CODERED ASM®

Continuous threat exposure management. We map what you expose to the internet, score it, and re-test every finding daily until it closes itself with proof.

Continuous Threat Exposure Management

Your attack surface grows without anyone deciding to grow it. A team spins up a cloud bucket for a migration and leaves it readable. A supplier stands up a subdomain on your brand. Someone reuses a work password on a site that gets breached two years later. An internal vulnerability scan finds none of this, because none of it sits inside your perimeter.

CodeRed ASM maps what your organization exposes to the internet, turns each exposure into a tracked finding with evidence, and closes it out when you fix it.

The discovery pipeline

Discovery runs weekly against each domain you hand us, and on demand whenever you ask. You install nothing.

  • Subdomain enumeration against external DNS intelligence
  • DNS resolution and an HTTP probe, to find which hosts respond
  • Technology fingerprinting: server, CMS, frameworks and versions
  • A full-page screenshot of every live host
  • An asset inventory update, and one finding raised for each new exposure we have not seen before

Every run records what it did: domains scanned, new subdomains, live subdomains, errors, findings raised.

What we find

Findings are filed against exposure categories including security misconfiguration, sensitive data leakage, shadow IT, vulnerable attack surface, system compromise indicators, phishing and online fraud, DDoS amplification, internet reputation risk, third-party risk, and credential leaks across employee, corporate, consumer and combolist sources.

What that looks like in practice: exposed admin panels including hosting control panels, NAS consoles and firewall logins. Public staging and dev sites. Exposed database and service ports. Outdated software versions. Missing security headers. Weak TLS, expired or mismatched certificates. Directory listing. Stack traces leaking to the browser. Subdomain takeover. Open recursive DNS and SSDP responders sitting ready to be used in an amplification attack.

Subdomain takeover

Takeover gets its own treatment, because it is the exposure most likely to become someone else publishing on your domain. We hold a signature database of roughly fifty hosting providers, covering static-site hosts, cloud storage, platform services, CDNs and helpdesk vendors, with the CNAME patterns and page fingerprints each one leaves behind. Every candidate is checked during discovery, on demand, and again in a daily rescan.

Why the findings are trustworthy

Most attack surface tools report an exposure once and leave you to argue about whether it is still real. We re-test.

A probe catalogue defines, for each shape of finding, the smallest read-only test that answers one question: is this still true. HTTP checks read headers, body and status. Network checks look at ports and TLS. Takeover checks run against the signature database. The probe parses deterministically, and CyberLLM rules on the result.

Silent re-validation

Every day we walk every unremediated asset on every open finding and re-probe it. When a probe confirms you have fixed something, we write the proof into the ticket and mark the asset remediated. When every asset on a finding is remediated, the ticket closes itself and you get an email with the evidence.

A probe that still finds the exposure says nothing at all. That is the point. Your team fixes things without telling us, and the findings close themselves, without a stream of email confirming what has not changed.

Leaked credentials are the exception, and we say so plainly: no probe can verify that someone reset a password. Those findings close when you mark the credential reset or the identity offboarded.

Scoring

AEAS blends exploitability, impact, exploit maturity, threat activity and exposure context, scored per asset and per finding, then rolled up for your organization. CVEs on the known-exploited catalogue weigh heavily, because an exploit that is already in use is a different problem from one that is theoretical.

PRS runs alongside it from dark web intelligence, forecasting whether someone is preparing to target you. AEAS tells you how exposed you are. PRS tells you who is looking.

Asset inventory

Every discovered asset lives in a searchable inventory with its technology fingerprint, screenshot and score. Our analysts attach tags and remarks, and those annotations survive rediscovery, so context your team built up is not wiped by the next scan.

How a finding reaches you

Discovery raises the finding. Noisier sources wait in our triage queue for an analyst to check before you ever see them. You get severity, evidence and remediation steps, and an email on release. You fix it. The daily re-validation confirms the fix, the ticket closes with proof attached, and your AEAS score drops.

Findings also feed the rest of what we run: they become hunting leads for the CyberSOC and scope for PENTESTBOX engagements.