External Attack Surface Management

External attack Surface Management tools for discovering and securing internet-facing assets, domains, and exposed services.

Explore 68 curated cybersecurity tools, with 14,802+ visitors searching for solutions

FEATURED

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

NordVPN Logo

VPN service providing encrypted internet connections and privacy protection

Mandos Fractional CISO Services Logo

Fractional CISO services for B2B companies to accelerate sales and compliance

Get Featured

Feature your product and reach thousands of professionals.

Findomain Logo

A domain reconnaissance tool that automates subdomain discovery, port scanning, and monitoring with support for multiple data sources and notification integrations.

0
cnames Logo

A tool for taking a list of resolved subdomains and outputting any corresponding CNAMES en masse.

0
csprecon Logo

A tool to discover new target domains using Content Security Policy

0
WayMore Logo

A tool that finds more information about a given URL or domain by querying multiple data sources.

0
Internet-Wide Misconfiguration Scanner Logo

Scan the internet for publicly exposed network components

0
ScanCannon Logo

A Python-based tool for external attack surface discovery and reconnaissance across large-scale networks, focusing on IP address and subdomain enumeration.

0
ONYPHE Logo

ONYPHE is a cyber defense search engine that discovers exposed assets and provides real-time monitoring to identify vulnerabilities and potential risks.

0
Censys Logo

A search engine for the Internet of Things (IoT) that provides real-time information about connected devices.

0
Wigle Logo

WiGLE.net is a platform that collects and provides data on WiFi networks and cell towers, with over 1.3 billion networks collected.

0
assetfinder Logo

A command-line tool for discovering domains and subdomains related to a target domain during reconnaissance activities.

0
CloudBrute Logo

A black-box reconnaissance tool that discovers cloud infrastructure, files, and applications across major cloud providers for security testing purposes.

0
GrayHatWarfare Buckets Logo

A search engine for open Amazon S3 buckets and their contents, allowing users to search for files using keywords, filename extensions, and full path.

0
Cloud_enum Logo

Cloud_enum is a multi-cloud OSINT tool that enumerates publicly accessible resources across AWS, Azure, and Google Cloud platforms for security assessment purposes.

0
Turbolist3r Logo

A Python-based tool for subdomain enumeration and analysis

0
CloudJack Logo

CloudJack identifies subdomain hijacking vulnerabilities in AWS accounts by detecting misconfigurations between Route53 DNS aliases and CloudFront distributions.

0
AttackSurfaceMapper Logo

Automate your reconnaissance process with AttackSurfaceMapper, a tool for mapping and analyzing network attack surfaces.

0
OWASP Amass Logo

Performs network mapping of attack surfaces and external asset discovery using open source information gathering and active reconnaissance techniques.

0
PublicWWW Logo

A source code search engine for searching alphanumeric snippets, signatures, or keywords in web page HTML, JS, and CSS code.

0
FullHunt Logo

FullHunt is a next-generation attack surface security platform that enables companies to discover, monitor, and secure their external attack surfaces.

0
massdns Logo

A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration)

0
altdns Logo

A tool for generating permutations, alterations and mutations of subdomains and resolving them

0
SpiderFoot Logo

Automate OSINT for threat intelligence and attack surface mapping with SpiderFoot.

0
Hijagger Logo

A tool that checks for hijackable packages in NPM and Python Pypi registries

0
Scilla Logo

An information gathering tool for DNS, subdomains, ports, and directories enumeration.

0