Solutions · CyberSec · Preempt

Know every door you have left open to the internet.

External Surface Defense traces every domain, DNS record and exposed endpoint you own to the workload behind it, finds the ones nobody listed, and classifies how exposed each one is, with the control in front of it named.

More of your internet-facing surface traced to what sits behind it.

  • More entry points traced to the workload behind them. Measured by ESC, External Surface Coverage.
  • Fewer exposed endpoints with no named control. Measured by exposed endpoints with no named control.
  • Fewer dangling DNS records. Measured by dangling DNS references.
ESC · External Surface Coverageasset spreadsheets and point-in-time external scansup against your baseline · every gap shown as a gap

Supporting KPIs

Entry points traced to their workload ↑

Share of internet-facing entry points traced, hop by hop, to the workload that serves them

twin

Untraced entry points ↓

Entry points whose route to a workload has a gap the twin cannot close

twin

Exposed endpoints with no named control ↓

Exposed endpoints with no control, such as a WAF, identified in front of them

twin

Dangling DNS references ↓

DNS records pointing at resources that no longer exist

twin

Baselines are set in the 30-day diagnostic. Targets are committed in the 90-day scorecard. A KPI we cannot measure is reported as UNMEASURED.

The door nobody listed is the one that gets used.

Your external surface is whatever the internet can reach, not whatever is on the asset list. A test environment given a public address for a week. A subdomain created for a campaign. A load balancer left running after a migration.

Read why

Outside-in scans see the door but not what is behind it. They cannot tell a marketing page from a build server holding deploy credentials, so every open port looks the same.

And a DNS record that still points at a resource you deleted is an invitation: whoever claims that resource inherits your name.

What it costs

  • Exposed assets that exist on no inventory and in no one's ownership.
  • Exposure ranked by port number rather than by what sits behind the port.
  • Dangling DNS records that let someone else speak under your domain.

An exposed endpoint with no name.

  • sg-0f3a41 · ingress tcp/8080 · src 0.0.0.0/0 · observed · as of 51 min
  • jenkins-01 · no DNS name · found from the infrastructure side
  • exposure class: open to the internet · control in front: none named
  • behind it: deploy credentials that reach s3://hl-cardholder, through path P-0198

illustrative console output · the categories and the final line are the contract

The surface as the internet sees it, and what sits behind each door.

External Surface Defense runs on SecSemantic's twin, so every entry point is traced inward to the workload and the business service it exposes.

Every route from the internet, through domain, DNS, CDN, WAF, load balancer and target group, is traced to the workload that serves it, each hop cited to the configuration that proves it. Gaps are shown as gaps.

What you get

  • An external surface inventory, every entry point traced to its workload
  • Exposed assets with no DNS name, found and assigned owners
  • An exposure class and named control for every exposed endpoint
  • Dangling DNS findings with their fix

Industry lens

Customer-facing and payment endpoints traced first, framed for PCI DSS scope.

What it is not

Not an outside-in scanner or a penetration test. It reads your configuration and DNS, and never attacks.

FAQ

Do you scan us from the outside?

No. The surface is read from your own DNS and cloud configuration, and traced inward. Nothing is probed or attacked.

How is this different from an external attack surface scanner?

A scanner sees the door. External Surface Defense also sees what is behind it: the workload, the credentials it holds and the business service it exposes, so exposure is ranked by consequence.

How do you find assets that have no DNS name?

By enumerating from the infrastructure side: every public address, load balancer and exposed security group in your cloud accounts, whether or not a name points at it.

Why does dangling DNS matter?

A record that points at a deleted resource can be claimed by anyone who creates that resource, and then they answer under your domain.

How External Surface Defense is delivered

A capability, the pod that runs it with you, and a scorecard you hold us to.

  • Diagnostic · days 0 to 30, at no cost.

    The twin is launched with read-only credentials and the coverage report arrives within 30 minutes. Your external surface is traced to its workloads, unnamed exposures and dangling DNS are found, and every KPI baseline is measured.

  • Outcome · days 30 to 90.

    Untraced entry points are closed or explained, missing controls are added, and dangling records are removed with your teams.

  • The Semantic Loop · from day 90.

    New entry points are flagged as they appear and traced before anyone has to ask.

The pod

two senior engineers and a fractional CISO advisor

  • Forward-deployed security engineer.

    Deploys the twin, connects your DNS and cloud accounts, and owns the KPI baseline with you.

  • Exposure analyst.

    Turns the surface inventory into owned, closed findings and tracks each to verified closure.

  • Fractional CISO advisor.

    Owns the 90-day scorecard with your leadership and chairs the day-90 review.

What runs underneath

SecSemantic's Sentinel: external attack surface, network reachability, business context and crown jewels, and findings and coverage. Insights presents the surface, read-only.

Count every door you have open.

In the diagnostic we trace every domain and exposed endpoint you own to what sits behind it, and show you the ones nobody listed.

  • SOC 2Type 2
  • HIPAACompliant
  • GDPRCompliant
  • ISO 270012013
  • ISO 90012015
  • ISO 200002018
  • ISO 134852016