For security teams

Attack surface management without the enterprise contract.

The enterprise EASM suites do continuous discovery well, for six figures and a sales cycle. Attack Surface Scan does the part that matters for a lean security team: CT-log subdomain discovery, lookalike-domain watching, a change feed with evidence inline, and an MCP server so your agents and tooling can drive it. Self-serve, from $25/month.

No card required to start. Plans from $25/month; first scan in about a minute.

Built around how security teams actually work

Discovery you didn't have to seed

Subdomain enumeration from certificate transparency logs, continuously, including dangling CNAMEs pointing at claimable services. The inventory grows as the estate does, not when someone updates a list.

A change feed, not a snapshot

Every scan diffs against the last: hardened SPF, new subdomain, a port that started answering, a header that vanished. The evidence is inline, so triage doesn't start with re-running the check.

Triage that sticks

Findings carry severity and evidence; accepted risk gets a review date, noise gets muted. What's left is a digest short enough that people keep reading it, which is the actual failure mode of most scanners.

Lookalike domains watched passively

Typosquats and homoglyph registrations (the raw material for phishing and invoice fraud), tracked with public DNS and CT data only.

Automation-first by design

The whole product as MCP tools

A hosted MCP server (OAuth 2.1, no API keys) exposes scans, findings, the change feed, triage and reports to Claude, ChatGPT, Codex or anything else that speaks MCP. Setup guide →

Webhooks into your pipeline

Critical changes can hit a webhook the moment they're found: into your SOAR, your ticketing, or a queue you own.

Hand-off prompts for remediation

Any scan exports as a severity-ordered prompt for a coding agent, with evidence and a verification command per finding, plus an honest flagged list for fixes that live at the registrar or in a console instead of a repo.

Scope you can defend

Scanning runs only against domains ownership-verified via DNS TXT. Deliberately: the platform cannot be pointed at infrastructure you don't control.

Common questions

How does Attack Surface Scan compare to enterprise EASM platforms?

The discovery core is the same idea: continuous external enumeration and change detection. What Attack Surface Scan doesn't have: seat-based enterprise pricing, deployment projects, or a sales cycle. What the big suites don't have: self-serve setup in minutes and a price a team can expense. Comparisons with specific tools are in the articles.

Is the check depth enough for a security team?

The modules cover TLS and chain validity, HTTP security headers, DNS and email authentication (SPF/DMARC/CAA), CT-log subdomain discovery, service fingerprinting and a TCP connect sweep of common ports. It's passive by design: it complements your pentest and internal scanning; it doesn't replace them.

Can we drive it entirely from our own tooling?

Close to it: the MCP server covers the workflow end to end (start scans, read findings and changes, triage, generate reports) and webhooks push changes outward. A human-facing console is still there for the parts you want eyes on.

Stand up external monitoring this afternoon.

Verify a domain, wire the webhook, and the change feed starts filling itself.

Start your 7-day trial

No card required to start. Cancel any time.