Skip to main content
own2pwn

EASM

Attack Surface

Everything you expose on the Internet, mapped and monitored continuously.

Discovery starts from a seed, one domain name, and widens in waves: what Certificate Transparency logs have published, what DNS answers in both directions, what WHOIS ties to the same registrant, then what open ports confirm. This page details that mechanism: the sources queried, the refresh cadence, and what happens to false positives.

Free account, hosted in the EU, one domain is enough
in, the whole surface out
1 domain
of multi-source discovery
14 plugins
continuous monitoring, not a yearly audit
24/7

Features

What continuous mapping sees of your exposure.

Automatic discovery from a single domain

You enter your root domain, the engine unrolls the rest. 14 discovery plugins cross Certificate Transparency, six public subdomain sources, DNS, WHOIS and reverse WHOIS, port scanning and service fingerprinting to surface the shadow IT nobody ever declared. No agent to install, no IP range to provide.

A live inventory of every exposed asset

Subdomains, IPs and ASNs, ports and services, TLS certificates, detected technologies, cloud buckets and storage: every asset reachable from the Internet and tied to your domain surfaces in the inventory, with its history. It is the real perimeter your CMDB doesn't have.

CyberScore and attack-path graph

A CyberScore from A to F sums up the state of your surface and tracks its trajectory over time. Assets and findings are linked together (shared certificates, DNS, cloud relationships) to reconstruct exploitation chains, each path ranked by severity with a blast radius.

Attack surface monitoring pricing.

Discovery

€0

  • Attack Surface module included in the EASM offering
  • In plain terms: the perimeter of a single domain name, 25 exposed assets at most.
  • 10 scans / mo
  • Multi-source discovery + more than 240 detection modules
  • CVE correlation and prioritisation by real exploitability
  • 2 AI-native validations / mo
  • Email alerts, 1 user
  • Free, no time limit and no credit card
Start for free
Recommended

Pro

€99 / mo

  • In plain terms: 5 domain names, 250 tracked exposed assets, 5 people on the account.
  • 100 scans / mo
  • 30 AI-native validations / mo
  • HMAC-signed webhooks (Slack, Teams, Discord, PagerDuty)
  • Jira, GitHub, GitLab, Slack integrations
  • PDF and CSV exports, API access (5 keys)
Subscribe

For businesses only, a company identifier is asked at the next step.

Business

€299 / mo

  • In plain terms: 15 domain names, 1,000 tracked exposed assets, no cap on scans.
  • 100 AI-native validations / mo
  • SSO, RBAC and role management
  • SIEM connector, custom integrations
  • Email support, prioritised handling
Subscribe

For businesses only, a company identifier is asked at the next step.

Enterprise

On request

  • In plain terms: the perimeter you set in the contract, no cap on domains or validations.
  • SSO / SAML, SCIM provisioning
  • Enhanced AI validation (extended reasoning)
  • GDPR-compliant DPA, master agreement and NIS2 guidance
  • A single point of contact: the pentester who runs it
Talk to a pentester

VAT not applicable (art. 293 B of the French tax code)

How it works

From setup to the first alert.

  1. 01

    The seed, and the boundary

    The only mandatory input is a root domain name. It plays two roles at once: the starting point of discovery, and the boundary of what we allow ourselves to attribute to you. Before the first pass you also set the maximum rate per host and the headers or cookies to attach to requests, enough to get through a WAF without waking it or to lift a geographic restriction.

  2. 02

    Passive sources, before touching anything

    The first wave generates no traffic towards you. Certificate Transparency first: every issued certificate publishes the names it covers, which gives away internal subdomains as soon as they get TLS. Then six public enumeration sources, DNS records, WHOIS and reverse WHOIS to tie other domains to the same registrant, and ASN data. By that point we already know what an attacker can learn about you without sending a single packet.

  3. 03

    Active confirmation, non-intrusive

    The second wave verifies what the first one assumed: name resolution, port scanning, service and version fingerprinting, vhost enumeration, web crawling, cloud storage detection across S3, Azure and GCP. No exploitation is replayed, no destructive payload is sent, redirects are disabled and a three-layer anti-SSRF guard stops the scanner from wandering into an internal network. A confirmed asset can open a new wave through its certificate or its ASN, until nothing new surfaces.

  4. 04

    The next pass, and what changed

    Every new pass is compared with the previous one. Assets and findings are deduplicated and reconciled: what already existed keeps its history and its first-detection date, what is no longer reproduced flips to resolved, and you only get what moved. The cadence is yours (cron or manual launch) within the plan limits: 10 passes a month on the free tier, 100 on Pro, no cap on Business.

