a credential or a scoping call.

Assessed by domain. No access to your environment required.

How it works

Discover, observe, prioritise, act

Attack surface management is a loop, not a report. Each pass re-discovers the estate, because the estate changes without telling you.

01

Discover

Subdomain enumeration and liveness checks find the estate nobody documented, staging hosts, forgotten marketing sites, acquired-company domains.

02

Observe

Technology discovery, exposed ports and services, security headers, certificate and DNS posture, cloud misconfiguration across AWS, GCP and Cloudflare.

03

Prioritise

CVEs are ranked with CVSS, EPSS and KEV so you work on what is actually being exploited, not the longest list.

04

Act

Every finding carries severity, evidence, remediation and an SLA, mapped to MITRE ATT&CK and to the control it breaks.

What makes it different

Breadth, with the evidence attached

Most outside-in platforms stop at infrastructure. The attack surface a real attacker uses also includes your brand and your people.

Agentless

Nothing to install

Everything is observed from the public internet. No agents, no credentials, no scoping call, the same vantage point an attacker has.

Evidence

Findings, not a feed

Each finding records what was observed, where, why it matters and who it affects. Prioritised and evidence-backed rather than a raw dump of every open port.

Continuous

Monitored, not sampled

Continuous monitoring with on-demand rescans, so the picture reflects the estate today rather than the quarter it was last reviewed.

Coverage

What gets discovered and assessed

Six modules, one score. Each finding carries severity, evidence, remediation and an SLA.

Infrastructure and applications

  • Subdomain enumeration and liveness across the estate
  • Technology discovery on every live host and high-signal path
  • CVE detection backed by NVD, prioritised with CVSS, EPSS and KEV
  • Exposed IPs, ports, services and service-level CVEs
  • Security headers and subresource integrity
  • Cloud posture and misconfiguration across AWS, GCP and Cloudflare

Domain, brand and people

  • SPF, DKIM, DMARC, MTA-STS and TLS-RPT, email spoofability as a headline finding
  • MX and mail-provider fingerprinting, DNS hygiene
  • Typosquat and lookalike-TLD registrations against your brand
  • WHOIS and abuse intelligence on hostile registrations
  • Leaked credentials belonging to your people, found in breach data
  • AI brand-mention intelligence across web and social
Overall rating with per-module scores and findings by severity

One rating for the organisation, six module scores underneath it

Questions

Common questions

How is this different from a vulnerability scanner?

A scanner tests hosts you already know about and usually needs credentials or network access. Attack surface management starts by finding the assets you did not know were exposed, from outside, and then assesses them. GuardianGaze needs no access to your environment at all.

Do you need access to our systems?

No. Discovery and assessment run entirely from the public internet. Cloud posture checks are the one exception and are optional, using read-only scoped access to AWS, GCP or Cloudflare if you choose to connect them.

What do you actually look at?

Six modules: brand protection, domain security, application security, network security, cloud security and compliance. Each produces a deterministic 0 to 100 score, and findings roll up into one overall rating for the organisation.

Can you assess companies other than our own?

Yes. Because assessment is outside-in and needs no permission from the target, the same process rates any company by domain, which is how the vendor and supply-chain use cases work.

See your external attack surface as an attacker sees it

Start with your own domain. The first report usually finds an exposed host nobody remembered owning.

Free for your own organisation. Assessed by domain, no access required.