Skip to content
Pentesys
EASM

Knowyourexternalattacksurfacebeforeanattackermapsit

Continuous discovery, monitoring and reduction of everything your organisation exposes to the internet — powered by Mirage Surface and validated by our consultants.

Mirage SurfacePowered by Mirage Surface

Most breaches begin with something the security team did not know was exposed — a forgotten subdomain, a staging environment left public, an expired certificate or an admin interface open to the world. External Attack Surface Management gives you an always-current inventory of that exposure and the context to fix it in priority order.

Pentesys combines automated discovery through Mirage Surface with consultant validation. Assets are enumerated continuously, changes are detected as they happen, and every material finding is reviewed by a tester before it reaches your inbox — so what you see is real risk, not scanner noise.

Discovery modules

Everything we look for on your perimeter

Each module runs continuously through Mirage Surface and feeds a single, validated view of your external exposure.

Domain & Subdomain Discovery

Passive and active enumeration of every domain, subdomain and DNS record tied to your brands, including forgotten and acquired estates.

IP & Network Range Mapping

Owned and cloud-allocated ranges resolved to live hosts, open ports and exposed services with ownership attribution.

Cloud Asset Exposure

Public buckets, storage endpoints, serverless functions and misconfigured cloud services surfaced across AWS, Azure and GCP.

Shadow IT Detection

Unsanctioned SaaS, marketing microsites and developer-spun environments identified before an attacker finds them.

Technology Fingerprinting

Frameworks, CMS platforms, libraries and server versions identified and matched against known CVEs and end-of-life status.

Certificate & TLS Monitoring

Expiring, misissued and weak certificates flagged, plus new certificates used to discover assets you never registered with IT.

Credential & Breach Monitoring

Corporate credentials appearing in breach dumps, paste sites and criminal marketplaces, mapped back to affected accounts.

Exposed Interfaces & Panels

Admin portals, VPN endpoints, remote access services and management interfaces reachable from the public internet.

API & Endpoint Discovery

Undocumented and legacy API endpoints discovered through crawling, JavaScript analysis and specification harvesting.

Brand & Typosquat Monitoring

Lookalike domains and impersonation infrastructure registered against your brand, an early indicator of phishing campaigns.

Capabilities

What's included in External Attack Surface Management

Everything below is delivered and tracked through the Mirage Portal.

Continuous asset discovery

Domains, subdomains, IP ranges, cloud resources, APIs and shadow IT enumerated automatically and re-checked on your chosen schedule — hourly, daily, weekly or monthly.

Technology fingerprinting

Over 300 technology signatures with version-level detection, mapped to known CVEs so end-of-life and vulnerable components surface immediately.

Credential and breach monitoring

Breach database scanning for leaked credentials tied to your domains, giving early warning of account takeover and credential-stuffing risk.

Certificate and exposure alerts

SSL/TLS certificate expiry tracking, open port detection and misconfiguration alerts with risk-scored context for each exposed service.

Risk scoring and trend analysis

A single external risk score, tracked over time, so you can evidence improvement to leadership, auditors and insurers.

Human validation

Consultants triage the automated output, confirm exploitability and add remediation guidance before findings are published to your portal.

Coverage

Scope and depth

What we discover

  • Root domains, subdomains and dangling DNS records
  • IP ranges, hosting providers and netblocks
  • Cloud storage buckets and public cloud services
  • Web applications, admin panels and login portals
  • APIs, endpoints and undocumented interfaces
  • Mail, VPN, RDP and remote-access services

What we flag

  • Vulnerable and end-of-life software versions
  • Exposed management interfaces and default credentials
  • Expiring or misconfigured certificates
  • Open ports and unnecessary services
  • Leaked credentials in breach corpora
  • New assets appearing outside change control
How it works

Our delivery process

A consistent, transparent methodology from first conversation to verified remediation.

  1. 01

    Scope and seed

    We agree your known estate, brands and acquisitions, then seed discovery from domains, IP ranges and cloud tenants.

  2. 02

    Baseline discovery

    A full enumeration establishes your current external footprint and initial risk score.

  3. 03

    Validate

    Consultants review the baseline, remove false positives and confirm which exposures are genuinely exploitable.

  4. 04

    Monitor continuously

    Scheduled rescans detect new assets and changes, with alerts routed to your team or ticketing system.

  5. 05

    Reduce and report

    Monthly reviews track surface reduction, remediation progress and risk-score trend.

What you receive

  • Live asset inventory in the Mirage Portal
  • Prioritised exposure findings with remediation guidance
  • External risk score with historical trend
  • Change and new-asset alerting via email, Slack or ticketing
  • Executive summary suitable for board and insurer reporting

Business outcomes

  • No more unknown internet-facing assets
  • Faster detection of risky change outside change control
  • Measurable, evidenced reduction in external exposure
  • Cleaner input into penetration testing scope
FAQs

Common questions

How is this different from a vulnerability scan?

A scan checks assets you already know about. EASM finds the assets you do not know about first, then assesses them — and keeps doing it continuously.

How quickly are new assets detected?

Discovery runs on your chosen schedule, from hourly to monthly. Most clients run daily discovery with real-time alerting on new exposure.

Do you need access to our environment?

No. EASM is entirely external and requires no agents, credentials or network access.

Save time and book a call with us

Enterprise-grade penetration testing, built around your business

CREST-registered testing delivered through a flexible PTaaS model — designed to fit your environment, risk profile and internal teams.