NEW Feeds & Signals now unifies live intel and curated dossiers

See what's exposed
outside your
network.

We map exposed assets, leaked passwords and fake look-alike domains. Then we show the actors, malware and CVEs pointed at you. No agent to install. Updated every night.

LIVE PERIMETER SWEEP
3 critical exposed
47 assets mapped
look-alike caught
Used by teams that cover the public internet side
BANKINGTELECOMGOVERNMENTMEDIAMSSP
120M+Infostealer records
NightlyAttack-surface rescans
CTIActors, malware, CVE, ransomware
0 agentsNothing to install on hosts
The problem

Attackers start outside. Most tools still start inside.

Forgotten subdomains, open FTP, stealer logs, ransomware leak sites. That's usually where the first hit comes from. OffPerimeter watches that side for you.

Blind spots

If you can't see it,
they already can.

One exposed admin panel or one corporate password in a stealer log is enough. We turn that into a list your team can actually work.

SOC & incident responseGo from an alert to the exposed host, the leaked password, and the actor using it.
MSSPsOne view per client. Attack surface, leaks and intel, without mixing client data.
CISOs & enterprise securityWhat the internet already knows about you, with evidence, so you can brief leadership.
Government & critical infrastructureExternal exposure plus the campaigns, ransomware groups and CVEs hitting your sector.
Product

Three parts of the same product.

Attack surface, leaked credentials, and global threat intel. Same tenant, same login.

01 · EASM

Attack surface

Subdomains, live hosts, open ports, tech stack, vulns and look-alike domains. Graph and dossier. We check for false positives.

ftp.example.com:21CRITICAL
mysql :3306 publicCRITICAL
wp-admin exposedHIGH
  • Rescans every night, no agent
  • Evidence and fix notes on every finding
02 · LEAKS

Credential exposure

Corporate emails and passwords in infostealer logs and breach dumps, matched to your domains.

stealer · chrome124M logs
breach records1.5M+
domain-scopedtenant isolated
  • Infostealers + published breaches
  • Isolated per org. Clients don't mix.
03 · CTI

Threat intelligence

Actors, malware, ransomware victims, exploited CVEs and a live Feeds & Signals stream.

LazarusACTOR
Akira · ClopRANSOM
KEV + EPSSprioritized
  • Panorama, dossiers, malware families
  • Live signals and curated intel in one stream, by time window
Attack surface sample

This is what an ASM result looks like.

A real perimeter scan with the company name hidden. Assets, findings with evidence, and the surface as a graph.

app.offperimeter.com / attack-surface Preview
Attack surface dossier (client name hidden)
0
THREAT
CRITICAL
0
Assets
0
Subdomains
0
Critical
0
High
0
Services
Severity distribution126 total
critical 4high 2medium 36low 59info 25
WordPress LiteSpeed Cache · Unauthenticated Privilege Escalation to Admin
· Incorrect Privilege Assignment
CRITICAL
FTP Exposed Publicly (:21)
· insecure protocol transmitting credentials
CRITICAL
MySQL Exposed Publicly (:3306)
· database reachable from the internet
CRITICAL
LiteSpeed Cache ≤ 5.7 · Unauthenticated Stored XSS
· cross-site scripting
HIGH
+ 122 more findings on 13 assets. The rest is in the platform.
Finding detail
Each finding has evidence, where we matched it, and links to fix it.
GLPI 9.2/<9.5.6 Information Disclosure
MEDIUM

Older GLPI (9.2 to before 9.5.6) leaks server details through the telemetry endpoint. That can help an attacker learn the stack and keep going.

tags
["cve","cve2021","glpi","exposure","vkev"]
matched_at
https:///ajax/telemetry.php
template_id
CVE-2021-39211
curl_command
curl -X GET 'https:///ajax/telemetry.php'
Attack surface graph
62 nodes · 61 edges
ALLCRITICALHIGHMEDIUM
Organization Asset Critical High Medium
Threat intel sample

CVE risk matrix: impact vs how likely it is to get exploited.

A slice of the Overview page. Actively exploited CVEs on CVSS vs EPSS, top actors, and the security feed.

app.offperimeter.com / threat-intel Preview
Actively exploited CVEs, risk matrix
CVSS (impact) on X, EPSS (exploit chance) on Y. Top right is what to fix first.
Critical High Medium known-exploited
Threat Actor Activity
Top actors by activity. 218 profiled in the catalog.
Security Feed
Latest items from the security feed.
Catalog sample

Open a card. This is the kind of dossier we keep.

Actors, malware and CVEs we track. This is a small sample from the dossiers in the platform.

Built for
Banking & Finance Government Defense Telecom Media Hospitality Retail Education
Where the data comes from

From the source to something you can use.

Four collection lanes. Surface, leaks, ransomware posts, and live intel. Not a generic dark-web slide.

COLLECTION

External attack surface

Nightly map of what answers on the public internet for each org. Same view a random attacker can get in a few minutes. No agent.

How it works

How a scan becomes work.

STEP 01

Find it

Give us a domain. We map what's public: hosts, services, leaks, fake domains, and intel aimed at that org.

STEP 02

Sort it

Open critical services and fresh stealer hits come up first. We drop a lot of noise. Evidence stays on the finding.

STEP 03

Fix it

Queues for SOC and MSSP, split by client, plus live intel so you know who is hitting you.

FAQ

Common questions

Do we install an agent?

No. OffPerimeter is external. We see what the internet sees: domains, services, leaks and fake domains. We don't touch endpoints.

How is this different from a scanner?

A scanner is a one-off. OffPerimeter keeps running: nightly ASM, stealer and breach data on your domains, and CTI (actors, malware, ransomware, CVEs, live feeds) in the same tenant.

What do you need from us to start?

A root domain (or a short list). From there we map subdomains, exposed services, look-alikes and credential exposure matched to your org. No VPN, no agent, no network access.

How often is the data refreshed?

Attack-surface scans run on a nightly cycle. Stealer logs, breach matches, ransomware victim posts and live intel signals update continuously as sources publish.

Can an MSSP run many clients?

Yes. Each org is isolated. Superadmins can view as a client without mixing leaks or findings.

Does OffPerimeter replace our SIEM or EDR?

No. It covers what's outside your network: external attack surface and threat intel. Your SIEM and EDR keep handling internal telemetry. OffPerimeter adds the outside view to the same workflow.

Next

See what attackers already see.

Book a walkthrough and we'll show the platform on your domains.

Book a demo