SecurityBoat

TriNetra Platform · Exposure & Risk

Find what you're exposing — before attackers do.

ASM starts with a request, not a black-box crawl: you tell it exactly what to scan — a domain, an IP range, an ASN, or a cloud account — our security team reviews and approves it, and only then does anything run. Nothing scans without your scope confirmed first.

Subdomain Inventory

24 targets+ Scan ad-hoc
SubdomainClassScanRisk
assets.netbanking.aecm-corp.comLive · 200cloudComplete20
dev.payments.aecm-corp.comLive · 200devComplete45
api.shop.aecm-corp.comLive · 200apiComplete65
mail.payments.aecm-corp.comLive · 200infraComplete30
admin.payments.aecm-corp.comLive · 200adminComplete90
staging.aecm-corp.comLive · 200webComplete40
vpn.partner.aecm-corp.comLive · 200infraComplete70

The problem

Most organizations don't actually know their own internet footprint. Subsidiaries spin up cloud accounts without central IT's knowledge, developers stand up test environments and forget to tear them down, M&A drags in infrastructure nobody inventoried, and shadow IT accumulates quietly for years. Whatever nobody's watching is exactly what an attacker finds first — and a spreadsheet updated at the last audit doesn't help, because it was already stale the day it was saved.

How Attack Surface Management answers it

ASM's Dashboard opens on an exposure-posture ring and KPI tiles for the numbers that actually matter to an attacker — Subdomain Takeovers, Exposed Login Portals, Secrets Exposed, Weak TLS Hosts — alongside a Most Exposed Targets list and a Threat Posture radar. Every target gets there through Request a Scan: Add Target for a domain, IP, or ASN, or Cloud Target for a cloud/SaaS account across a 4-step wizard. Nothing scans until it's approved. Once running, the Scans tab tracks every pipeline state with an attributable trigger, and the Subdomains tab holds a living inventory that updates itself.

How it actually works

Posture at a glance.

Exposure rings, attributable scans, and a living subdomain inventory — and nothing scans until your scope is reviewed and approved.

0targets
Exposure posture

Watching 10 of 12 targets · 0 open findings

2 At RiskView latest scan →

How it works

Request a Scan — the real flow.

ASM's real tab bar — Dashboard for posture, Targets for the onboarded inventory, Scans for every pipeline run with its trigger, Subdomains for the living per-row inventory.

DashboardTargetsScansSubdomains

Add Target

Domain / IP / ASN

Pick the target type before entering a value.

Target Value

The domain, IP range, or ASN to onboard.

Monitoring schedule

Choose the default scan cadence for this target.

Freshness SLA override

Optional — override the default cadence for this specific target.

Note for reviewer

Optional — context for the security team approving the request.

Submit a target for review — our security team approves and runs the scan.

Cloud Target — 4-step wizard

Select ProviderAccount DetailsCredentialsValidate
AWS
Azure
GCP
Kubernetes
GitHub
Microsoft 365
MongoDB Atlas
Google Workspace
Infrastructure as Code
Container Registry
Oracle Cloud
Alibaba Cloud

Every scan, attributable

Scans

ScheduledManualWebhook
aecm-corp.comComplete2h ago
dev.payments.aecm-corp.comProfilingrunning
103.21.44.0/24Passive6h ago
assets.netbanking.aecm-corp.comComplete1d ago

A trigger on every scan — nothing runs as a mystery cron job.

Capabilities

What ships in the box.

Nothing scans without approval

Both Add Target and Cloud Target route through review before execution — the "Submit for review" copy on the Add Target tab isn't a formality, it's the actual gate.

A freshness SLA per target, not one global setting

Add Target lets you override the default monitoring cadence per target, so your crown-jewel production domain and a low-priority staging box don't share a schedule.

12 cloud and SaaS providers, one wizard

AWS, Azure, GCP, Kubernetes, GitHub, Microsoft 365, MongoDB Atlas, Google Workspace, Infrastructure as Code, Container Registry, Oracle Cloud, and Alibaba Cloud — each onboarded through the same 4-step Select Provider → Account Details → Credentials → Validate flow.

Every scan is attributable

The Scans tab's trigger column — Scheduled, Manual, or Webhook — means you always know why a scan ran, not just that it did.

A subdomain inventory with a monitor toggle per row

State, classification, source, scan status, tags, and risk score sit on every subdomain, with "Scan ad-hoc" available the moment something looks off.

The Threat Posture radar

Scored against the live inventory on the Dashboard, so posture reads as a shape you can compare over time, not a single number in isolation.

KPIs that mean something

The Dashboard leads with Subdomain Takeovers, Exposed Login Portals, Secrets Exposed, and Weak TLS Hosts — the exposures attackers actually use — not a generic vulnerability count.

FAQ

Common questions.

Only the first time a target is onboarded. Add Target and Cloud Target both route through a review-and-approve step before anything runs — after that, the target scans on its configured schedule, or on demand via "Scan ad-hoc" from the Subdomains tab.

See your real attack surface — all of it.

Tell SecurityBoat your primary domain. We'll walk you through the Request a Scan flow on your own scope — Add Target or Cloud Target — and show you what TriNetra ASM discovers within days.

Related: Digital Risk Protection · PTaaS · Bug Bounty · Ish