Know If a Company Is Already Compromised Before You Do Business With It
Import a whole sector, supplier book, or country and triage every company in seconds to minutes each - exposure, compromise indicators, threat-actor interest, a compliance baseline, and OSINT, aggregated from every Pentesterra module that has evidence on it. Agentless, mostly passive, no scanning authorization required to start.
Continuous Threat-Intel Monitoring vs. Manual Vendor Review
| Dimension | Manual / Questionnaire-Based | Pentesterra External Exposure |
|---|---|---|
| Scale | One vendor questionnaire at a time | 50,000+ companies, seconds to minutes each |
| Discovery scope | One domain you already know about | Full domain/IP/CIDR footprint, cross-module evidence included |
| Compromise detection | Manual OSINT / vendor questionnaires | Continuous cross-reference against a live threat-intel KB |
| Breach signal | Found by chance, months later | Ransomware leak-site + breach-news correlation, flagged for review |
| Freshness | Re-checked only at renewal / annual review | Auto-rechecked the moment the KB updates |
| Cross-module view | Every finding lives in a separate tool/report | One company record aggregates OSINT, DevGuard, VM, Pentest, Phishing |
| Authorization needed | Scanning/pentest sign-off before you can start | Passive/semi-passive - no authorization required to begin |
| Footprint | Your domains only | Your domains, your suppliers', your prospects' - same workflow |
See It in the Product
How External Exposure Assessments Work
Bulk Triage, Not One Domain at a Time
Import 50,000+ companies in one pass - a whole sector, a whole customer/supplier book, a whole country. Each one gets checked in seconds to a few minutes, not the days a manual review or a full pentest would take, so you can find the handful worth a deeper look before committing real engagement time.
- →Bulk CSV import, batch scanning at real scale, no artificial per-request cap
- →Per company: exposure, compromise, compliance, OSINT - one pass
- →Filter thousands down to "high risk", "not yet scanned", "confirmed compromise"
- →Progress tracked server-side, visible and cancellable from any session
Compromise & Threat-Actor-Interest Signals
Beyond "is a port open" - is this company already compromised, or actively interesting to attackers right now. Every tracked target is cross-checked against a continuously updated threat-intel KB, not a one-time lookup.
- →Open mail relay, phishing susceptibility, known-malware indicators
- →Employee credential/session exposure from infostealer logs
- →Ransomware leak-site and breach-news correlation, human-verified before it's shown as confirmed
- →Darknet/criminal-forum mention signal - is this company being discussed or targeted
One Company, Every Module's Evidence
A company can have several domains, IP ranges, and CIDR blocks, and evidence about it can come from anywhere in the platform - OSINT, DevGuard, Vulnerability Scanning, Web/API Pentest, Phishing Simulation. External Exposure Assessments is the layer that pulls it all together under one company record, without requiring any of those modules to run differently or duplicate their own results.
- →Per-module coverage shown explicitly: assessed, not yet assessed, never silently blank
- →Drill straight through from a company summary to the underlying module's own evidence
- →Web Pentest and Vulnerability Management findings feed the company's exposure score, not just its own passive scan
- →Modules stay fully independent - nothing here changes how they operate on their own
Attack Surface, Checked the Passive Way
Domains and services are checked against common attack classes using passive and semi-passive methods - no active exploitation, no port-scanning noise on infrastructure you don't operate. Enough signal to prioritize, without needing scanning authorization from a third party first.
- →DNS/email hygiene, TLS, security headers, cookies, WAF/CDN/cloud fingerprinting
- →Opt-in safe-active checks (VPN/firewall portal exposure, open-relay test) - never on by default
- →Same engine covers your own domains and your suppliers' or prospects'
- →Explicit about what a passive check cannot see - never implied broader coverage than it has
Compliance Baseline From Real Evidence
A baseline compliance read generated from what was actually found - not a self-attested questionnaire. One-click evidence reports for the frameworks that matter, control by control, with an explicit note wherever something simply can't be evidenced externally.
- →NIS2, DORA, GDPR, ISO 27001, NIST CSF, SOC 2, CMMC, PCI DSS, TISAX ISA coverage
- →One-click per-supplier PDF evidence pack, built for the auditor's actual question
- →Coverage percentage shown honestly - a compliance signal, not a compliance certification
- →Never a legal conclusion from country/industry alone - always overridable
Monitoring and Outreach, Not a Point-in-Time Report
A scan result is a snapshot; a threat feed keeps moving. Every tracked company is automatically re-checked when the KB updates - every few hours, or on demand - and the same infrastructure powers fast, country- or sector-wide outreach with delivery and read/open tracking.
- →Automatic backfill against every already-tracked company on every feed update
- →Notification the instant a new compromise indicator matches a tracked company
- →Batch outreach notices with per-recipient open/click tracking
- →A whole country or sector analyzed and notified within hours, not weeks
What this can't see - stated plainly
If a target only exposes a domain that sits behind NAT, a proxy, or a CDN, an infected host inside that organization's internal network is invisible to any external scan - no amount of IP-space discovery changes that. This is a fast, mostly passive external-exposure check, not a substitute for an internal network assessment; we'd rather say so than imply broader coverage than actually exists.
Frequently Asked Questions
Does this require installing anything on the target?
No. External Exposure Assessments run agentless, mostly passive checks (DNS, TLS, headers, cookies, WAF/CDN fingerprinting) with any active check strictly opt-in, following the same attestation model as the rest of the platform.
Can I track my suppliers and third parties, not just my own domains?
Yes. The same domain/IP/CIDR input and the same threat-intel cross-reference apply whether the target is your own infrastructure or a third-party supplier - one workflow, business-criticality tagged per target.
What happens when a new threat-intel source is added?
Already-tracked targets are automatically re-checked against newly ingested indicators - you don't need to trigger a fresh scan to find out a target is now a match. You're notified as soon as one is found.
How is a ransomware-victim match verified before I see it?
Name correlation against leak-site listings is surfaced as an explicit, clearly labeled "unconfirmed match - verify manually" item, not scored as a confirmed finding - avoiding false positives from companies that share a common name.
How large a batch can I actually run?
Tens of thousands of companies in one import. Batch scanning has no artificial per-request cap, dispatches in the background across however many scanner nodes are available, and progress is tracked server-side - visible and cancellable from any session in your organization, not just the browser tab that started it.
Does this replace the results already in my other Pentesterra modules?
No. Web Pentest, Vulnerability Management, DevGuard, OSINT, and Phishing Simulation each remain the system of record for their own evidence. External Exposure Assessments aggregates and correlates what those modules already found under one company record - it doesn't duplicate or replace their results, and a module's own results page still works exactly as it always has.


