External attack surface management

HebeGuard finds the domains, subdomains, IP addresses, cloud services and open ports your organization exposes to the internet, checks them for weaknesses attackers can use, and ranks what to fix first. It works from outside your network with no agents, and repeats the checks daily.

See it in the console
  • No agents to install
  • New assets found daily
  • One 0-100 risk score

What it finds

Domains and subdomains

Subdomains found through certificate transparency logs, passive DNS and enumeration, including sites nobody registered with IT.

IP addresses, ports and services

Reachable IP addresses, open ports and the services behind them, such as a database or remote login left open to the internet.

Exploitable vulnerabilities

Findings weighted by CVSS score, known active exploitation and public exploit availability, so the dangerous ones rise to the top.

TLS, DNS and email security

Expiring certificates, weak TLS, missing security headers, and SPF or DMARC gaps that let others send email as you.

Subdomain takeover risk

Dangling DNS records that still point to cloud services you no longer control.

Shadow IT and third parties

Services launched outside IT, and the third-party scripts and services your pages load.

In the console

Illustrative data from a demo tenant, shown as it appears in HebeGuard.

01Attack Surface

Every internet-facing asset, classified

HebeGuard discovers the subdomains, IPs, URLs and open ports anyone can reach from the public internet, including shadow IT nobody told security about. Each host shows live/dead status, TLS grade and the service banner an attacker would fingerprint first.

  • Subdomain, IP, URL and open-port discovery from passive + active sources
  • Live / dead status and per-host TLS grade (A+ → F)
  • Service and version fingerprints with an open-vs-filtered port map
  • Subdomain takeover detection for dangling DNS records
globex-demo.test
Attack Surface · Completed 31/08/2026 16:18:12
16 issues
02Recon & DNS

DNS, TLS and hosting, mapped to attack paths

WHOIS, DNS records, the full TLS certificate chain and hosting details, turned into the concrete routes an outsider could take from the open internet to a compromised host.

  • WHOIS, DNS records, nameservers and registration history
  • SSL/TLS certificate monitoring: full chain, grade, cipher flags and expiry countdown
  • Infrastructure correlated into ranked, outsider-reachable attack paths
globex-demo.test
Recon & DNS · Completed 31/08/2026 16:18:12
3 attack paths
03Vulnerabilities

Vulnerabilities ranked by real-world exploitability

Findings are ranked by CVSS severity, known active exploitation and public-exploit availability, then matched with CVE data for your detected stack. Secrets exposed in the same crawl, such as API keys, show up here too.

  • Findings scored by CVSS × exploitability, with confirmed / suspected status
  • CVE intelligence and known-exploited flags mapped to your tech stack
  • Exposed API keys and secrets surfaced from the same crawl
globex-demo.test
Vulnerabilities · Completed 31/08/2026 16:18:12
26 findings

How it works

  1. 01

    Start from your domain

    Give us a domain name. Nothing is installed and no firewall rules change.

  2. 02

    Discover

    HebeGuard maps the subdomains, IP addresses, ports, certificates and cloud services that belong to you.

  3. 03

    Validate and rank

    Findings are checked, deduplicated and weighted by severity, exploitability and exposure into one 0-100 risk score.

  4. 04

    Monitor daily

    Discovery repeats daily, so new assets and new exposures are flagged as they appear. Reports export as PDF, XLS or STIX 2.1.

Who it is for

Security teams

An outside-in inventory that stays current between penetration tests and audits.

MSSPs and vCISOs

A multi-tenant Client Portal: each client gets its own tenant, users and branded reports.

Regulated companies

A risk score mapped to ISO 27001 and PCI-DSS control families, with reports you can hand to auditors.

FAQ

What is attack surface management?

Attack surface management (ASM) is the continuous work of finding everything your organization exposes to the internet and fixing the riskiest items first. External attack surface management (EASM) looks at it from outside, the way an attacker does: domains, subdomains, IP addresses, cloud services, open ports and leaked credentials.

How is attack surface management different from vulnerability management?

A vulnerability scanner checks the targets you give it. Attack surface management starts from your domain name, finds the assets first, including ones missing from your inventory, and then checks them. The two work well together, because ASM tells the scanner what to scan.

Does attack surface management replace penetration testing?

No. A penetration test (VAPT) is a deep, manual test of agreed targets, usually once a quarter or once a year. Attack surface management runs daily across all your external assets. Many teams use HebeGuard between tests and HebeSec’s VAPT service for depth.

How does attack surface management relate to exposure management and CTEM?

Continuous threat exposure management (CTEM) is a five-stage program: scope, discover, prioritize, validate and mobilize. Attack surface management is the discovery stage, and it feeds the other four. HebeGuard runs all five stages on your external assets in a daily cycle.

What should an attack surface management tool include?

Automatic asset discovery, continuous monitoring, vulnerability detection with clear priorities, and alerts when something new appears. HebeGuard adds dark web monitoring, brand monitoring and a 0-100 risk score in the same console.

How do we reduce our external attack surface?

Start with an accurate inventory, then remove what you no longer need: old subdomains, test servers, dangling DNS records and unused open ports. Patch the exposed services attackers can exploit first, fix weak TLS and missing security headers, and keep watching for new assets. HebeGuard handles the discovery and daily monitoring, and tells you which of these to do first.

Do we need to install anything?

No. HebeGuard works entirely from outside your network. You give us a domain and discovery starts.

We reply within one business day

See what an attacker can see of your company.

Send us your primary domain. We'll map your external attack surface and walk you through what we find.

sales@hebesec.com
What we'll cover
Asset inventoryExposure scoreValidated findingsDark-web hits
ISO 27001-alignedPCI-DSS-alignedNo agent