Every way in, found before they use it.
Give the ASM agent a single domain. It maps everything attached to you, subdomains, IPs, ports, certificates, technologies and the forgotten hosts nobody remembers, from the outside in, continuously, exactly the way an attacker would.
One domain in. Your whole exposure out.
From a single seed to a ranked map of forgotten, exploitable hosts. This is the ASM agent reasoning through one run, condensed.
One seed. The map draws itself.
This is the recon console your team signs into. Feed it acme-corp.com and the agent charts everything attached to it, subdomains, IPs, certificates, open ports, the way an attacker would. Click any node for the dossier: what it is, how we found it, and the verdict in plain English.
Product preview: the VenusHawk recon console. The seed domain acme-corp.com sits at the centre of a live map while discovered assets, subdomains, IPs, a wildcard certificate and an exposed Elasticsearch port, radiate outward. Selecting an asset shows what it is, how it was found and a plain-English risk verdict. A discovery stream appends newly found assets. Simulated data.
Simulated data · product preview
You can’t defend what you can’t see.
Attackers don’t work from your asset list. They map what’s actually exposed, and the gaps in your inventory are exactly where they start.
Shadow IT
Marketing spins up a subdomain, a team ships a side app, and none of it ever reaches your asset inventory.
Cloud & M&A drift
Every acquisition, cloud account and quick deploy widens the surface faster than anyone can track.
It changes daily
Certificates lapse, ports open, staging goes live. A yearly audit is stale the week after it ships.
We find what your inventory forgot.
Start with one domain. The agent reaches far past what you list, the way an attacker enumerates you.
Internet-scale scraping
We scrape the internet at large to attribute the maximum number of subdomains and hosts back to you.
Brute-force discovery
Hosts that never surface in scraping are found by directed brute-forcing.
Name permutation
api.acme.com → api-stage → api-dev-1…, the variants attackers guess, generated and probed.
Scheduled monitoring & diff
Recurring scans surface only what’s new since last time, fresh hosts, ports and findings.
A scan, streaming live.
Every run walks the same pipeline an attacker would — enumerate, permute, probe, fingerprint — and streams each discovery the second it lands.
A simulated scan run: the stage timeline advances from subdomain discovery through port scanning to vulnerability detection while a terminal streams each discovery and counters tally 128 subdomains, 54 services, 31 IPs and 6 vulnerabilities.
Simulated data · product preview
Open any asset. See what an attacker sees.
Every discovered host comes fully profiled, technologies, live screenshot, certificate, ASN, open ports and its vulnerabilities, in one dossier.
Then slice the whole surface the way you actually reason about it:
Proof, a fix, and a retest, in one place.
Each vulnerability lands with the request, the response and a screenshot as evidence, plus an AI-written remediation for the exact stack on the host — here, an SSRF reaching AWS instance credentials. Patch it, click retest, and watch it flip to Fixed.
POST /v2/fetch HTTP/1.1 Host: api.acme.com Content-Type: application/json {"url":"http://169.254.169.254/latest/meta-data/iam/security-credentials/"}
HTTP/1.1 200 OK Content-Type: application/json { "Code": "Success", "AccessKeyId": "ASIA5EXAMPLE7QODK3RN", "SecretAccessKey": "wJalr…bPxRfiCY", "Token": "IQoJb3JpZ2luX2VjEND…", "Expiration": "2026-08-12T18:42:10Z" }
curl -s https://api.acme.com/v2/fetch \ -H 'Content-Type: application/json' \ -d '{"url":"http://169.254.169.254/latest/meta-data/iam/security-credentials/acme-api-role"}'
Remediation — server-side request forgery
1. Allow-list destination hosts; reject RFC-1918, loopback and link-local ranges — block 169.254.169.254 outright.
2. Resolve the hostname first, then validate the resolved IP before connecting (defeats DNS-rebinding).
3. Enforce IMDSv2 (hop-limit 1, token-required) so the metadata endpoint refuses proxied reads.
4. Scope the instance IAM role to least privilege and rotate the exposed ASIA… credentials now.
Simulated data · product preview · click Retest to verify the fix
The surface moves. So does the agent.
Put any domain into continuous monitoring and every re-scan surfaces just the delta, the new door, the freshly opened port, the certificate that lapsed overnight.
The outside-in view, wired to everything else.
Most tools inventory only what you tell them about. VenusHawk maps what’s actually exposed, and connects it to the rest of the constellation.
- Attacker’s-eye view
- Mapped from the outside in, with no agents to install and nothing to configure on your hosts.
- Finds the forgotten
- Scraping, brute-force and permutation surface hosts that never appear in any inventory.
- Always current
- Continuous re-scans show the delta: you see change the day it happens, not at the next audit.
- Proof and a fix
- Every finding carries evidence, an AI remediation and a one-click retest.
- Wired to the code
- Hand an exposed app straight to the Code & App Security agent to test it for real.
- One engine, many surfaces
- The same brain ties your surface to code, data and dark-web exposure.
They work better together.
Every agent feeds the same brain. Findings here correlate with the rest of the constellation.
Bring this agent into your constellation.
VenusHawk is rolling out to lighthouse customers and design partners. Tell us a little about your environment and we’ll see how we can accommodate you.
