External attack surface management
What this category covers, and where an automated external assessment sits in it
What external attack surface management covers, how an automated external assessment fits into it, and where a read-only scanner cannot go.
The problem the category exists to solve
An organisation's attack surface is everything an attacker can reach without being let in. It is not the same as its estate, and it is not the same as its applications. It is the union of all the internet-facing addresses that belong to the organisation, including the ones nobody remembers approving:
- a marketing site and a campaign microsite on a different provider;
- a staging hostname that outlived its project;
- a subdomain delegating to a SaaS provider, and the provider releasing it;
- an acquired company's domain, still resolving, still answering;
- the certificates in transparency logs — a public, historical record of every name a certificate has ever covered, including names nobody would put in an inventory today.
The reason this needs a discipline rather than an occasional review is that none of it changes through a change-management process. Each item above arrived the way attack surface arrives: somebody set something up, it was never removed, and the inventory that would have caught it was written down once.
What the discipline covers
Discovery. Finding internet-facing assets the organisation owns, including ones nobody declared. Passive sources — certificate transparency, DNS, search engines, threat feeds — plus active confirmation that each still answers.
Classification and ownership. Deciding what each asset is, whether it should exist, and who is responsible for it. This is the part most tools under-serve, and it is the part that determines whether a finding becomes work or becomes noise.
Configuration analysis. Applying the organisation's policy to what is observed — headers, TLS, DNS, mail configuration — and reporting the gap between the two.
Continuous monitoring. Re-checking, so that a new asset, a new certificate or an expired control is noticed by something other than a customer.
Remediation routing. Getting a finding to whoever can fix it, with enough evidence that they act on it.
Where Soryvex fits, stated precisely
Soryvex does configuration analysis and continuous monitoring of external assets, with an evidence-backed report. That is the middle of the discipline, and it is worth being specific about what it does not include.
It does. Repeated external assessment of domains you add, at a bounded request cost, with the results ranked by severity and confidence and the evidence attached. Re-running after a change is a first-class operation rather than an export for someone else to diff.
It does not discover unknown assets. Soryvex assesses domains you add. Passive asset discovery — enumerating what else you own from certificate transparency and passive DNS — is a different capability, and this product does not have it. If you do not know you have a hostname, this will not tell you.
It does not replace a vulnerability scanner for authenticated application testing, or a penetration test, or a code review, or a compliance audit.
It does not do classification and ownership resolution. That is a human process — knowing whether a staging hostname is still in use is a question for the person who owns it, not for a scanner.
How it works alongside the rest
The useful framing is that these are complementary layers rather than competing products. A reasonable arrangement:
- Discovery tells you what exists. Do this periodically; it is a snapshot problem.
- Soryvex tells you the current external configuration of what you already know about, continuously, and produces the report that a developer or an MSP can act on.
- Authenticated testing tells you about the application behind the login. Periodic, human-led, and expensive.
- A penetration test tells you what an adversary would actually do with what the first three found. Periodic, human-led, expensive, and the one that produces a defensible statement about security rather than a list.
The attack-surface guide works through the first two layers as a manual process, which is also the right way to evaluate whether any of this is worth buying.
What "external attack surface management" is often used to mean
- Vendors in this category differ enormously in scope. Some do passive discovery and configuration checking; some are continuous authenticated scanners; some are full vulnerability platforms. Soryvex is external, unauthenticated and read-only — a configuration and exposure layer, not an application-testing platform.
- A finding from an external assessment means a control is missing or weak. It does not mean the system is compromised, and it does not certify the system as secure.
Add continuous external assessment to what you already have
Assess a domain, fix what it finds, and re-assess to show the difference. Free to start on one domain.
Read-only and unauthenticated. It sees what an outside observer sees.