← Blog
2 min readOlesia Shelestova

External Exposure Assessments: What We Wanted to Give Users

Upload 50,000+ companies and check each one in seconds to minutes - open mail relays, phishing exposure, leaks, active malware, dark-web mentions, how often companies like this get hacked, exposed domains and services, basic compliance, scoring and OSINT. Here's the thinking behind the feature.

external exposureattack surface managementthird-party riskthreat intelmonitoring
External Exposure Assessments dashboard: thousands of companies scored by risk, each card showing exposure findings at a glance

1. Check tens of thousands of companies, fast

The ability to quickly upload 50,000+ companies and rapidly check them for:

  • whether there is an open mail relay
  • how vulnerable they are to phishing
  • whether there are leaks related to the company
  • whether there is active malware within the company
  • whether the company is mentioned on the dark web
  • how often companies like this are hacked
  • how interesting the company is to hacker groups, and whether there are mentions/orders related to it
  • what domains/services the company has, and how exposed/protected they are against common attacks - at a surface level, using semi-passive/passive methods without active scanning
  • basic compliance based on the data collected
  • final scoring, conclusions, findings
  • OSINT analysis

Analysis of a single company takes from a few seconds to a few minutes.

2. The "company" as an asset

All Pentesterra modules can essentially work autonomously with their own datasets, but they also share data with each other. In reality, one company may have several domains, CIDR ranges, and individual IP addresses - and all of them belong to the same company.

So External Exposure Assessments brings the results of different modules together into a single company-level view: what attacks the company is exposed to, which of its components/nodes are affected, whether the company has already been compromised, and how access could potentially be obtained - using which techniques and attacks.

Other Pentesterra modules can be involved: OSINT, DevGuard, vulnerability scanning, web app pentest, API pentest, phishing, and more. If a module has information, it will be available at the "company" level.

3. Near-real-time monitoring

Once companies are added, they are re-checked whenever the Knowledge Base data is updated - every few hours, or on manual launch.

4. Watching your contractors, suppliers, and clients

Without permissions for scanning or pentesting, and without waiting a long time for scans to complete.

5. Our outreach mechanism

Rapid analysis across an entire country within hours, notifications, and read/open tracking on reports.

Share on LinkedInhttps://pentesterra.com/blog/external-exposure-assessments-what-we-wanted

Take Control of Your Attack Surface.

Start with the free tier or talk to us about your environment - network, web, cloud, or on-prem.