External Attack Surface Management

External attack Surface Management tools for discovering and securing internet-facing assets, domains, and exposed services.

Explore 68 curated cybersecurity tools, with 14,802+ visitors searching for solutions

FEATURED

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

NordVPN Logo

VPN service providing encrypted internet connections and privacy protection

Mandos Fractional CISO Services Logo

Fractional CISO services for B2B companies to accelerate sales and compliance

Get Featured

Feature your product and reach thousands of professionals.

Pentera Surface Logo

Pentera Surface is an external attack surface management platform that continuously maps, monitors, and validates web-facing assets through automated reconnaissance and safe exploitation testing.

-1
ZeroFOX Platform Logo

ZeroFox Platform is a unified external cybersecurity solution that helps organizations identify, monitor, and remediate threats across social media, surface web, deep web, and dark web environments.

0
Axur Platform Logo

A comprehensive external cybersecurity platform that combines AI and human expertise to detect, analyze, and remediate threats outside the traditional security perimeter including brand impersonation, data leakage, and digital asset exposure.

0
ZeroFox EASM Logo

A solution that discovers, analyzes, and helps remediate vulnerabilities across an organization's external digital attack surface by identifying and monitoring internet-facing assets.

0
ImmuniWeb® Discovery Logo

ImmuniWeb Discovery is an attack surface management platform that continuously monitors an organization's external digital assets for security vulnerabilities, misconfigurations, and threats across domains, applications, cloud resources, and the dark web.

0
BeVigil Enterprise Logo

An attack surface management platform that discovers, maps, and monitors an organization's external digital assets to identify vulnerabilities and security weaknesses before they can be exploited.

0
Recorded Future Logo

A threat intelligence platform that provides comprehensive visibility into an organization's attack surface by collecting, analyzing, and structuring threat data to enable proactive security measures against emerging threats.

0
s3viewer Logo

A storage exploration tool that provides unified access to view publicly accessible Amazon S3 buckets, Azure Blob storage, FTP servers, and HTTP directory listings.

0
as3nt Logo

A tool for enumerating subdomains of a given domain

0
GitRob Logo

A reconnaissance tool for GitHub organizations

0
censys-enumeration Logo

A script to extract subdomains/emails for a given domain using SSL/TLS certificate dataset on Censys.

0
python-builtwith Logo

A Python API client for BuiltWith that enables programmatic access to website technology profiling and reconnaissance data.

0
2tearsinabucket Logo

A tool for enumerating and analyzing Amazon S3 buckets associated with specific targets to identify potential security misconfigurations.

0
HostileSubBruteforcer Logo

A tool for bruteforcing subdomains of a given domain

0
censys-subdomain-finder Logo

A tool for performing subdomain enumeration using Censys API

0
SubOver Logo

A powerful tool for finding and exploiting subdomain takeover vulnerabilities

0
autoSubTakeover Logo

A tool to identify potential subdomain takeovers by checking if a CNAME record resolves to the scope address.

0
CloudScraper Logo

CloudScraper is an enumeration tool that discovers cloud storage resources including S3 buckets, Azure blobs, and DigitalOcean Spaces across target environments.

0
TypeError/domained Logo

A multi-tool for subdomain enumeration

0
S3BucketList Logo

A Chrome extension that automatically detects and lists Amazon S3 buckets while browsing websites.

0
Knock Logo

A subdomain scan tool that helps you find subdomains of a given domain.

0
crawley Logo

A Go-based web crawler that supports multiple protocols and authentication methods for systematic web resource discovery and collection.

0

Stay Updated with Mandos Brief

Get the latest cybersecurity updates in your inbox

POPULAR

RoboShadow Logo

A cybersecurity platform that offers vulnerability scanning, Windows Defender and 3rd party AV management, and MFA compliance reporting, among other features.

14
Mandos Brief Newsletter Logo

A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

7
CloudDefense.AI Logo

CloudDefense.AI is a Cloud Native Application Protection Platform (CNAPP) that safeguards cloud infrastructure and cloud-native apps with expertise, precision, and confidence.

7
Fabric Platform by BlackStork Logo

Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.

6
TestSavantAI Logo

Security platform that provides protection, monitoring and governance for enterprise generative AI applications and LLMs against various threats including prompt injection and data poisoning.

5
View Popular Tools →