Know If You're Already Compromised Before an Attacker Tells You
Continuously track your organization's - and your suppliers' - external footprint against live threat intelligence: botnet/C2 infrastructure, malicious TLS certificates, IP reputation, and ransomware leak-site listings. Agentless, mostly passive, no active exploitation required.
Continuous Threat-Intel Monitoring vs. Manual Vendor Review
| Dimension | Manual / Questionnaire-Based | Pentesterra External Exposure |
|---|---|---|
| Discovery scope | One domain you already know about | Full IP-space from a domain, IP, or CIDR |
| Compromise detection | Manual OSINT / vendor questionnaires | Continuous cross-reference against a live threat-intel KB |
| Breach signal | Found by chance, months later | Ransomware leak-site correlation, flagged for review |
| Freshness | Re-checked only at renewal / annual review | Auto-rechecked the moment the KB updates |
| Footprint | Your domains only | Your domains and your suppliers', same workflow |
How External Exposure Assessments Work
IP-Space & Footprint Discovery
Give it a domain, an IP, or a CIDR block. Pentesterra resolves your organization's real IP-space and every asset tied to it - so shadow subdomains, forgotten hosts, and third-party/supplier assets surface before someone else finds them.
- →Accepts domains, individual IPs, and CIDR ranges as scan input
- →Agentless - passive checks by default, active checks opt-in
- →DNS/email hygiene, TLS, headers, cookies, WAF/CDN detection
- →Same engine covers your own domains and your suppliers'
Compromise-Indicator Monitoring
Every tracked domain and IP is cross-checked against a continuously updated threat-intel KB - not a one-time lookup. New sources land in the KB on their own schedule and every existing target benefits immediately.
- →Known C2 / botnet infrastructure (Feodo Tracker, IPsum)
- →Malicious TLS certificate fingerprints (SSLBL)
- →Aggregated IP-reputation blocklists, cross-list corroborated
- →Open-relay / phishing-relay abuse checks on mail infrastructure
Ransomware & Leak-Site Correlation
Tracked organizations and suppliers are correlated against ransomware-gang leak-site listings - the highest-signal public indicator that a company was actually breached, published by the attackers themselves.
- →RansomLook leak-site feed, updated continuously
- →Name-match surfaced as an explicit "unconfirmed, verify" flag
- →Human confirm/reject workflow - never an automatic false alarm
- →Group, sector, and leak-site listing date included as evidence
Always-On Rechecking, Not Point-in-Time
A scan result is a snapshot; a threat feed keeps moving. When the KB picks up a new indicator, every already-tracked target is automatically re-checked against it - no need to wait for the next scheduled scan.
- →Automatic backfill against already-added targets on every feed update
- →Notification the moment a new match is found for a tracked target
- →Rescans and settings changes never delete prior scan history
- →Read-only Threat Intel KB browser - see what's actually being collected
What this can't see - stated plainly
If a target only exposes a domain that sits behind NAT, a proxy, or a CDN, an infected host inside that organization's internal network is invisible to any external scan - no amount of IP-space discovery changes that. This is a fast, mostly passive external-exposure check, not a substitute for an internal network assessment; we'd rather say so than imply broader coverage than actually exists.
Frequently Asked Questions
Does this require installing anything on the target?
No. External Exposure Assessments run agentless, mostly passive checks (DNS, TLS, headers, cookies, WAF/CDN fingerprinting) with any active check strictly opt-in, following the same attestation model as the rest of the platform.
Can I track my suppliers and third parties, not just my own domains?
Yes. The same domain/IP/CIDR input and the same threat-intel cross-reference apply whether the target is your own infrastructure or a third-party supplier - one workflow, business-criticality tagged per target.
What happens when a new threat-intel source is added?
Already-tracked targets are automatically re-checked against newly ingested indicators - you don't need to trigger a fresh scan to find out a target is now a match. You're notified as soon as one is found.
How is a ransomware-victim match verified before I see it?
Name correlation against leak-site listings is surfaced as an explicit, clearly labeled "unconfirmed match - verify manually" item, not scored as a confirmed finding - avoiding false positives from companies that share a common name.