External Attack Surface Management

You can't defend
what you don't know you own.

Your attack surface, in ten seconds.

No signup, no card.

discover hidden subdomainsfind forgotten servicesspot exposed admin panelscatch credentials in breach datawatch for changeturn every finding into a next stepdiscover hidden subdomainsfind forgotten servicesspot exposed admin panelscatch credentials in breach datawatch for changeturn every finding into a next step
nanoeasm.com/discovery/map
Assets discovered
0
Live discovery
Scanning…
critical
high
medium
low
7
Detection categories
23
Secret formats
12
Discovery sources
6
Compliance frameworks
What ten seconds buys

A finding you can check yourself.

Every result carries what was actually observed, and says which.

highSecurity Hygieneevidenced
Login form served without transport security
testfire.net/login.jsp
A login page of a public demo target, served over plain HTTP, with username and password fieldsscreenshot
criticalVulnerabilitiesvalidated
Remote code execution via Log4Shell
api.acme.example
POST /api/v1/search HTTP/1.1
X-Api-Version: ${jndi:ldap://…}
→ 500, callback observed in 1.2s
CVE-2021-44228 · CVSS 10.0
highMisconfigurationsvalidated
CORS allows any origin with credentials
api.acme.example
OPTIONS /api/v1/me
Origin: https://evil.example
→ 204
Access-Control-Allow-Origin: *
Access-Control-Allow-Credentials: true
mediumCompromised Credentialsinferred
Employee addresses found in breach data
acme.example
4 addresses
Matched against known breach corpora. No page to photograph, and nothing of ours to replay.
breach database · first seen 2026-08-02

Quick Asset Scan

Scan any domain or IP, no account needed

Sign in for deeper scans and richer findings

Scan results
Run a scan to see results
Total findings
-
IPs scanned
-

Quick Discovery

Discover subdomains and IPs, no account needed

Sign in to unlock deeper enumeration

Discovery results
Run discovery to see results
Subdomains found
-
Apex IPs
-

LookUp Tools

Quick-check any domain or IP, no account needed

Enter a domain or SHA-256 hash and press Enter

Verify once: token is good for the next tool you run.

Capabilities

Everything you need to manage
your attack surface

Find what you forgot you owned

Shadow IT, contractor leftovers, abandoned cloud assets. Add a root domain: 12 passive and active intelligence sources surface every subdomain, IP, and service across your external surface.

Multi-Engine Scanning

Scan with 9 purpose-built engines across network, web, and certificate attack surfaces. Choose Quick, Standard, or Deep profiles, or schedule recurring scans.

Find leaked API keys before attackers do

Public GitHub and GitLab pushes, exposed .env files, .git directories served as static assets, SSH keys leaked in repos. Recognises 23 secret formats (AWS, GitHub PATs, Stripe, OpenAI, Anthropic, Slack, Twilio, JWTs) and surfaces them within hours of the push.

Exposure Scoring

Quantified risk scores per asset and group with logarithmic severity weighting. Track score changes over time with trend analysis.

Know the moment something new shows up

A new subdomain, an open port that wasn't there last week, a service responding where one shouldn't. Checks run on a configurable cadence (every 12 hours to every 5 days) and alert rules fire only on the changes that matter, not every churn.

Remediation Workflow

Track findings through open → in progress → resolved. Accept risk with justification, suppress false positives, and measure time-to-remediate.

Reports & Trending

Generate executive summaries and full technical PDF reports with embedded charts. Schedule weekly or monthly report delivery.

Integrations

Connect to Slack, Jira and email, or push anywhere over outbound webhooks and the REST API. Create notification rules that auto-fire on critical findings or exposure thresholds.

API & Automation

Full REST API with scoped API keys. Automate asset onboarding, trigger scans, pull findings, and integrate with your existing security toolchain.

Query your attack surface from any AI tool or LLM client

Connect any MCP-compatible AI tool or LLM client directly to your org's live attack surface data. Ask about findings, assets, scan history, and exposure stats without leaving your AI workflow.

Spot the domain pretending to be you

Typosquats, homoglyphs, IDN punycode tricks, TLD swaps, and look-alike domains built for phishing or brand impersonation. Continuous monitoring flags new registrations before they go live in a campaign.

Team & governance

Enterprise Controls

Role-based access
Viewer, Analyst, Admin, Owner: scoped per workspace.
Full audit log
Every action recorded, exportable, SIEM-streamable.
Team management
Invite, role-promote, suspend, and offboard members.
Tiered plan controls
Asset, scan, and monitor limits enforced per plan.

Want to see exactly what we detect?

Every alert falls into one of seven categories: vulnerabilities, service exposure, leaked secrets & configs, misconfigurations, security hygiene, lookalike domains, and compromised credentials. Toggle any of them on or off, per organisation or per asset group.

See full coverage
Continuous exposure

Start with visibility. Grow into exposure management.

The scan at the top of this page is the first stage. The rest is what the product does once it's watching continuously.

01

Discover

Uncover internet-facing domains, IPs, services, and cloud assets.

02

Prioritise

Rank findings by severity, exposure, and context.

03

Monitor

Track exposure changes over time.

04

Remediate

Turn findings into plain-English next steps.

05

Validate

Re-check fixes and confirm exposure reduction where supported.

Nano EASM focuses on the external exposure layer of CTEM, where unknown internet-facing assets, exposed services, and changing risk often create the first gaps teams need to close.

It goes where your team already works.

Including, uniquely, straight into an AI client.

Built in
MCP serverSlackJiraEmailOutbound webhooksAudit-log stream (SIEM)REST API
Works over webhook or the API
TinesPagerDutySplunkSentinelany SOAR with an HTTP trigger

The questions people actually ask.

Is this a false positive?
Findings carry the request that produced them where the check can produce one, a screenshot on Professional and above, and a label: inferred, validated, or evidenced.
Why is your scan instant when others need a form?
Ours is passive. It reads what internet-wide scanners have already published, so nothing is sent to your infrastructure. Active testing sends traffic at infrastructure, which needs the owner's authorisation.
What don't you do?
No takedown, no dark-web monitoring, no threat-actor intelligence. How we compare lists what we are not.
What happens to my data?
Retention is published per data class, including the unauthenticated quick-scan log.
What does it cost?
The scan on this page is free to run. The free plan keeps an inventory and runs scans on demand. Continuous monitoring starts on paid plans. See Plans for what each includes.
Can I get findings into my own tooling?
REST API, outbound webhooks, an audit-log stream for your SIEM, and an MCP server for AI clients.
Free plan available

Start free, scale when ready

Start on the Free plan with no payment details required. Paid plans add continuous monitoring and higher limits.

Free
2 assets
Start here
Starter
15 assets
Monitor 5
Professional
100 assets
Monitor 25
Ent. Silver
10k assets
Monitor 100
Ent. Gold
20k assets · audit log
Monitor 250
Get in touch

Contact us

Questions, feedback, or interested in Enterprise? Send us a message and we'll get back to you within one business day.

Loading…

Response time

One business day on weekdays. Enterprise & demo requests are routed straight to a human, not a ticket queue.

Already a customer?

Sign in and reach support from inside the app; your org context is included automatically.

Open the app

Want to skip the form?

Run a real scan against your own domain right now: no signup, no card, no demo call.

Try it now