Skip to content
RU
External exposure

A database port opened on a host you forgot you had

Nobody told you. Attack Surface lists every hostname under your domain, what each resolves to, which ports accept a connection, what the TLS listener presents and which sensitive paths answer — and tells you the day any of it changes.

Three hosts on the free plan. No card required — a DNS record or a file is, to prove the domain is yours.

Nothing runs until you prove it is yours

Listing hostnames from public certificate logs touches nobody. Connecting to a port does. So every active check waits for one TXT record or one file on your apex — the same proof a registrar would ask for. Port-scanning somebody else's hosts on your word is not a service we sell.

Reachable, not "vulnerable"

We see that port 3306 accepts a connection. We do not try a password, send a command or read a banner, so we cannot know whether anyone could get in — and we do not pretend to. Every finding names what is exposed and stops there. The top severity is never used.

Silence is not "nothing exposed"

A port that never answered is not a closed port. A handshake that timed out is not "no TLS". A bot wall's headers are not your server's. Each of those is listed as "could not check", left out of the score, and never allowed to close an earlier finding.

How it works

Discovery is passive and free

Certificate Transparency logs and passive DNS know your hostnames before you do — dev, staging, the old shop, the subdomain a contractor left behind. They are read, never contacted, and do not count against your plan.

Probing is a fixed, small set of questions

Two dozen well-known TCP ports, one TLS handshake, one page fetch for its headers, one pass over a fixed catalogue of paths that should never answer, and a look in ten blocklists. No banner grabbing, no version guessing, no path guessing, no exploit. What we send is a connection; what we keep is the answer, never a body.

The score leaves out what it could not measure

Exposure is 0–100 per host, from six check classes with published weights. A class the probe could not complete is left out of both sides of the arithmetic — never scored as clean, never as failed. The breakdown that travels with the number says which classes were measured.

The change is the news

A hostname that appeared, a port that opened, a path that started answering, a certificate that changed. A hundred hosts that look like last week are not news and do not send a message.

What it does not do

  • It does not exploit, guess passwords, brute-force, or run any payload. It is an inventory, not a penetration test, and it says so on every screen.
  • It does not scan domains you have not proved you own. Discovery from public logs is the only thing that runs before the proof.
  • It does not tell you a version is vulnerable. It may tell you a port is reachable; what listens behind it and whether it is patched is yours to know.