Advanced level

SORT ASM: what your organisation exposes online, including what it forgot

Continuous monitoring of up to two IPs or domains that discovers and watches the organisation’s real attack surface, beyond the declared inventory.

Ask about ASM

subdomain enumerationDNS reconsubdomain takeoverhistorical URLsHTTP probeShodan / Censysport scanSSL / TLS

What problem it solves

When we ask an organisation how many assets it has exposed to the internet, the answer is usually a round, low number. When we run the discovery, the real number is systematically higher — and not by two or three: by an order of magnitude. What turns up is almost never the main website, which is well looked after: it is the test environment left public, the subdomain from a 2019 campaign, or the panel of a supplier that no longer works with the company.


Who it is for

  • Organisations that grew project by project and have no reliable inventory of what they expose.
  • Small IT teams that cannot dedicate time to continuous discovery.
  • ISMSs that need periodic evidence of control over the exposed surface.

Capabilities

01

Discovery

Subdomain enumeration, DNS reconnaissance and retrieval of historical URLs to find what the declared inventory does not record.

02

Service verification

HTTP probing, port scanning and queries against exposure sources such as Shodan and Censys over the assets found.

03

Takeover risk

Detection of subdomain takeover: DNS records still pointing at decommissioned services that a third party could claim.

04

Cryptographic posture

Review of certificates and SSL/TLS configuration: expiry dates, weak algorithms and badly built chains.


What the rollout includes

  • Onboarding of up to two domains or IP addresses into monitoring.
  • Initial baseline with the discovered inventory and its classification.
  • Continuous monitoring with notification of changes in exposure.
  • Periodic report with prioritised findings and recommended actions.

Frequently asked questions

Is ASM the same as a penetration test?

No. A pentest is point-in-time and deep: it tries to exploit what it finds within a set window. ASM is continuous and broad: it does not exploit, but it permanently watches what is exposed and flags changes. They complement each other —ASM usually shows where a pentest is worth aiming— and neither replaces the other.

Can the scanning affect our services?

No. Discovery relies on public sources and non-intrusive probes, equivalent to what any search engine does. No exploits or load tests are run against the client’s infrastructure.

Why is it limited to two domains or IPs?

Because that is the scope included in the Advanced level of the service model, and it covers the usual case: the corporate domain and the main application. Organisations with a larger surface contract additional scope, quoted by the number of assets.

your business partner

Protecting you today, innovating for tomorrow