Benefits

What a living inventory changes in your daily work.

01

Discovery that widens on its own

Discovery works in waves. The first one never touches your infrastructure: it queries Certificate Transparency logs, where every certification authority publishes the names covered by a certificate it issues, including the staging subdomain nobody declared. Add six public enumeration sources, DNS in both directions, WHOIS and reverse WHOIS to tie other domains to the same registrant. The next wave confirms what was found: name resolution, port scanning, service fingerprinting, vhost enumeration, web crawling. A confirmed asset becomes a seed again through its certificate or its ASN, and the wave after that starts from there. That loop is why the result always overflows the official inventory: nobody remembers to declare an asset, but a certification authority publishes it automatically.

02

Track a trajectory, not a snapshot

A yearly audit gives you a snapshot that is already stale the next day. Here the inventory stays alive: periodic or on-demand scans, history per asset, change detection, and a CyberScore from A to F to see whether your surface is improving or drifting. You don't discover a forgotten asset six months after it opened; the alert lands the day it appears, where your team already works.

03

A timestamped trail, not a screenshot

What an auditor asks for is not an inventory, it is proof the inventory is kept. So every asset carries its first and last detection date, every scan leaves its delta, and the CyberScore keeps its history: enough to show a six-month trajectory rather than a state as of the meeting date. PDF and CSV exports are done by section, which saves attaching 40 pages to justify one point. This is the raw material for the mapping part of Article 21 of NIS2, not the whole of compliance: governance, incident response and supply chain remain yours.

Overview

The platform in pictures.

EASM overview with the global CyberScore and the list of prioritised critical findings, NIS2 and PCI DSS tagsThe CyberScore up top, the Priority to handle list below: critical findings first, with their compliance tags. You know what to fix before reading anything.
Attack surface map: graph of discovered assets, nodes coloured by severityThe graph of discovered assets, coloured by severity. Handy to see at a glance what hangs at the end of the chain.
Inventory of exposed assets: type, identifier, risk level, first and last detectionThe inventory of exposed assets, with type, risk and first and last detection dates. What your CMDB doesn't have.
EASM scan management, scheduled and on demand, with status and progressScans scheduled or launched by hand, with status and progress. No maintenance window to negotiate.

Why own2pwn

Why this mapping is not one more scan.

What we refuse to attribute to your perimeter

A map is worth what its attribution is worth. An asset wrongly tied to you is an alert that does not concern you, and after three of those, a console nobody opens. So an asset only enters your inventory through a verifiable chain from a domain you declared: a certificate covering the name, a DNS record pointing to it, a shared WHOIS registrant, a cloud relationship. No attribution by name resemblance, no whole IP block added because the neighbour looks like you.

A closed false positive does not come back next pass

Detection is automated: nobody re-reads findings by hand before they reach you, so we do not promise zero false positives (human verification is the pentest, a separate offering). What we do hold is that noise does not pile back up. Findings are deduplicated from one pass to the next and reconciled with the previous state: a known finding does not fire another notification, and a finding no longer reproduced flips to resolved instead of sitting in the pile.

You set the cadence and the footprint

A scan scheduled via cron, a scan launched by hand from the interface or the API, or both. Between two passes nothing runs against your infrastructure. During a pass the per-host rate is capped and adjustable from 1 to 1000 requests per second: you arbitrate between a fast map and a near-zero footprint on a sensitive environment, without negotiating a maintenance window with the ops team.

Your exposure data stays under European law

The inventory of an attack surface is exactly the document you do not want leaving the building: it says where to hit. So it stays hosted in the EU, under European law, GDPR compliant, with strict per-customer isolation at the database level. Handing it to a US vendor exposes it to extraterritorial access requests, which is hard to defend in front of a NIS2 auditor.

Frequently asked questions

Your questions about attack surface monitoring.

What is the external attack surface, concretely?

It is everything your organisation exposes on the Internet that an attacker can reach without prior access: subdomains, IPs and ASN ranges, open ports and services, TLS certificates, web applications, admin interfaces, cloud storage across S3, Azure or GCP. The catch is that this surface always spills over the official inventory: staging left online, a bucket created off-process, a subsidiary's asset, a forgotten subdomain. The Attack Surface module starts from a single root domain and reconstructs that real perimeter, not the one you think you have.

How do you discover my assets from a single domain?

