EXTERNAL EXPOSURE ASSESSMENTS

Know If a Company Is Already Compromised Before You Do Business With It

Import a whole sector, supplier book, or country and triage every company in seconds to minutes each - exposure, compromise indicators, threat-actor interest, a compliance baseline, and OSINT, aggregated from every Pentesterra module that has evidence on it. Agentless, mostly passive, no scanning authorization required to start.

50,000+
Companies importable and triaged in a single batch
Agentless
Nothing installed on your - or your suppliers' - infrastructure
24/7
Automatic recheck when the threat-intel KB updates

Continuous Threat-Intel Monitoring vs. Manual Vendor Review

DimensionManual / Questionnaire-BasedPentesterra External Exposure
ScaleOne vendor questionnaire at a time50,000+ companies, seconds to minutes each
Discovery scopeOne domain you already know aboutFull domain/IP/CIDR footprint, cross-module evidence included
Compromise detectionManual OSINT / vendor questionnairesContinuous cross-reference against a live threat-intel KB
Breach signalFound by chance, months laterRansomware leak-site + breach-news correlation, flagged for review
FreshnessRe-checked only at renewal / annual reviewAuto-rechecked the moment the KB updates
Cross-module viewEvery finding lives in a separate tool/reportOne company record aggregates OSINT, DevGuard, VM, Pentest, Phishing
Authorization neededScanning/pentest sign-off before you can startPassive/semi-passive - no authorization required to begin
FootprintYour domains onlyYour domains, your suppliers', your prospects' - same workflow

See It in the Product

External Exposure Assessments KPI dashboard showing thousands of tracked targets by risk tier, with a live organization-wide scan progress indicator and cancel control
Every tracked company broken down by risk tier, coverage, compromise indicators, and outreach status - with a live, organization-wide view of scans currently in progress and a one-click way to stop them.
Company detail page showing Security Coverage across External Exposure, Web Pentest, Vulnerability Management, OSINT and DevGuard, plus compliance evidence coverage across NIS2, GDPR, DORA, ISO 27001 and other frameworks
One company, every module's evidence - Security Coverage across External Exposure, Web Pentest, Vulnerability Management, OSINT and DevGuard, plus a compliance evidence baseline across the frameworks that matter.
Scan settings panel showing opt-in Safe Active checks: WAF detection, CDN/cloud hosting detection, mail relay check, exposed VPN/firewall portal detection, employee infostealer exposure check, and contact email discovery
Every active check is opt-in and explained plainly - what it does, why it's safe - with an explicit authorization confirmation before anything beyond passive checks runs.

How External Exposure Assessments Work

Bulk Triage, Not One Domain at a Time

Import 50,000+ companies in one pass - a whole sector, a whole customer/supplier book, a whole country. Each one gets checked in seconds to a few minutes, not the days a manual review or a full pentest would take, so you can find the handful worth a deeper look before committing real engagement time.

  • Bulk CSV import, batch scanning at real scale, no artificial per-request cap
  • Per company: exposure, compromise, compliance, OSINT - one pass
  • Filter thousands down to "high risk", "not yet scanned", "confirmed compromise"
  • Progress tracked server-side, visible and cancellable from any session

Compromise & Threat-Actor-Interest Signals

Beyond "is a port open" - is this company already compromised, or actively interesting to attackers right now. Every tracked target is cross-checked against a continuously updated threat-intel KB, not a one-time lookup.

  • Open mail relay, phishing susceptibility, known-malware indicators
  • Employee credential/session exposure from infostealer logs
  • Ransomware leak-site and breach-news correlation, human-verified before it's shown as confirmed
  • Darknet/criminal-forum mention signal - is this company being discussed or targeted

One Company, Every Module's Evidence

A company can have several domains, IP ranges, and CIDR blocks, and evidence about it can come from anywhere in the platform - OSINT, DevGuard, Vulnerability Scanning, Web/API Pentest, Phishing Simulation. External Exposure Assessments is the layer that pulls it all together under one company record, without requiring any of those modules to run differently or duplicate their own results.

