We look at your company the way an attacker does
then price what we find
Scout is an external attack surface assessment. Two to four weeks, fixed scope, and a plan your engineers can start on Monday.
No agents to install, no access to grant. We start from what the open internet already knows about you — which is more than most inventories admit.
Domains & Hosts
Live URLs
Known CVEs
Credential Material
Supply Chain
DNS & Takeover
How a Scout Runs
Recon first, judgment second. The scan tells us what is reachable; the engagement decides what matters.
1. Scope
Your engineers name the apex domains and the things we must not touch.
2. Discover
Subdomains, hosts, live HTTP services, TLS and cloud fingerprints.
3. Probe
High-signal CVE and misconfiguration templates, secret patterns, lockfile advisories.
3. Quantify
Exposure priced in dollars, ranked by business impact — not raw CVE count.
5. Roadmap
A 30 / 60 / 90-day sequence with an owner against every line.
Findings that look alarming and cost nothing to reach get ranked above findings that score higher and cannot be touched. If a remediation costs more than the exposure, we will tell you to leave it alone.
What Comes Back
One assessment, two readings. The board gets the sentence; the SOC gets the evidence.
Executive view
What leadership needs to know, in fifteen seconds.
SOC view
The same findings with the evidence attached.
Host × finding matrix
One row per finding, pinned to one host.
It is the triage queue, sorted by severity.
| Severity | Finding class | Host | Evidence | Owner hint |
|---|---|---|---|---|
| How bad | What we found | Where it lives | How we proved it | Who fixes it |
| CRITICAL | Credential material in a public artifact | ████████ | served lockfile | Eng / Security |
| CRITICAL | Non-production host on the public internet | ████████ | full app stack, 200 | Platform / Cloud |
| HIGH | Known CVE on an internet-facing appliance | ████████ | template match | Infra / AppSec |
| HIGH | Unauthenticated debug endpoint | ████████ | profiler reachable | Cloud / SRE |
| HIGH | Dangling DNS, takeover candidate | ████████ | CNAME to released resource | Cloud / DNS |
| HIGH | Vulnerable transitive dependency | ████████ | advisory in bundle | Frontend |
Structure only. Hosts and evidence are redacted here; yours arrive filled in.
Medium, Low and Info findings continue in the full report, with inventory items kept for ownership mapping.
The First 90 Days
Highest business risk first, without freezing product delivery.
0–30 days
Stop the Bleed
Rotate exposed credential material. Pull non-production hosts off the public internet. Patch or isolate anything a public template already matches.
30-60 days
Hardening
Close supply-chain advisories. Secret scanning in CI and pre-commit. Block debug and VCS paths at the edge. Every public host gets a team against its name.
60-90 days
Operate continuously
Recurring recon diffed against this baseline. A standard for non-production environments. One executive number: Critical and High open under 30 days.
What You Keep
Scout findings belong to you. So does the roadmap.
Both views, the raw evidence, and the host inventory hand over at the end of the engagement. Executing the plan is a separate decision, and you can take it to anyone. We are vendor-neutral: no reseller margin, no platform to push.
Start Here
Request a Scout assessment. It begins with a short working session with the engineers who own the system.