Skip to main content
own2pwn
Back to the EASM platform

Attack Surface

Everything you expose on the Internet, mapped and monitored continuously.

You enter your root domain, we pull up your entire exposed surface: subdomains, IPs and ASNs, ports and services, TLS certificates, technology fingerprints, cloud storage across S3, Azure and GCP. The map stays alive, a CyberScore from A to F tracks the trajectory, and the alert lands the moment an asset appears or a port opens.

1 domain
in, the whole surface out
14 plugins
of multi-source discovery
24/7
continuous monitoring, not a yearly audit

Fonctionnalités

Tout ce qu'il faut pour sécuriser, sans le superflu.

Automatic discovery from a single domain

You enter your root domain, the engine unrolls the rest. 14 discovery plugins cross Certificate Transparency, six public subdomain sources, DNS, WHOIS and reverse WHOIS, port scanning and service fingerprinting to surface the shadow IT nobody ever declared. No agent to install, no IP range to provide.

A live inventory of every exposed asset

Subdomains, IPs and ASNs, ports and services, TLS certificates, detected technologies, cloud buckets and storage: every asset reachable from the Internet and tied to your domain surfaces in the inventory, with its history. It is the real perimeter your CMDB doesn't have.

Cloud detection across S3, Azure and GCP

Public S3 buckets, Azure Blob Storage, GCP Storage, exposed instances, subdomains pointing to a CDN or a cloud host. Dedicated modules also check storage ACLs and metadata leaks. The bucket created off-process surfaces like the rest.

Comment ça marche

Du setup à la première alerte.

  1. 01

    You enter a domain

    A single root domain name in, for example acme.com. No agent to install, no IP range to provide, no cloud access to connect. The scan starts right away. You stay in control of the scope: we follow the chain from what you give us, no reckless attribution of assets that aren't yours.

  2. 02

    We unroll your entire exposed surface

    14 discovery plugins start from that domain and rebuild what an attacker would see: subdomains (via Certificate Transparency and six public sources), DNS records, IPs and ASNs, ports and services, technology fingerprints, cloud storage across S3, Azure and GCP, TLS certificates. The forgotten subdomains, the pre-prod environments left online, the open bucket: they all surface in the inventory. Discovery is included from the free tier.

  3. 03

    Mapping, CyberScore and attack paths

    Every discovered asset is enriched and linked to the others. The CyberScore from A to F sums up the state of the surface, the graph links assets and findings through shared certificates, DNS and cloud relationships, and the attack paths are ranked by severity with a blast radius. You see at a glance where to look first and what falls behind a compromised asset.

  4. 04

    Continuous monitoring, an alert on the first change

    Scans run continuously and on demand, and change detection flags every new subdomain, every port that opens, every CVE that touches an exposed service. The alert lands the same day in Slack, Teams, Jira, GitHub, PagerDuty or a signed webhook, not at the next yearly audit. This is exactly the mapping and continuous monitoring expected by Article 21 of NIS2.

Bénéfices

L'impact concret pour vos équipes.

01

Know what you actually expose

The staging subdomain left online after a project, the cloud bucket created off-process, a subsidiary's instance, the expired certificate on an old app: these are the first doors an attacker tries. We start from a single root domain and pull up the whole chain. 14 discovery plugins cross Certificate Transparency, DNS, WHOIS, passive subdomain sources, port scanning and service fingerprinting to reconstruct your real perimeter, not the one in your spreadsheet. Every new scan compares the inventory to the previous state: a new asset, a port that opens, a service that changes surfaces on its own.

02

Track a trajectory, not a snapshot

A yearly audit gives you a snapshot that is already stale the next day. Here the inventory stays alive: periodic or on-demand scans, history per asset, change detection, and a CyberScore from A to F to see whether your surface is improving or drifting. You don't discover a forgotten asset six months after it opened; the alert lands the day it appears, where your team already works.

03

Keep the continuous map your auditor asks for

Article 21 of NIS2 calls for asset mapping and continuous monitoring of the exposed surface, shadow IT included. A quarterly spreadsheet can't keep up with a surface that moves every week. You export reports as PDF and CSV by section, CyberScore included, to hand straight to an auditor or the board. Data hosted in the EU, under European law, designed by an OSWE-certified pentester.

Aperçu

La plateforme en images.

EASM overview with the global CyberScore and the list of prioritised critical findings, NIS2 and PCI DSS tags
EASM overview with the global CyberScore and the list of prioritised critical findings, NIS2 and PCI DSS tagsThe CyberScore up top, the Priority to handle list below: critical findings first, with their compliance tags. You know what to fix before reading anything.
Attack surface map: graph of discovered assets, nodes coloured by severity
Attack surface map: graph of discovered assets, nodes coloured by severityThe graph of discovered assets, coloured by severity. Handy to see at a glance what hangs at the end of the chain.
Inventory of exposed assets: type, identifier, risk level, first and last detection
Inventory of exposed assets: type, identifier, risk level, first and last detectionThe inventory of exposed assets, with type, risk and first and last detection dates. What your CMDB doesn't have.
EASM scan management, scheduled and on demand, with status and progress
EASM scan management, scheduled and on demand, with status and progressScans scheduled or launched by hand, with status and progress. No maintenance window to negotiate.

Pourquoi own2pwn

Ce qu'on fait différemment.

Hosted in the European Union

Your exposure data stays under European law: hosted in the EU, GDPR compliant, with strict per-customer isolation at the database level. Handing the map of your attack surface to a US vendor exposes it to extraterritorial access requests; your inventory stays hosted in the EU.

Designed by an OSWE-certified pentester

The discovery logic follows what an attacker enumerates first, not a generic checklist copied from a framework. Prioritisation reflects real exploitability: an exposed admin console ranks ahead of a high CVSS hidden behind a WAF. It is an offensive method turned into SaaS, not a dashboard dreamed up by marketers.

