Managed service · Attack Surface Monitoring

Your attack surface changes. We keep it in view all year round.

Your external attack surface shifts with every migration, every new service and every supplier. Continuous discovery from the outside, ongoing assessment and alerts on new risks — non-invasive and operated by us.

Operated by Graydaxe · non-invasive · data processed in the EU
ATTACK SURFACE — CHANGES IN THE LAST 7 DAYS
shop-staging.example.comNewly discovered · reachable for two days
New
m.example.comNew vulnerability · known exploited
Critical
vpn.example.comCertificate expires in nine days
Change
example.comThree credentials in a new data leak
High
Illustrative example · fictitious values · no customer data

What the service does

Discover, attribute, report.

Continuous discoveryNew domains, subdomains, IP addresses, services and cloud resources — found as soon as they become reachable from outside.
Attribution, not guessworkEvery asset is attributed to your company and validated before it enters the assessment.
Changes with historyWhat appears, what disappears, what changes — traceable over time instead of a single snapshot.
Risks with contextPrioritisation by real exploitability: EPSS, CVSS, known exploited vulnerabilities (KEV) and exploit data.
Leaked credentialsCredentials tied to your domains that surface in data leaks — reported as soon as they become known.
Suppliers on requestOn request we also monitor the external attack surface of critical suppliers — relevant for NIS2 Art. 21(2)(d).

How to get it

Three routes, one data basis.

The same discovery, the same assessment — you decide whether you want a report, the ongoing service or access to the platform.

ONE-OFF

External Attack Surface Assessment

A snapshot with a result report for management, the security team and audit — with no ongoing contract. The usual way in.

To the attack surface assessment →
MANAGED SERVICE

Attack Surface Monitoring

We run the monitoring for you: onboarding, ongoing assessment, regular reports and alerts. No security department of your own required.

SAAS

Platform access

For teams that want to run the monitoring themselves. Please talk to us about availability and terms.


What you get

We run it. You get results.

  • Onboarding: discovery and attribution of your externally reachable assets, reconciliation with your inventory, definition of the scope
  • Ongoing re-discovery of the confirmed assets and comparison against the last state
  • Reports with the asset inventory, new and closed findings, prioritisation by EPSS, CVSS and KEV, and the trend over time
  • Alerts on new discoveries, status changes and leaked credentials
  • Review sessions to walk through and prioritise findings with your team

Reporting frequency, assessment depth and alerting follow the agreed service level.


And before that?

No baseline yet?

Onboarding captures your assets in any case. Many companies still start with the one-off assessment: it delivers a report that management, the security team and an auditor can work from — and a documented baseline against which the ongoing service can be measured.

To the attack surface assessment →

FAQ

Frequently asked questions

Do we need a security team of our own?

No. We run the monitoring. You receive reports and alerts and discuss the results with us.

How does the monitoring access our systems?

It does not. Discovery happens from the outside and non-invasively: no exploitation of vulnerabilities, no credentials, no access to your internal network.

What does the service cost?

Scope and service level depend on the number of validated assets and are agreed separately. We provide the pricing and billing model on request.

Can subsidiaries and suppliers be included?

Yes. We define entities and their domains during onboarding. On request we monitor the external attack surface of critical suppliers as well.


Let us talk about your scope.

Tell us the domains you want monitored. From those we determine the externally reachable assets and propose a scope and service level.