ISO 27001 CertifiedSOC 2 Compliant A product by Visit the Trust Center
Agent 04 · Attack surface

Every way in, found before they use it.

Give the ASM agent a single domain. It maps everything attached to you, subdomains, IPs, ports, certificates, technologies and the forgotten hosts nobody remembers, from the outside in, continuously, exactly the way an attacker would.

The agent, thinking

One domain in. Your whole exposure out.

From a single seed to a ranked map of forgotten, exploitable hosts. This is the ASM agent reasoning through one run, condensed.

Attack‑surface agent · reasoning live
1
Seed domain in, your entire surface out
24/7
Continuous discovery, re-scan and change detection
0
Agents to install, mapped from the outside in
The blind spot

You can’t defend what you can’t see.

Attackers don’t work from your asset list. They map what’s actually exposed, and the gaps in your inventory are exactly where they start.

01

Shadow IT

Marketing spins up a subdomain, a team ships a side app, and none of it ever reaches your asset inventory.

02

Cloud & M&A drift

Every acquisition, cloud account and quick deploy widens the surface faster than anyone can track.

03

It changes daily

Certificates lapse, ports open, staging goes live. A yearly audit is stale the week after it ships.

Discovery

We find what your inventory forgot.

Start with one domain. The agent reaches far past what you list, the way an attacker enumerates you.

Internet-scale scraping

We scrape the internet at large to attribute the maximum number of subdomains and hosts back to you.

Brute-force discovery

Hosts that never surface in scraping are found by directed brute-forcing.

Name permutation

api.acme.com → api-stage → api-dev-1…, the variants attackers guess, generated and probed.

Scheduled monitoring & diff

Recurring scans surface only what’s new since last time, fresh hosts, ports and findings.

Per-asset intelligence

Open any asset. See what an attacker sees.

Every discovered host comes fully profiled, technologies, live screenshot, certificate, ASN, open ports and its vulnerabilities, in one dossier.

Asset profile · discovered outside-inlive
staging-admin.acme.comNot in inventory
IP
203.0.113.24
ASN
AS14061 · DigitalOcean
Ports
22 · 80 · 443 · 8080
Status
200 OK
Certificate
Expired 41 days ago
CNAME
→ legacy-lb.acme.net
nginx 1.18PHP 7.2 · EOLWordPress 5.4jQuery 1.12
HIGHExposed admin panel behind an expired certificate.AI fix · retest

Then slice the whole surface the way you actually reason about it:

HostIPTechnologyPortStatus codeCNAMECustom label
Triage

Proof, a fix, and a retest, in one place.

Each vulnerability lands with evidence and an AI-written remediation. Adjust severity to your real exposure, then retest the moment it’s fixed.

01
Proof

Evidence, not guesswork

Every finding ships with the request, the response and a live screenshot that proves it’s real.

Request / responseLive screenshotPer asset
02
Fix

An AI-written remediation

A specific fix with references, written for the technology actually running on the host.

AI remediationWith references
03
Severity

Severity you control

Adjust severity to match your context; the change sticks and informs how the surface is ranked next time.

Editable severity
04
Retest

One-click retest

Re-run the exact check the moment you’ve patched, confirmation, not assumption.

One-click retest
Change detection

The surface moves. So does the agent.

Put any domain into continuous monitoring and every re-scan surfaces just the delta, the new door, the freshly opened port, the certificate that lapsed overnight.

Change logNew since last scan · ranked
AS-4471New hoststaging-admin.acme.com appeared and is publicly reachable.Profiled, ranked HIGH, owner alerted. Triaged
AS-4468Open portPort 8080 opened on api.acme.com since the last scan.Flagged; service fingerprinted and checked. Triaged
AS-4463Expired certThe TLS certificate on pay.acme.com lapsed two days ago.Caught the same day; renewal raised. Triaged
AS-4459New vulnAn exposed admin panel on a forgotten subdomain.Evidence captured; AI fix attached. Triaged
Why it’s different

The outside-in view, wired to everything else.

Most tools inventory only what you tell them about. VenusHawk maps what’s actually exposed, and connects it to the rest of the constellation.

Attacker’s-eye view
Mapped from the outside in, with no agents to install and nothing to configure on your hosts.
Finds the forgotten
Scraping, brute-force and permutation surface hosts that never appear in any inventory.
Always current
Continuous re-scans show the delta: you see change the day it happens, not at the next audit.
Proof and a fix
Every finding carries evidence, an AI remediation and a one-click retest.
Wired to the code
Hand an exposed app straight to the Code & App Security agent to test it for real.
One engine, many surfaces
The same brain ties your surface to code, data and dark-web exposure.
Early access

Bring this agent into your constellation.

VenusHawk is rolling out to lighthouse customers and design partners. Tell us a little about your environment and we’ll see how we can accommodate you.