Secuur / Services / Attack surface visibility
01 · Discovery & inventory

You cannot protect the assets you forgot you had.

The average team underestimates its own external footprint by 30–40% — a staging box someone spun up in 2023, a marketing subdomain pointed at a dead CDN, an API gateway nobody owns. Secuur finds all of it, then grades every TLS endpoint on the same A–F scale as the free scan.

readiness-scan
https://
What it is

Attack surface visibility.

Attack surface visibility is the unglamorous foundation everything else sits on. Penetration tests scope to what you tell the tester about. Compliance evidence covers the systems you listed. Automated scanners only scan the targets in the queue. Every one of those activities inherits the blind spots of your inventory.

Secuur builds the inventory from the outside in — the same way an attacker would. We start from your domains and enumerate subdomains, resolve them, fingerprint what is listening, pull and parse every certificate, and attribute each asset back to a business owner. Then we keep doing it, because your surface changed while you were reading this.

What you get

Six things this actually does.

01

Subdomain & DNS enumeration

Passive sources plus active resolution across your registered domains. Catches the forgotten staging., old-app. and vendor-hosted CNAMEs.

02

Service & port fingerprinting

What is actually listening on each resolved host, what software version it reports, and whether it should be internet-facing at all.

03

Certificate inventory

Every leaf and chain you present publicly — issuer, key type, key size, signature algorithm, SAN sprawl, and days to expiry.

04

Dangling-DNS detection

CNAMEs pointing at deprovisioned cloud resources are a subdomain-takeover waiting to happen. We flag them the day they go stale.

05

Ownership attribution

An asset with no owner never gets patched. Each finding is tagged to a team so remediation has an address to go to.

06

Change alerting

New host, new certificate, downgraded cipher suite, expiring cert — delivered to email, SMS or webhook the same day it appears.

The Secuur difference

The layer other ASM tools do not have

Conventional attack-surface tools tell you a host exists and what version it runs. They will not tell you that its TLS handshake negotiates a classical-only key exchange — which means every session it has ever served is harvestable today and readable the moment a cryptographically-relevant quantum computer exists.

  • Each discovered endpoint is graded A–F on the negotiated TLS 1.3 key-exchange group, using the same OpenSSL-backed engine as the free scan.
  • Certificates are inventoried by signature algorithm, so you know which of your PKI is RSA/ECDSA and will need re-issuing under FIPS 204.
  • The output doubles as the first draft of your Cryptographic Bill of Materials — the artifact CNSA 2.0 and NSM-10 programmes now ask for.
How it runs

Three steps, start to evidence.

01

Seed

You give us your domains — or just your primary one and we work outward from registration and certificate-transparency records.

02

Enumerate & grade

First full sweep completes in hours, not weeks. Every live TLS endpoint comes back with an A–F quantum grade attached.

03

Watch

Continuous re-discovery on your cadence. You get a diff, not another 400-row dashboard to go read.

Deliverables

What lands in your hands.

  • Full external asset inventory (CSV + JSON API)
  • Per-endpoint A–F quantum-readiness grade
  • Certificate register with key type, size and expiry
  • Dangling-DNS and takeover-risk report
  • Draft Cryptographic Bill of Materials (CBOM)
  • Change diffs on your chosen cadence
Questions

Straight answers.

How is this different from a vulnerability scanner?

A vulnerability scanner tests targets you give it. Attack surface visibility discovers the targets in the first place. The two are complementary — discovery feeds the scanner its queue, which is why Secuur runs them together.

Do you need access to our infrastructure?

No. External discovery runs entirely from the outside using public DNS, certificate transparency logs and unauthenticated network probes — the same data any attacker can reach. Authenticated internal discovery is available as an add-on where you want cloud-account coverage.

What is a Cryptographic Bill of Materials?

A CBOM is an inventory of every cryptographic algorithm, key and certificate your systems depend on. It is the prerequisite for any post-quantum migration plan, and US federal guidance under NSM-10 and CNSA 2.0 increasingly expects agencies and their suppliers to maintain one.

How often does discovery run?

Weekly by default, daily or continuous on higher tiers. Certificate expiry and new-host events are alerted as soon as they are observed rather than waiting for the next full sweep.

Related services

Often bought together.

Every engagement starts the same way

Know your grade.
Then pick your service.

The scan is free and takes 20 seconds. It also tells us enough to scope attack surface visibility properly instead of guessing.