New here? Start with Getting started. Reviewing us for a security questionnaire? How scanning works and Data sources answer most of it, and the privacy policy covers data handling.
Start here
Getting started
Add a domain to Attack Surface Scan and prove you control it with a DNS TXT record, a well-known file, a work email at the domain, or an emailed approval.
How scanning works
Attack Surface Scan's passive scanning posture: what traffic it sends, what it never does, how it identifies itself, and how ownership is enforced on every scan.
What we check
Checks reference
Every finding Attack Surface Scan can raise, grouped by area: the finding ID, default severity, what it means and how to fix it.
Vulnerability matching
How Attack Surface Scan matches detected software versions to CVEs and prioritises them with CISA KEV and EPSS, plus potential matches, JavaScript library advisories and end-of-life software.
Exposed services and ports
The full list of TCP ports Attack Surface Scan checks on each host, the default severity of each, how CDN edge IPs are handled, and how service greetings are read.
Asset inventory and discovery
How Attack Surface Scan builds the asset inventory: hosts, IPs, third-party dependencies and related domains, discovery sources, asset states, pruning and network context.
Certificates and certificate transparency
Attack Surface Scan's certificate monitoring: CT logs read every 15 minutes, the authorized-CA list, the unknown-certificate queue, served-certificate probes, stalled renewals and extra ports.
Email security
Attack Surface Scan's email authentication checks: SPF, DMARC, MTA-STS, TLS-RPT and CAA, plus lookalike domain monitoring and change alerts when records weaken.
Domain registration hygiene
Attack Surface Scan's registration checks: registrar transfer, update and delete locks via RDAP, DNSSEC status, security.txt, weak certificate signatures, registration expiry and registrar sprawl.
Web page and privacy checks
Attack Surface Scan's page crawl: login and personal-data forms without encryption, mixed content, third-party scripts without SRI, tracking cookies before consent, and the third-party script inventory.
Reputation monitoring
How Attack Surface Scan checks your hosts and their IP addresses against free public abuse feeds, what a listing means, and how to get delisted.
Reporting
Connect
Integrations
Send Attack Surface Scan alerts to email, Slack, Microsoft Teams, PagerDuty, Jira (via Jira Automation) and HTTPS webhooks, including an OCSF payload option for SIEMs.
REST API
Attack Surface Scan's read-only REST API v1: API keys, Bearer authentication, endpoints for domains, findings, assets, changes and scans, rate limits, errors and curl examples.
MCP server
Connect Claude, ChatGPT, Codex, Cursor and other MCP clients to Attack Surface Scan with OAuth. Summary and link to the full MCP setup guide.