Vorpcel // Attack Surface Management

See your attack surface
the way an attacker does.

Attack Surface Management continuously maps everything you expose to the internet - domains, subdomains, certificates, services - and checks each one for posture gaps and real exposures. Continuous, not a once-a-quarter scan, and every finding comes with the evidence behind it.

active new exposed
What it does

You can't defend what you don't know you have.

Forgotten subdomains, an expiring certificate, an exposed .env file, a dangling DNS record ripe for takeover - the surface an attacker probes is bigger than the one you track in your head. Attack Surface Management discovers it, watches it continuously, and flags what is exposed. Every check is deterministic and evidence-backed, so alerts stay focused on real problems.

01

Discovery

Find the domains, subdomains, IPs, services and certificates you expose - including the ones nobody remembered - from DNS, certificate transparency and active resolution.

02

Posture & exposure

Email authentication, TLS and certificates, security headers, cookies, DNS hygiene - plus real exposures: leaked files, subdomain takeover, open buckets and exposed APIs.

03

Continuous monitoring

Re-checked on your schedule, from hourly to weekly. New assets and new findings surface as they appear, and a fixed issue resolves itself automatically.

§ Discovery

Map everything you expose to the internet.

Give us a domain. We enumerate its subdomains, pull hostnames from public certificate transparency logs, resolve what is live, and track every asset over time - so a new host that appears next month shows up on its own, and one that disappears is marked gone.

Subdomain & CT-log discovery
Curated DNS enumeration plus certificate-transparency mining find the hosts you never inventoried.
Change tracking
Every asset carries a first-seen and last-seen date; new surface is a first-class event.
Services & certificates
Reachable services and the certificates behind them, catalogued alongside each host.
Discovered assetsexample.com
api.example.com
A · first-seen 04-12
active
mail.example.com
25/tcp · first-seen 04-12
active
cdn.example.com
CNAME · first-seen 05-03
active
staging.example.com
ct-log · first-seen 07-18
new
legacy.example.com
dangling CNAME
takeover
§ Posture & exposure

Posture gaps and real exposures, side by side.

Every discovered asset is checked against objective criteria. Some findings are posture - a weak TLS config, a missing email record - and some are live exposures an attacker can use today. Each is confirmed by evidence, so what you triage is real.

Posture gapsEmail, TLS, DNS, headers
SPF / DMARC missingmedium
Certificate expires in 9 daysmedium
Security headersreview
Weak cookie flagsreview
Confirmed exposuresUsable by an attacker today
Exposed .git repositoryhigh
Subdomain takeoverhigh
Publicly-listable buckethigh
Leaked secret in JavaScripthigh
Email, TLS & DNS posture
SPF/DMARC/DKIM/DNSSEC, certificate expiry and protocol, zone transfer, CAA and wildcard checks.
Headers, cookies & tech
Missing security headers, weak cookie flags and version-disclosing banners across the surface.
Confirmed exposures
Exposed .git/.env and backups, subdomain takeover, publicly-listable cloud buckets, leaked secrets in JavaScript and exposed API specs - each signature-confirmed.
Posture score · example.comC
Re-checked every 6 hours.68 / 100
§ Continuous

Continuous, not a snapshot.

A one-off pentest is out of date the day after it lands. Attack Surface Management re-checks your surface on a schedule you set, rolls everything into a single posture score, and resolves a finding automatically once the underlying issue is gone - so the number always reflects reality.

One posture score, A to F
Every finding rolls into a single grade that moves as your team resolves issues.
Self-resolving findings
A finding auto-resolves when a check stops reporting it, and reopens if it regresses - no stale alerts to chase.
Correlated with your edge
The same platform that runs your WAF and Outbound Control, so surface, requests and responses live in one place.
§ How it works

Add a domain, and the surface maps itself.

01

Add a domain

Point us at a domain you own. Nothing to install - discovery works from the outside, like an attacker.

02

We map & check it

The engine discovers your assets and runs every posture and exposure check, then keeps doing it on your schedule.

03

Triage with context

Each finding carries its asset, evidence and severity. Fix it and it resolves on its own; leadership watches one score.

Start now

Know your attack surface
before someone else does.

Free trial, no credit card required. Add a domain and watch your surface map itself in the dashboard.