  • Per-module coverage shown explicitly: assessed, not yet assessed, never silently blank
  • Drill straight through from a company summary to the underlying module's own evidence
  • Web Pentest and Vulnerability Management findings feed the company's exposure score, not just its own passive scan
  • Modules stay fully independent - nothing here changes how they operate on their own

Attack Surface, Checked the Passive Way

Domains and services are checked against common attack classes using passive and semi-passive methods - no active exploitation, no port-scanning noise on infrastructure you don't operate. Enough signal to prioritize, without needing scanning authorization from a third party first.

  • DNS/email hygiene, TLS, security headers, cookies, WAF/CDN/cloud fingerprinting
  • Opt-in safe-active checks (VPN/firewall portal exposure, open-relay test) - never on by default
  • Same engine covers your own domains and your suppliers' or prospects'
  • Explicit about what a passive check cannot see - never implied broader coverage than it has

Compliance Baseline From Real Evidence

A baseline compliance read generated from what was actually found - not a self-attested questionnaire. One-click evidence reports for the frameworks that matter, control by control, with an explicit note wherever something simply can't be evidenced externally.

  • NIS2, DORA, GDPR, ISO 27001, NIST CSF, SOC 2, CMMC, PCI DSS, TISAX ISA coverage
  • One-click per-supplier PDF evidence pack, built for the auditor's actual question
  • Coverage percentage shown honestly - a compliance signal, not a compliance certification
  • Never a legal conclusion from country/industry alone - always overridable

Monitoring and Outreach, Not a Point-in-Time Report

A scan result is a snapshot; a threat feed keeps moving. Every tracked company is automatically re-checked when the KB updates - every few hours, or on demand - and the same infrastructure powers fast, country- or sector-wide outreach with delivery and read/open tracking.

  • Automatic backfill against every already-tracked company on every feed update
  • Notification the instant a new compromise indicator matches a tracked company
  • Batch outreach notices with per-recipient open/click tracking
  • A whole country or sector analyzed and notified within hours, not weeks

What this can't see - stated plainly

If a target only exposes a domain that sits behind NAT, a proxy, or a CDN, an infected host inside that organization's internal network is invisible to any external scan - no amount of IP-space discovery changes that. This is a fast, mostly passive external-exposure check, not a substitute for an internal network assessment; we'd rather say so than imply broader coverage than actually exists.

Frequently Asked Questions

Does this require installing anything on the target?

No. External Exposure Assessments run agentless, mostly passive checks (DNS, TLS, headers, cookies, WAF/CDN fingerprinting) with any active check strictly opt-in, following the same attestation model as the rest of the platform.

Can I track my suppliers and third parties, not just my own domains?

Yes. The same domain/IP/CIDR input and the same threat-intel cross-reference apply whether the target is your own infrastructure or a third-party supplier - one workflow, business-criticality tagged per target.

What happens when a new threat-intel source is added?

Already-tracked targets are automatically re-checked against newly ingested indicators - you don't need to trigger a fresh scan to find out a target is now a match. You're notified as soon as one is found.

How is a ransomware-victim match verified before I see it?

Name correlation against leak-site listings is surfaced as an explicit, clearly labeled "unconfirmed match - verify manually" item, not scored as a confirmed finding - avoiding false positives from companies that share a common name.

How large a batch can I actually run?

Tens of thousands of companies in one import. Batch scanning has no artificial per-request cap, dispatches in the background across however many scanner nodes are available, and progress is tracked server-side - visible and cancellable from any session in your organization, not just the browser tab that started it.

Does this replace the results already in my other Pentesterra modules?

No. Web Pentest, Vulnerability Management, DevGuard, OSINT, and Phishing Simulation each remain the system of record for their own evidence. External Exposure Assessments aggregates and correlates what those modules already found under one company record - it doesn't duplicate or replace their results, and a module's own results page still works exactly as it always has.

Take Control of Your Attack Surface.

Start with the free tier or talk to us about your environment - network, web, cloud, or on-prem.