ISO 27001 CertifiedSOC 2 Compliant A product by Visit the Trust Center
Agent 04 · Attack surface

Every way in, found before they use it.

Give the ASM agent a single domain. It maps everything attached to you, subdomains, IPs, ports, certificates, technologies and the forgotten hosts nobody remembers, from the outside in, continuously, exactly the way an attacker would.

The agent, thinking

One domain in. Your whole exposure out.

From a single seed to a ranked map of forgotten, exploitable hosts. This is the ASM agent reasoning through one run, condensed.

Attack‑surface agent · reasoning live
0
Assets mapped from a single seed domain — subdomains + resolved IPs
0
Services fingerprinted — open ports, technologies and live URLs
0
Agents to install, mapped from the outside in
The product · live view

One seed. The map draws itself.

This is the recon console your team signs into. Feed it acme-corp.com and the agent charts everything attached to it, subdomains, IPs, certificates, open ports, the way an attacker would. Click any node for the dossier: what it is, how we found it, and the verdict in plain English.

app.venushawk.ai/recon · acme-corp.comLive

Product preview: the VenusHawk recon console. The seed domain acme-corp.com sits at the centre of a live map while discovered assets, subdomains, IPs, a wildcard certificate and an exposed Elasticsearch port, radiate outward. Selecting an asset shows what it is, how it was found and a plain-English risk verdict. A discovery stream appends newly found assets. Simulated data.

Seed acme-corp.com discovering · pass 14 27 assets · 5 risky
Discovery streamlive · hover to pause

    Simulated data · product preview

    The blind spot

    You can’t defend what you can’t see.

    Attackers don’t work from your asset list. They map what’s actually exposed, and the gaps in your inventory are exactly where they start.

    01

    Shadow IT

    Marketing spins up a subdomain, a team ships a side app, and none of it ever reaches your asset inventory.

    02

    Cloud & M&A drift

    Every acquisition, cloud account and quick deploy widens the surface faster than anyone can track.

    03

    It changes daily

    Certificates lapse, ports open, staging goes live. A yearly audit is stale the week after it ships.

    Discovery

    We find what your inventory forgot.

    Start with one domain. The agent reaches far past what you list, the way an attacker enumerates you.

    Internet-scale scraping

    We scrape the internet at large to attribute the maximum number of subdomains and hosts back to you.

    Brute-force discovery

    Hosts that never surface in scraping are found by directed brute-forcing.

    Name permutation

    api.acme.com → api-stage → api-dev-1…, the variants attackers guess, generated and probed.

    Scheduled monitoring & diff

    Recurring scans surface only what’s new since last time, fresh hosts, ports and findings.

    Watch it work

    A scan, streaming live.

    Every run walks the same pipeline an attacker would — enumerate, permute, probe, fingerprint — and streams each discovery the second it lands.

    app.venushawk.ai/scans/run-4471 · acme.comLive

    A simulated scan run: the stage timeline advances from subdomain discovery through port scanning to vulnerability detection while a terminal streams each discovery and counters tally 128 subdomains, 54 services, 31 IPs and 6 vulnerabilities.

    Simulated data · product preview

    Per-asset intelligence

    Open any asset. See what an attacker sees.

    Every discovered host comes fully profiled, technologies, live screenshot, certificate, ASN, open ports and its vulnerabilities, in one dossier.

    Asset profile · discovered outside-inlive
    staging-admin.acme.comNot in inventory
    IP
    203.0.113.24
    ASN
    AS14061 · DigitalOcean
    Ports
    22 · 80 · 443 · 8080
    Status
    200 OK
    Certificate
    Expired 41 days ago
    CNAME
    → legacy-lb.acme.net
    nginx 1.18PHP 7.2 · EOLWordPress 5.4jQuery 1.12
    HIGHExposed admin panel behind an expired certificate.AI fix · retest

    Then slice the whole surface the way you actually reason about it:

    HostIPTechnologyPortStatus codeCNAMECustom label
    Triage

    Proof, a fix, and a retest, in one place.

    Each vulnerability lands with the request, the response and a screenshot as evidence, plus an AI-written remediation for the exact stack on the host — here, an SSRF reaching AWS instance credentials. Patch it, click retest, and watch it flip to Fixed.

    app.venushawk.ai/vulnerabilities/VH-2214 · acme.com
    Critical SSRF → AWS metadata credential theft api.acme.com · POST /v2/fetch · CVSS 9.1 Open
    POST /v2/fetch HTTP/1.1
    Host: api.acme.com
    Content-Type: application/json
    
    {"url":"http://169.254.169.254/latest/meta-data/iam/security-credentials/"}
    HTTP/1.1 200 OK
    Content-Type: application/json
    
    {
      "Code": "Success",
      "AccessKeyId": "ASIA5EXAMPLE7QODK3RN",
      "SecretAccessKey": "wJalr…bPxRfiCY",
      "Token": "IQoJb3JpZ2luX2VjEND…",
      "Expiration": "2026-08-12T18:42:10Z"
    }
    curl -s https://api.acme.com/v2/fetch \
      -H 'Content-Type: application/json' \
      -d '{"url":"http://169.254.169.254/latest/meta-data/iam/security-credentials/acme-api-role"}'
    Method POSTStatus 200Detected 2d ago
    AI Fix · generated for the /v2/fetch URL handler

    Remediation — server-side request forgery

    1. Allow-list destination hosts; reject RFC-1918, loopback and link-local ranges — block 169.254.169.254 outright.

    2. Resolve the hostname first, then validate the resolved IP before connecting (defeats DNS-rebinding).

    3. Enforce IMDSv2 (hop-limit 1, token-required) so the metadata endpoint refuses proxied reads.

    4. Scope the instance IAM role to least privilege and rotate the exposed ASIA… credentials now.

    AI sources · OWASP SSRF prevention · CWE-918 · AWS IMDSv2 docs

    Simulated data · product preview · click Retest to verify the fix

    Change detection

    The surface moves. So does the agent.

    Put any domain into continuous monitoring and every re-scan surfaces just the delta, the new door, the freshly opened port, the certificate that lapsed overnight.

    Change logNew since last scan · ranked
    AS-4471New hoststaging-admin.acme.com appeared and is publicly reachable.Profiled, ranked HIGH, owner alerted. Triaged
    AS-4468Open portPort 8080 opened on api.acme.com since the last scan.Flagged; service fingerprinted and checked. Triaged
    AS-4463Expired certThe TLS certificate on pay.acme.com lapsed two days ago.Caught the same day; renewal raised. Triaged
    AS-4459New vulnAn exposed admin panel on a forgotten subdomain.Evidence captured; AI fix attached. Triaged
    Why it’s different

    The outside-in view, wired to everything else.

    Most tools inventory only what you tell them about. VenusHawk maps what’s actually exposed, and connects it to the rest of the constellation.

    Attacker’s-eye view
    Mapped from the outside in, with no agents to install and nothing to configure on your hosts.
    Finds the forgotten
    Scraping, brute-force and permutation surface hosts that never appear in any inventory.
    Always current
    Continuous re-scans show the delta: you see change the day it happens, not at the next audit.
    Proof and a fix
    Every finding carries evidence, an AI remediation and a one-click retest.
    Wired to the code
    Hand an exposed app straight to the Code & App Security agent to test it for real.
    One engine, many surfaces
    The same brain ties your surface to code, data and dark-web exposure.
    Early access

    Bring this agent into your constellation.

    VenusHawk is rolling out to lighthouse customers and design partners. Tell us a little about your environment and we’ll see how we can accommodate you.