
Vulnerability Scanning

80%
attack surfaces partly unseen
continuous
exploit checks
We routinely find assets our
customers didn’t know they had.
how it works
Six techniques.
One full surface map.
We start with one domain. Then we triangulate everything you own,
host, or have ever briefly stood up.
Passive DNS
DNS sources cross-referenced. Catches undocumented subdomains, including internal services leaking into DNS.
Certificate transparency
Every TLS certificate ever issued for your domains, mined from CT logs. Including the staging-only ones your team forgot about.
ASN / BGP topology
Maps the IP ranges and netblocks your business owns or rents. Cloud-hosted assets that share a tenancy come along too.
Public GitHub leak detection
Scans public repos and gists for leaked credentials, internal hostnames and API keys tagged to your domain.
Cloud asset enumeration
S3 buckets, Azure blob containers, GCS buckets and Cloudflare R2. Public-readable detection across the major hyperscalers.
Search-engine recon
Shodan and Censys lookups against your IPs and certificate identities — catches hosts your team did not realise were public.
Live map
One domain in.
Your entire surface out.
Our scanner discovers every subdomain, service and dependency exposed to the internet. Then it continuously scans for misconfigurations, expired certs and exploitable CVEs — and routes the fixes to the team that owns each asset.
Full subdomain enumeration & DNS graph
Live CVE matching against exposed software
Certificate, TLS, and header hygiene
Cloud asset discovery (S3, Azure blobs, GCS)
Continuous — not a quarterly pentest

Vulnerability classes
Every finding knows who fixes it.
Every finding is scored, contextualised and assigned to the team that owns the asset.

Scenario
The Forgotten Subdomain
Found day 1 · fixed by Friday
A forgotten staging server, exploitable and exposed for months.
A growing tech business onboards on Monday. The first agent scan completes in 8 minutes and surfaces a forgotten staging subdomain — staging-old.acme-tech.co — running unpatched software with a known critical CVE. Publicly exploitable, unauthenticated, and sitting open for over seven months.
CyberProtect surfaces it in the day-one executive digest. The agent auto-identifies the engineering owner from DNS records, drafts the patch path, and pre-fills a Jira ticket. The platform team picks it up Tuesday morning and fixes it Wednesday.
The agent re-validates on Thursday's scan. Total time from “we didn't know this asset existed” to “fixed and verified”: four working days.
Outcome
8 min
first scan completion
7+ mo
exposure age before discovery
1 ticket
auto-routed to platform team
4 days
to fix + re-validate
Integrations
Plugs into the SOC
stack you already run.
The feed ships in the formats your tools already speak — no rip-and-replace.
Point it at your SIEM and indicators start landing in minutes.
AWS
S3, EBS snapshots, ECR, public ELB
Azure
Blob containers, App Service, Front Door
Google Cloud
GCS, Cloud Run, Load Balancers
Cloudflare
R2 buckets, Pages, Workers, Tunnels
DigitalOcean
Spaces, droplets with public IPs
Microsoft 365
SharePoint anonymous links, OneDrive
And a bucket of others
Heroku
Vercel
Netlify
Fastly
Akamai
Vultr
GitHub
GitLab
Kubernetes
Docker
+ 40 more
AI AGENTS
External surface,
not the whole stack.
We DO this
Subdomain & DNS-graph enumeration
Cert / TLS / header hygiene
Public-facing CVE matching
Cloud surface (S3, Azure blobs, GCS, R2)
Subdomain takeover risk detection
Owner mapping + Jira / Slack routing
Continuous — not a quarterly snapshot
We don't do this
Authenticated application testing
Source-code review (SAST tooling)
Internal-network scanning (no agent inside)
Active exploitation or red-team work
Bug bounty triage
The questions IT teams ask first.
How is this different from an EASM tool like Randori or Censys?
Do I need to install agents inside my network?
How do you map owners to assets?
How often does the scanner re-scan?
Does this replace our annual pentest?
What about subdomains we don't own — partner-hosted, white-labelled?

Is your business
exposed now?
Find out what attackers see. Get in contact with us today and secure your perimeter in under 10 minutes.








