SecurityBoat

Solutions / Use Cases

The network diagram is a snapshot. Your infrastructure isn't.

Ask most security teams for a current map of every domain, IP range, and ASN their organization is responsible for, and the honest answer is a spreadsheet that's months out of date. Subsidiaries provision infrastructure without telling central IT. A subnet from an acquisition never gets formally inventoried. A test environment goes up for a sprint and never comes down. None of that shows up until it's already exposed.

Where this actually breaks

  • Internal/external network segments and legacy protocols rarely get the same test rigor as customer-facing web apps — harder to scope, easier to defer.

  • An ASN's announced netblocks include infrastructure nobody remembers owning — exactly the infrastructure with the weakest controls.

  • Point-in-time scans miss what changes between them; a port closed at scan time can be open a week later with nobody watching.

  • Network pentest findings and external attack-surface findings usually live in two different tools, so nobody sees the full picture.

How TriNetra covers it

Attack Surface Management

ASM's Add Target flow is the actual onboarding mechanic: pick a target type — Domain, IP, or ASN — enter the value, set a monitoring schedule and a freshness SLA override, and optionally leave a note for the reviewer. The product copy is exact: “Submit a target for review — our security team approves and runs the scan.” An ASN auto-expands to its announced netblocks, pulling in infrastructure you forgot you were responsible for. From there, ASM's live subdomain inventory tracks every asset with a classification tag (web / api / admin / dev / infra / cloud), live/down status, last HTTP response, and a per-asset monitoring toggle — an inventory that updates itself instead of aging into a spreadsheet.

Scans

ScheduledManualWebhook
aecm-corp.comComplete2h ago
dev.payments.aecm-corp.comProfilingrunning
103.21.44.0/24Passive6h ago
assets.netbanking.aecm-corp.comComplete1d ago

A trigger on every scan — nothing runs as a mystery cron job.

PTaaS

PTaaS scopes internal and external network engagements like any other asset class — black, grey, or white box, tracked through the same 12-state lifecycle, with a Coverage tab measuring methodology completion against a named framework instead of “we looked at it.”

Agentic Pentest

Agentic Pentest matters most here because network attack surfaces expand faster than tester-hours scale — a coordinated agent crew handles reconnaissance at a pace no human team matches alone, surfaced into the real Human Review Queue kanban (Agent-Surfaced → Under Human Review → Confirmed) so every conclusion that reaches you has passed a human.

The workflow

  1. 1

    Submit a Domain, IP, or ASN target through Add Target — set the monitoring schedule and freshness SLA.

  2. 2

    The security team approves scope; the scan runs and populates the subdomain and asset inventory.

  3. 3

    A PTaaS engagement scopes deeper manual testing against what ASM found reachable.

  4. 4

    Agentic Pentest keeps recon current on newly discovered segments between formal cycles.

Ready when you are

Submit your first ASN and see what's actually announced under it