You enter your root domain, the scan starts. No agent to install, no cloud access to provide. We combine 14 discovery plugins: passive sources (Certificate Transparency via crt.sh, six public subdomain sources, WHOIS and reverse WHOIS, DNS), then non-intrusive active steps (port scanning, service fingerprinting, vhost enumeration, web crawling, cloud detection for S3/Azure/GCP). Step by step, we pull up subdomains, IPs, ports, TLS certificates, technologies and exposed services. The scope stays under your control: we unroll from the domains you declare, no reckless attribution to entities that aren't yours.

Do you detect cloud assets (AWS, Azure, GCP)?

Yes. Public S3 buckets, Azure Blob Storage, GCP Storage, exposed instances, subdomains pointing to a CDN or a cloud host. Dedicated modules also check storage ACLs and metadata leaks. If a cloud asset is reachable from the Internet and tied to your domain, it surfaces in the inventory just like the rest of your surface.

How often is my surface re-scanned?

You schedule periodic scans (cron) and trigger on-demand scans from the interface or the API. On every pass, you get the delta: new asset, port that opens, new CVE on an exposed service, finding resolved. Volumes depend on the plan: 10 scans a month on Discovery, 100 on Pro, unlimited on Business and Enterprise. You track your usage in real time.

What is the CyberScore?

A grade from A to F that sums up the state of your attack surface from the discovered assets and open findings, weighted by severity. It serves two purposes: giving an immediate read to a non-technical audience (the board, an auditor) and tracking a trajectory over time, to see whether your surface improves after a remediation effort or drifts as new assets appear. It is not a compliance grade, it is an exposure indicator.

What is the attack-path graph for?

An isolated finding doesn't tell you much. The graph links your assets and findings together (shared certificates, DNS records, cloud relationships) to reconstruct exploitation chains: this subdomain leads to this service, which shares a certificate with that other asset. Each path is ranked by severity, with a blast radius measuring what falls behind a compromised asset. You prioritise on what actually leads somewhere, not on a flat list of CVEs.

Could the scan disrupt my production?

Discovery and mapping are non-intrusive by design: no exploitation, no destructive payload, redirects disabled, per-host rate capped (adjustable from 1 to 1000 req/s), three-layer anti-SSRF guard. You can add it to your perimeter without coordinating a maintenance window with the ops team. For each run, you also tune custom headers, cookies and the maximum per-host rate, useful to respect a WAF or a sensitive environment.

How does this module help my NIS2 compliance?

Article 21 of NIS2 mandates risk management that includes asset mapping and continuous monitoring of the exposed surface, shadow IT included. The Attack Surface module addresses this part directly: a live inventory of exposed assets, change detection, a CyberScore to track the trajectory, PDF and CSV reports exportable for your auditors. To be clear: it doesn't cover all of NIS2 on its own (governance, incident response, supply chain remain on you). It addresses the knowing and controlling what you expose part.

Is there a minimum term, and how do I cancel?

No minimum term. The subscription is monthly or annual (annual works out at ten months paid), renewed tacitly at each due date, and you cancel it at any time, with no justification to give: either you do it yourself from your billing area, or you write to contact@own2pwn.fr and the answer comes within 24 hours. No notice period to serve: cancellation takes effect at the end of the current billing period, and you keep access until then. In return, that period is not refunded pro rata. That is not a sales promise, it is article 7 of the terms of sale.

Do I need a credit card for the free plan?

No. The Discovery plan opens from the sign-up form, with no payment method: no card to enter, no counter starting after fourteen days. It is not a trial but a free plan with no time limit and its own quotas (1 domain, 25 tracked assets, 10 scans per month). The Attack Surface module is included in it, not sold separately. A card only comes into play if you move to a paid plan, and payment happens on own2pwn.fr, by card only.

How long between payment and actual access?

Access opens immediately after the payment is validated. In practice: as soon as the payment is confirmed, the subscription is attached to your account and the plan quotas apply, with no manual step in between. If you subscribe without an own2pwn account yet, the payment creates one and you get an email to set your password: access is live as soon as that is done. If anything gets stuck, write to contact@own2pwn.fr, the answer comes within 24 hours.

Can I change plan mid-subscription?

Yes, and without starting over: the account, the domains you declared and the scan history stay in place, only the quotas change. Modules are never billed separately: Attack Surface comes with the EASM subscription, so changing plan moves the quotas of every module at once. You request the change by email to contact@own2pwn.fr, stating the plan you want and the date it should take effect; the answer comes within 24 hours. What is settled on the billing side is that the period already paid for is not refunded pro rata (article 7 of the terms of sale); the exact amount and the effective date of the new plan are confirmed to you in writing before anything is validated.

Want to see your attack surface?

One root domain is enough to start the mapping. To talk it through first, a reply lands within 24 hours.