Vorpcel // Attack Surface Management

Know your external assets.
Prioritize their exposure.

Discover domains, subdomains and exposed services, then assess their security posture on a recurring schedule. Attack Surface Management brings asset inventory, exposure findings and change history together to guide remediation.

active new exposed
What it does

Maintain visibility as your external surface evolves.

New deployments, DNS changes and third-party services can introduce exposure beyond the assets your team already tracks. Recurring discovery and security checks help identify overlooked hosts, configuration gaps and exposed resources, with evidence for review.

Discovery

Build an external asset inventory using DNS enumeration, certificate transparency and active resolution.

Posture & exposure

Assess email authentication, TLS, DNS and HTTP configuration alongside exposed files, public storage and takeover indicators.

Continuous monitoring

Schedule recurring checks and track new findings, resolution and recurrence across monitored assets.

Discovery

Build an inventory of your internet-facing assets.

Start with the domains in your scope. Discovery combines DNS and certificate data to identify associated hosts, record reachable assets and track their first and most recent observations.

Subdomain & CT-log discovery
Identify associated hostnames through DNS enumeration and public certificate records.
Change tracking
Compare first-seen and last-seen observations to investigate changes in asset visibility.
Services & certificates
Review service and certificate information alongside the assets it belongs to.
Discovered assetsexample.com
api.example.com
A · first-seen 04-12
active
mail.example.com
25/tcp · first-seen 04-12
active
cdn.example.com
CNAME · first-seen 05-03
active
staging.example.com
ct-log · first-seen 07-18
new
legacy.example.com
dangling CNAME
Takeover risk
Posture & exposure

Assess configuration gaps and exposed resources.

Findings distinguish configuration weaknesses from exposure indicators and include the observed evidence. Review the affected asset and severity to decide which issues require immediate attention and which belong in planned remediation.

Posture gapsEmail, TLS, DNS, headers
SPF / DMARC missingMedium
Certificate expires in 9 daysMedium
Security headersReview
Weak cookie flagsReview
Exposure findingsObserved indicators for investigation
Exposed .git repositoryHigh
Subdomain takeoverHigh
Publicly-listable bucketHigh
Leaked secret in JavaScriptHigh
Email, TLS & DNS posture
SPF/DMARC/DKIM/DNSSEC, certificate expiry and protocol, zone transfer, CAA and wildcard checks.
Headers, cookies & tech
Missing security headers, weak cookie flags and version-disclosing banners across the surface.
Exposure findings
Identify exposed repositories, environment files, backups, public buckets, JavaScript secrets and API descriptions using targeted checks.
Posture score · example.comC
Illustrative posture history.68 / 100
Continuous

Track posture throughout the remediation cycle.

Recurring assessments help validate remediation and identify regressions. Findings and posture grades update as checks complete, giving engineering a working queue and leadership a view of progress over time.

One posture score, A to F
Review the posture grade alongside the findings and observations behind it.
Self-resolving findings
Follow finding status across completed assessments, including automatic resolution and reopening when an issue recurs.
Exposure and protection in one platform
Review external posture alongside WAF and Outbound Control to coordinate application security work.
How it works

Define scope. Discover assets. Investigate findings.

Add a domain

Select an authorized domain and the monitoring scope for its external assets.

Discover and assess

Run discovery and the selected security checks, then repeat assessments on the configured schedule.

Triage with context

Review evidence, prioritize remediation and use subsequent assessments to track progress.

Start now

Make external exposure
part of your security operations.

Evaluate asset discovery, posture checks and finding workflows for your domains.