Platform

Everything Disruptors ASM looks at, and how

Ten passive scored factors plus ten active testing categories, 90+ checks per domain, 40+ independent intelligence sources and 129 offensive security tools — cross-validated so every finding is backed by real evidence before it is flagged.

Asset discovery

Certificate transparency, passive DNS, RDAP and archive sources reconciled into one inventory — then every host probed individually.

Vulnerability intelligence

Ports, services and CVEs from multiple internet-wide engines, enriched with NVD severity, EPSS probability and CISA KEV status.

API security

Exposed Swagger/OpenAPI schemas, GraphQL introspection, CORS misconfiguration and unauthenticated endpoints — confirmed by response content.

Email security

DMARC, SPF, DKIM, BIMI and MTA-STS assessed directly, plus MX and reputation intelligence.

Malicious infrastructure

Every IP and domain cross-referenced against abuse, botnet and malware distribution databases.

Credential exposure

Breach-database intelligence and corporate email-pattern mapping for the accounts attackers target first.

Brand & phishing

Lookalike domains, exposed cloud storage, leaked source code and subdomain takeover risk.

Company intelligence

Registration, ownership, technology stack and historical footprint for context around the exposure.

Supply chain visibility & risk

Supplier domain discovery from email and procurement metadata, with automatic passive risk scoring for the vendors and services your business depends on.

Built-in AI analyst

Ask Miles Dyson questions about any finding, compare scans over time, and get grounded, evidence-based answers drawn from your actual scan data — not generic security advice.

Scheduled monitoring & change tracking

Schedule repeat passive scans on the cadence you choose. New subdomains, exposed ports, fresh CVEs and lookalike domains surface automatically whenever you run the next scan.

Compliance & framework mapping

Every finding is mapped to Cyber Essentials, ISO 27001, NIST CSF, GDPR, NCSC CAF and OWASP, so gaps line up to the standards auditors actually ask for.

Reporting & portfolio

Consultancy-grade PDF reports, executive risk summaries, attack paths, score history and change tracking — across a single company or an entire portfolio, with team workspaces and task assignment.

Proof on demand

Any passive finding can be escalated to Active Mode for verified exploit evidence, and self-reported fixes can be independently validated by CREST-accredited testers.

See how active testing works →

This report is based on publicly available data and may include false positives. Active testing via Disruptors Radar confirms which findings are genuinely exploitable.