Every internet-facing asset, every change, before the attacker finds it.
ShadowMap rediscovers your external attack surface every 24 hours — domains, subdomains, ports, services, mobile binaries, certificate changes, cloud exposures — and ranks each finding by what an attacker can actually do with it. No agents, no allowlists, no cooperation from the asset owner required.
Customers typically discover 30–60 % more external assets in the first scan than they had inventoried internally — including a few that turn out to be legacy, forgotten, and exploitable.
What it discovers
Discovers, prioritises, and routes — automatically.
Continuous discovery of external assets, ports, services, mobile apps, and cloud exposures — prioritised by exploitability.
Subdomain + DNS discovery
Passive + active enumeration across registrar, DNS, certificate transparency, and reverse-DNS sources. Catches the orphan subdomain marketing spun up last quarter.
Open ports + service banners
Daily port-scan with banner grabbing across the discovered surface. New service appearing on a known host = same-day alert.
Web app + API fingerprinting
Tech-stack detection on every web property. Knowing it's WordPress 6.2 vs 6.7 changes which CVEs matter.
Mobile app inventory
Continuous monitoring of Play Store, App Store, and side-loaded marketplaces for legitimate and impersonating apps that carry your name.
Cloud-storage exposures
Misconfigured S3, GCS, Azure Blob, and DigitalOcean Spaces buckets that match your asset graph.
Certificate + TLS posture
Expired, weak, or wildcard-leaking certificates flagged with renewal and remediation guidance.
Exploitability scoring
Each finding ranked by the joint signal of severity × exploit availability × your asset criticality. Makes triage finite.
Change diffing
Daily diffs surface the exact thing that changed — new port, new subdomain, new TLS cert — so you don't re-read yesterday's noise.
How it works
From seed to remediation, in four steps.
Seed
Start from your apex domain(s); ShadowMap fans out via passive + active discovery sources.
Map
Build a typed asset graph: domains → hosts → services → web apps → APIs → mobile apps → cloud resources.
Score
Each asset + finding scored by severity, exploit availability, and your business-context criticality.
Notify
New + changed exposures route to Slack, Jira, ServiceNow, Splunk, or whatever ticketing you already live in.
In the Platform
Composes with
ShadowMap modules share one asset graph. The signals from this module sharpen — and are sharpened by — the modules below.
Data Exposure
Code repositories, cloud buckets, paste sites, and document leaks — surfaced with secret scanning and ownership attribution.
BRP-01 · ExposureBrand Protection
Domain spoofs, social impersonation, phishing kits, and look-alike apps — detected and taken down before customers are hit.
VAL-01 · ValidationCART
Continuous attack & red team validation — exposures discovered upstream are exercised end-to-end so you know which ones actually matter.
See Attack Surface on your own assets.
A 30-minute live walk-through with a ShadowMap engineer on your own domains. We map you live; you keep the report whether or not you choose to engage.