Product update: Dynamic API Scanning, Recommendations & Classifications, and more
We know the importance of staying ahead of threats. At Detectify, we’re committed to providing you with the tools you need to secure your applications …
Victor Arellano
TL/DR: Users now get additional insights on what is discovered on the attack surface. This includes information such as when an asset was last seen and to what extent an asset is exposed online, and much more.
The attack surface is inevitably going to grow. That’s why we believe it’s crucial for customers to not only know what assets they are exposing online but knowing to what extent assets are exposed.
Users can now toggle the view of their attack surface by active and inactive assets. When toggled on, users will see all active assets present on their attack surface in the last 14 calendar days making it easier to discern what may no longer be on the attack surface.
Of course, discovering what is on your attack surface is important, however, understanding to what extent your attack surface is exposed is doubly important. Surface Monitoring users can now view the state of their attack surface. This helps them know whether a particular domain has open ports, has reachable IPs but no open ports, or whether there’s just a resolving DNS record.
The attack surface is shown in the following states:
Autodiscovery helps customers identify all of their publicly available subdomains. This is particularly useful whether users want to discover legacy systems to a forgotten marketing landing page to potential subdomain takeovers. Sometimes, users would like to run autodiscovery manually for various reasons. Until recently, that has not been possible.
Now, all users can manually trigger autodiscovery on root assets which means users never have to worry if an asset is missing from their attack surface.
Occasionally, you might need to manually add a subdomain. Previously, that wasn’t possible, which meant some corners of the attack surfaces weren’t covered. We’ve now made it possible for customers to manually add subdomains to a root asset.
Adding a subdomain for verified root assets:
Users can add a subdomain to an unverified root asset which will create a separate root asset that will automatically convert to a sub asset once the actual root is verified. You can read more about verifying assets on our knowledge base.
To keep up with today’s evolving security challenges, you need continuous coverage of the attack surface. Login to check your assets. Go hack yourself!
We’re hiring engineers, product managers, sales, & more! Learn more by visiting https://detectify.com/career.
We know the importance of staying ahead of threats. At Detectify, we’re committed to providing you with the tools you need to secure your applications …
What if we told you that our newly released API Scanner has 922 quintillion payloads for a single type of vulnerability test? A quintillion is …