AI where it actually helps

No chatbot. AI is used to rank more than 240 detection modules by real risk (CVE correlation, CISA KEV and EPSS prioritisation, dedup, attack paths), so you handle what matters first. Detection stays automated: we don't promise zero false positives, and human verification of findings is our pentests, a separate offering.

Non-intrusive scans, production-safe

The scan is built to run on production without taking it down: no exploitation replayed, three-layer anti-SSRF guard, per-host rate limits adjustable from 1 to 1000 req/s. You add it to your perimeter without coordinating a maintenance window with the ops team. A single domain in, no agent to install, no cloud access to connect.

Des tarifs lisibles, sans surprise.

Discovery
€0
  • Attack Surface module included in the EASM offering
  • 1 monitored domain, up to 25 assets
  • 10 scans / mo
  • Multi-source discovery + more than 240 detection modules
  • CVE correlation, KEV and EPSS prioritisation
  • 2 AI-native validations / mo
  • Email alerts, 1 user
  • Free, no time limit
Start for free
Recommandé
Pro
€99 / mo
  • Up to 5 domains, 250 tracked assets
  • 100 scans / mo
  • 30 AI-native validations / mo
  • HMAC-signed webhooks (Slack, Teams, Discord, PagerDuty)
  • Jira, GitHub, GitLab, Slack integrations
  • PDF and CSV exports, API access (5 keys), up to 5 users
  • VAT not applicable (art. 293 B of the French tax code)
Subscribe
Business
€299 / mo
  • Up to 15 domains, 1,000 tracked assets
  • Unlimited scans
  • 100 AI-native validations / mo
  • SSO, RBAC and role management
  • SIEM connector, custom integrations
  • Email support, prioritised handling
  • VAT not applicable (art. 293 B of the French tax code)
Subscribe
Enterprise
On request
  • Unlimited domains, scans, assets and AI validations
  • SSO / SAML, SCIM provisioning
  • Enhanced AI validation (extended reasoning)
  • GDPR-compliant DPA, master agreement and NIS2 guidance
  • A single point of contact: the pentester who runs it
Talk to a pentester

Questions fréquentes

Ce que vous voulez probablement savoir.

What is the external attack surface, concretely?

It is everything your organisation exposes on the Internet that an attacker can reach without prior access: subdomains, IPs and ASN ranges, open ports and services, TLS certificates, web applications, admin interfaces, cloud storage across S3, Azure or GCP. The catch is that this surface always spills over the official inventory: staging left online, a bucket created off-process, a subsidiary's asset, a forgotten subdomain. The Attack Surface module starts from a single root domain and reconstructs that real perimeter, not the one you think you have.

How do you discover my assets from a single domain?

You enter your root domain, the scan starts. No agent to install, no cloud access to provide. We combine 14 discovery plugins: passive sources (Certificate Transparency via crt.sh, six public subdomain sources, WHOIS and reverse WHOIS, DNS), then non-intrusive active steps (port scanning, service fingerprinting, vhost enumeration, web crawling, cloud detection for S3/Azure/GCP). Step by step, we pull up subdomains, IPs, ports, TLS certificates, technologies and exposed services. The scope stays under your control: we unroll from the domains you declare, no reckless attribution to entities that aren't yours.

Do you detect cloud assets (AWS, Azure, GCP)?

Yes. Public S3 buckets, Azure Blob Storage, GCP Storage, exposed instances, subdomains pointing to a CDN or a cloud host. Dedicated modules also check storage ACLs and metadata leaks. If a cloud asset is reachable from the Internet and tied to your domain, it surfaces in the inventory just like the rest of your surface.

How often is my surface re-scanned?

You schedule periodic scans (cron) and trigger on-demand scans from the interface or the API. On every pass, you get the delta: new asset, port that opens, new CVE on an exposed service, finding resolved. Volumes depend on the plan: 10 scans a month on Discovery, 100 on Pro, unlimited on Business and Enterprise. You track your usage in real time.

What is the CyberScore?

A grade from A to F that sums up the state of your attack surface from the discovered assets and open findings, weighted by severity. It serves two purposes: giving an immediate read to a non-technical audience (the board, an auditor) and tracking a trajectory over time, to see whether your surface improves after a remediation effort or drifts as new assets appear. It is not a compliance grade, it is an exposure indicator.

What is the attack-path graph for?

An isolated finding doesn't tell you much. The graph links your assets and findings together (shared certificates, DNS records, cloud relationships) to reconstruct exploitation chains: this subdomain leads to this service, which shares a certificate with that other asset. Each path is ranked by severity, with a blast radius measuring what falls behind a compromised asset. You prioritise on what actually leads somewhere, not on a flat list of CVEs.

Could the scan disrupt my production?

Discovery and mapping are non-intrusive by design: no exploitation, no destructive payload, redirects disabled, per-host rate capped (adjustable from 1 to 1000 req/s), three-layer anti-SSRF guard. You can add it to your perimeter without coordinating a maintenance window with the ops team. For each run, you also tune custom headers, cookies and the maximum per-host rate, useful to respect a WAF or a sensitive environment.

How does this module help my NIS2 compliance?

Article 21 of NIS2 mandates risk management that includes asset mapping and continuous monitoring of the exposed surface, shadow IT included. The Attack Surface module addresses this part directly: a live inventory of exposed assets, change detection, a CyberScore to track the trajectory, PDF and CSV reports exportable for your auditors. To be clear: it doesn't cover all of NIS2 on its own (governance, incident response, supply chain remain on you). It addresses the knowing and controlling what you expose part.

Parlons de votre besoin.

Démo, devis ou question technique : réponse sous 48 h ouvrées.