Vulnerability Management

External Attack SurfaceNew

Maps and monitors your complete external attack surface — domains, subdomains, open ports, exposed services, and SSL certificate health — giving you a continuous outside-in view of your organisation.

External Attack Surface

Know your perimeter before attackers do

What it does

Key capabilities

Domain & Subdomain Discovery

Continuously enumerates all domains and subdomains associated with your organisation, including forgotten assets.

Open Port Monitoring

Tracks every exposed port and service across your perimeter, flagging changes and unexpected exposures.

SSL/TLS Certificate Health

Monitors certificate validity, weak cipher suites, and TLS configuration issues before they become outages or vulnerabilities.

Technology Fingerprinting

Identifies web technologies, frameworks, and versions exposed externally to target CVE matching.

Change Detection

Alerts on new exposures or unexpected changes to your external footprint — ideal for catching shadow IT.

Asset Timeline

Historical record of every change to your external attack surface for investigation and audit purposes.

Highlights

Why External Attack Surface?

  • Complete outside-in view of your digital perimeter
  • Catches shadow IT and forgotten internet-exposed assets
  • SSL certificate expiry alerts before they cause incidents
  • Change detection fires on new exposures immediately
  • Feeds findings into Vulnerability Manager for tracking
Included in OneView

External Attack Surface is part of the Hakware OneView platform. All findings, events, and data from this module flow into your central dashboard alongside every other security signal in your environment.

24/7 Support Available
Phone: +27 060 984 1210
FAQs

Frequently asked questions

External Attack Surface continuously enumerates all subdomains associated with your registered domains, including ones your team may have forgotten — staging environments, old product portals, test servers, and acquired company domains. Every discovered asset is monitored for open ports, exposed services, and SSL certificate health.

Monitoring runs continuously — new subdomains and newly exposed ports are detected as part of ongoing enumeration cycles, not on a fixed daily schedule. When a change is detected — a new subdomain, a newly open port, or a certificate approaching expiry — an alert is generated and the asset is added to your inventory.

Every SSL/TLS certificate on your external assets is monitored for expiry date, cipher suite strength, and TLS configuration quality. Alerts fire at configurable thresholds before expiry (typically 30 and 14 days) so your team can renew certificates before they expire and cause browser warnings or service outages.

Yes. Shadow IT — cloud services, test environments, and third-party integrations spun up without security team involvement — frequently appear as new subdomains or IP addresses. External Attack Surface catches these through continuous DNS enumeration and feeds them into the asset inventory, where they can be assessed and owned.

See External Attack Surface in action

Request a personalised demo and we'll show you exactly how External Attack Surface works within your environment.