Automated reconnaissance across your hosts and public footprint, followed by baseline scanning for open ports, exposed storage, and TLS problems, and across the domains and DNS records that point at them.
Risk Monitoring & Ratings
Everything you have exposed to the internet, watched and scored.
Hosts, ports, services, storage, and the names and delivery path that lead users to them. Guardian maps the perimeter the way an attacker first encounters it, as a list of things that answer, sorts it into the things that should and the things that should not, and then keeps looking. Your exposure moves every time something is deployed, and the rating moves with it.
Every host, port, and service you have exposed.
Including the staging box from last quarter and the bucket someone made public to debug something. We enumerate the whole public footprint, the parts nobody has logged into for a year included, and check each one against what reaching it would let somebody do. That sweep then repeats, so the box spun up next Tuesday is found in days rather than at the next audit.
- Asset discovery Subdomain enumeration, DNS sweeps, and reconnaissance across your public footprint to find the hosts you have and the ones you forgot you had.
- Exposed services Open ports, running services, and admin interfaces reachable from the internet: databases, dashboards, and internal tooling that was never meant to be public.
- Exposed data Public cloud storage buckets, open directories, backups, and configuration files left readable by anyone who knows the URL.
- Known vulnerabilities Outdated and unpatched software on anything exposed, checked against publicly known exploits and then verified by hand, so you get confirmed exposure rather than scanner noise.
- Encryption in transit TLS configuration, certificate validity and issuance controls, and any endpoint still accepting a weak or expired connection.
- Edge protection WAF and Cloudflare configuration: whether the rules do what you assume, and whether the origin can simply be reached directly, around them.
And the names and delivery path that lead users there.
The hosts are one half of the perimeter. The other half is the route a user takes to reach them: a domain name, a DNS answer, and a bundle served from somewhere. Control any one of those and the protocol never has to be attacked at all, so the same coverage watches them.
- Registrar and DNS Registrar account security and transfer locks, DNSSEC, registrar-level 2FA, and who inside the company can change a record.
- Domain inventory Forgotten subdomains, dangling records pointing at deprovisioned hosts, and lookalike registrations already in circulation.
- Delivery path CDN and hosting account access, build-to-deploy integrity, TLS and certificate issuance controls, and CAA records.
- Frontend integrity Content Security Policy, subresource integrity, third-party scripts on signing pages, and detection when the served bundle changes.
How it works
Every automated finding is reviewed and validated by an engineer, and the edge configuration is checked directly. You are not handed a scanner report, and you are not paged for one either.
The verified inventory becomes your rating, and the sweep repeats. New exposure moves the score, and anything urgent reaches you when it is found rather than in a quarterly document.
What stays monitored
Every internet-facing server, port, and interface that answers a stranger.
Buckets, directories, and backups reachable by anyone who knows the URL.
Primary and secondary names, registrar accounts, and every record that resolves.
The accounts able to change what is served at your domain.
Lookalike domains, impersonation, and the paths users take to find you.
Why this exists
The registrar was hijacked and the frontend swapped. Users signed on what looked like the real site.
CoW Swap · $1.2M (read the incident write-up)