Domain & Subdomain Discovery
Passive and active enumeration of every domain, subdomain and DNS record tied to your brands, including forgotten and acquired estates.
Continuous discovery, monitoring and reduction of everything your organisation exposes to the internet — powered by Mirage Surface and validated by our consultants.
Powered by Mirage SurfaceMost breaches begin with something the security team did not know was exposed — a forgotten subdomain, a staging environment left public, an expired certificate or an admin interface open to the world. External Attack Surface Management gives you an always-current inventory of that exposure and the context to fix it in priority order.
Pentesys combines automated discovery through Mirage Surface with consultant validation. Assets are enumerated continuously, changes are detected as they happen, and every material finding is reviewed by a tester before it reaches your inbox — so what you see is real risk, not scanner noise.
Each module runs continuously through Mirage Surface and feeds a single, validated view of your external exposure.
Passive and active enumeration of every domain, subdomain and DNS record tied to your brands, including forgotten and acquired estates.
Owned and cloud-allocated ranges resolved to live hosts, open ports and exposed services with ownership attribution.
Public buckets, storage endpoints, serverless functions and misconfigured cloud services surfaced across AWS, Azure and GCP.
Unsanctioned SaaS, marketing microsites and developer-spun environments identified before an attacker finds them.
Frameworks, CMS platforms, libraries and server versions identified and matched against known CVEs and end-of-life status.
Expiring, misissued and weak certificates flagged, plus new certificates used to discover assets you never registered with IT.
Corporate credentials appearing in breach dumps, paste sites and criminal marketplaces, mapped back to affected accounts.
Admin portals, VPN endpoints, remote access services and management interfaces reachable from the public internet.
Undocumented and legacy API endpoints discovered through crawling, JavaScript analysis and specification harvesting.
Lookalike domains and impersonation infrastructure registered against your brand, an early indicator of phishing campaigns.
Everything below is delivered and tracked through the Mirage Portal.
Domains, subdomains, IP ranges, cloud resources, APIs and shadow IT enumerated automatically and re-checked on your chosen schedule — hourly, daily, weekly or monthly.
Over 300 technology signatures with version-level detection, mapped to known CVEs so end-of-life and vulnerable components surface immediately.
Breach database scanning for leaked credentials tied to your domains, giving early warning of account takeover and credential-stuffing risk.
SSL/TLS certificate expiry tracking, open port detection and misconfiguration alerts with risk-scored context for each exposed service.
A single external risk score, tracked over time, so you can evidence improvement to leadership, auditors and insurers.
Consultants triage the automated output, confirm exploitability and add remediation guidance before findings are published to your portal.
A consistent, transparent methodology from first conversation to verified remediation.
We agree your known estate, brands and acquisitions, then seed discovery from domains, IP ranges and cloud tenants.
A full enumeration establishes your current external footprint and initial risk score.
Consultants review the baseline, remove false positives and confirm which exposures are genuinely exploitable.
Scheduled rescans detect new assets and changes, with alerts routed to your team or ticketing system.
Monthly reviews track surface reduction, remediation progress and risk-score trend.
A scan checks assets you already know about. EASM finds the assets you do not know about first, then assesses them — and keeps doing it continuously.
Discovery runs on your chosen schedule, from hourly to monthly. Most clients run daily discovery with real-time alerting on new exposure.
No. EASM is entirely external and requires no agents, credentials or network access.
CREST-registered testing delivered through a flexible PTaaS model — designed to fit your environment, risk profile and internal teams.