Articles
Practical external security, explained.
Comparisons, how-tos and plain-language explainers on attack surface monitoring, TLS, DNS and the other things the outside world can see about your infrastructure.
The Best DMARC Monitoring Tools in 2026 (Free and Paid)
The best DMARC monitoring tools compared: free analyzers from Postmark and Cloudflare, paid platforms like dmarcian and EasyDMARC, and open source parsedmarc.
Read article →The Best SSL Certificate Monitoring Tools in 2026
The best SSL certificate monitoring tools compared: free options, open source (Zabbix, blackbox_exporter), dedicated monitors and enterprise CLM platforms.
Read article →The Best Open Source Attack Surface Management Tools in 2026
The best open source attack surface management tools: Amass, Subfinder, httpx, nuclei, testssl.sh, OpenVAS and more. What each does and how to chain them.
Read article →What Does Attack Surface Management Actually Cost in 2026?
Attack surface management pricing in 2026: the four models, real ranges from $25/month to six figures, the costs vendors leave out, and how to size a budget.
Read article →47-Day TLS Certificates: The Schedule, and How to Be Ready
TLS certificate lifetimes drop to 100 days in 2027 and 47 in 2029. The CA/Browser Forum schedule, why it is happening, and what breaks if you renew by hand.
Read article →EASM vs. CAASM vs. CSPM: The Acronyms, Untangled
EASM looks inward from the internet, CAASM aggregates the tools you already run, and CSPM audits cloud config. What each acronym means and which one you need.
Read article →The Gap in Your Compliance Stack Is the Part the Internet Can See
MDM, CSPM and vulnerability scanners only watch assets someone enrolled. Breaches start at the ones nobody did. Why the stack is inside-out, and what fixes it.
Read article →Attack Surface Scan vs. OpenVAS: Vulnerability Scanner or External Monitor?
OpenVAS is a free self-hosted vulnerability scanner; Attack Surface Scan is a hosted external monitor. What each does, the real cost of self-hosting, and when to run both.
Read article →Hand Your Security Findings to a Coding Agent: Claude Code, Codex and opencode
Most scan findings are config changes in a repo, exactly what coding agents do well. How to hand a security report to Claude Code, Codex or opencode.
Read article →Turning External Monitoring Into SOC 2 and ISO 27001 Evidence
SOC 2 CC7.1 and ISO 27001 Annex A 8.8 expect monitoring you can prove. What scan history maps to which control, what auditors sample, and what it misses.
Read article →The Best External Attack Surface Monitoring Tools in 2026, Compared
The best attack surface monitoring tools in 2026 compared: Attack Surface Scan, Detectify, Intruder, Censys and Microsoft Defender EASM, ranked by team size and budget.
Read article →Attack Surface Scan vs. Detectify: Which External Security Monitor Fits Your Team?
Attack Surface Scan vs. Detectify for external attack surface monitoring: what each product checks, how the two price, and which kind of team each one actually fits.
Read article →Attack Surface Scan vs. Intruder: Vulnerability Scanning or Attack Surface Monitoring?
Intruder is a vulnerability scanner with attack surface features; Attack Surface Scan is a passive external monitor with change detection. How to decide which one you need.
Read article →Attack Surface Scan vs. Shodan and Censys: Search Engines Aren't Monitoring
Shodan and Censys index the whole internet; Attack Surface Scan monitors the domains you own. Where they overlap, and why searching yourself is not monitoring.
Read article →Which HTTP Security Headers Actually Matter in 2026 (and How to Set Them)
The HTTP security headers worth setting in 2026: HSTS, Content-Security-Policy, nosniff, Referrer-Policy and cookie flags, with copy-paste starting values.
Read article →SSL Labs vs. SecurityHeaders.com vs. Mozilla Observatory: Free Scanners Compared
The best free website security scanners compared: SSL Labs, securityheaders.com, Mozilla Observatory, MXToolbox and Hardenize. What each grades and misses.
Read article →Subdomain Takeover: How a Dangling CNAME Becomes Someone Else's Website
Subdomain takeover happens when a dangling CNAME points at a service anyone can claim. How the attack works, how to find dangling records, and how to stop it.
Read article →How to Monitor SSL/TLS Certificate Expiry (Before Your Users Do)
SSL certificate expiration monitoring explained: how expiry outages happen, how to monitor certificate expiry for free, and what a good setup should alert on.
Read article →SPF, DKIM and DMARC Explained: Stop Other People Sending Email as You
What SPF, DKIM and DMARC each do, how the three records fit together, the mistakes that silently break them, and how to reach a DMARC reject policy safely.
Read article →What Is External Attack Surface Management (EASM)? A Plain-English Guide
External attack surface management (EASM) is the continuous discovery of everything you expose to the internet. What it covers and how it differs from scanning.
Read article →