Attack surface
Subdomains, live hosts, open ports, tech stack, vulns and look-alike domains. Graph and dossier. We check for false positives.
- Rescans every night, no agent
- Evidence and fix notes on every finding
We map exposed assets, leaked passwords and fake look-alike domains. Then we show the actors, malware and CVEs pointed at you. No agent to install. Updated every night.
Forgotten subdomains, open FTP, stealer logs, ransomware leak sites. That's usually where the first hit comes from. OffPerimeter watches that side for you.
One exposed admin panel or one corporate password in a stealer log is enough. We turn that into a list your team can actually work.
Attack surface, leaked credentials, and global threat intel. Same tenant, same login.
Subdomains, live hosts, open ports, tech stack, vulns and look-alike domains. Graph and dossier. We check for false positives.
Corporate emails and passwords in infostealer logs and breach dumps, matched to your domains.
Actors, malware, ransomware victims, exploited CVEs and a live Feeds & Signals stream.
A real perimeter scan with the company name hidden. Assets, findings with evidence, and the surface as a graph.
Older GLPI (9.2 to before 9.5.6) leaks server details through the telemetry endpoint. That can help an attacker learn the stack and keep going.
A slice of the Overview page. Actively exploited CVEs on CVSS vs EPSS, top actors, and the security feed.
Actors, malware and CVEs we track. This is a small sample from the dossiers in the platform.
Four collection lanes. Surface, leaks, ransomware posts, and live intel. Not a generic dark-web slide.
Nightly map of what answers on the public internet for each org. Same view a random attacker can get in a few minutes. No agent.
Give us a domain. We map what's public: hosts, services, leaks, fake domains, and intel aimed at that org.
Open critical services and fresh stealer hits come up first. We drop a lot of noise. Evidence stays on the finding.
Queues for SOC and MSSP, split by client, plus live intel so you know who is hitting you.
No. OffPerimeter is external. We see what the internet sees: domains, services, leaks and fake domains. We don't touch endpoints.
A scanner is a one-off. OffPerimeter keeps running: nightly ASM, stealer and breach data on your domains, and CTI (actors, malware, ransomware, CVEs, live feeds) in the same tenant.
A root domain (or a short list). From there we map subdomains, exposed services, look-alikes and credential exposure matched to your org. No VPN, no agent, no network access.
Attack-surface scans run on a nightly cycle. Stealer logs, breach matches, ransomware victim posts and live intel signals update continuously as sources publish.
Yes. Each org is isolated. Superadmins can view as a client without mixing leaks or findings.
No. It covers what's outside your network: external attack surface and threat intel. Your SIEM and EDR keep handling internal telemetry. OffPerimeter adds the outside view to the same workflow.
Book a walkthrough and we'll show the platform on your domains.
Book a demo