Disruptors ASM
Everything a hacker sees. Checked before they find it.
Disruptors ASM maps your entire public attack surface the same way an attacker would — then correlates every finding against live exploit data, threat intelligence and 90+ individual checks across ten factors.
7
Factors
90+
Individual checks
40+
Intelligence sources
600+
Vendor signatures
129
Offensive pen testing tools
How pricing works
There is no subscription and no per-seat fee. You buy prepaid scan credits and spend them when you scan. Everything else on this page is optional.
1 credit buys
One full scan of one root domain
Including its first 10 discovered subdomains. Every other subdomain is still discovered and listed — each extra credit deep-scans another 10.
Credits are spent
Per scan, not per month
Scan monthly, quarterly or on demand — you decide the cadence. Credits are valid for 12 months, shared across your whole workspace, and automatically refunded if a scan fails.
Included free
AI findings verification
AI verify re-checks the findings from your passive scan and marks each one confirmed, refuted or inconclusive — no extra cost, and it never spends Active Mode credits.
What every credit includes
- All ten factors and 90+ checks on every scan
- AI validation of passive findings — included free
- Scheduled rescans, change diffing and alerts
- Board-ready PDF reports and CSV export
- Related-domain discovery and portfolio roll-up
- Compliance framework mapping on every finding
- Unlimited users in your workspace — credits are pooled
Credit price
The volume price applies to your whole order. Minimum order 1 credit.
1 – 49 credits
£30
per credit
50 – 199 credits
£25
per credit
200+ credits
£20
per credit
Estimate your spend
Credits per scan
1
Credits per year
12
Estimated year one
£360
at £30 per credit
Excludes Active Mode credits, which are priced separately below. Running 200+ credits a year? Talk to us about an annual contract.
Active Mode credits — AI-driven penetration testing
Active Mode is a full penetration test, not a re-check of your passive findings. One credit launches one test against a domain: an AI pen tester chains 129 industry-standard offensive tools, attempts real exploits to prove impact, then stops before causing damage, and feeds proven evidence back into the same report. Start from as little as one credit — no minimum platform commitment.
Just want your passive findings re-checked? That is AI verify — free and unlimited with passive scan credits, and it never spends Active Mode credits.
Credits are deducted the moment a test starts. A full Active Test consumes one Active credit; a single-finding Active Test is charged separately at £25 per finding. Failed launches are automatically refunded. Monthly-plan credits are always used before any prepaid pack credits.
1 scan
£300
£300 per Active Test
5 scans
£1,250
£250 per Active Test
15 scans
£3,000
£200 per Active Test
30 scans
£4,500
£150 per Active Test
- Buy a single scan or a volume pack
- Test a single finding for £25
- Credits valid for 12 months
- Shared across your workspace
Active Mode is an optional upgrade inside Disruptors ASM. It does not replace the passive scan, scheduled monitoring or the free AI findings verification — it is the fastest way to prove, with real exploitation, whether a finding is genuinely exploitable without leaving the platform.
Bring your whole team — no per-seat fee
Invite as many colleagues as you like into your workspace. Credits are pooled, so you are never charged per user — you only pay for the scans you run. Everyone works from the same live findings instead of a PDF emailed around the business.
- Unlimited team members — invite by email in seconds
- Roles and permissions so viewers, editors and admins see the right thing
- Assign findings as tasks to the person who owns the fix
- Leave notes and comment threads on any finding for shared context
- Send findings for investigation and track them to closure
- Rescan after changes and watch your score improve over time
- Change diffing shows exactly what was fixed, what is new and what regressed
- Score history and trend charts for board and insurer reporting
Want to add human pen tester hours?
Users can accept risks and submit version numbers inside the platform, and the projected score reacts — but nobody marks their own work. Validation days buy the time of a CREST-accredited pen test company to independently verify those claims and sign off your report. The day rate falls as the pack size rises. These days are a professional service: we scope them on a call and invoice them directly, rather than selling them through the checkout.
1 day
£1,250
£1,250 / day
2 days
£2,300
£1,150 / day
5 days
£5,500
£1,100 / day
10 days
£8,400
£840 / day
20 days
£16,000
£800 / day
- CREST-accredited third-party sign-off on your report
- Verifies accepted risks, version submissions and remediation claims
- Evidence insurers, auditors and boards will accept
- Manual review of findings the automated scan can only infer
Indicative prices, excluding VAT, invoiced on agreed scope. Validation covers verifying findings, remediation claims and accepted risks; ongoing offensive penetration testing is delivered by our separate Radar service and quoted after a scoping call.
Visibility
See what attackers see
An outside-in view of your entire public footprint — including the subdomains, services and cloud assets that internal inventories miss.
Prevention
Close the window before it's used
Most breaches trace back to a known, unpatched weakness that sat exposed for months. Regular scanning shrinks that window from months to days.
Assurance
Evidence, not guesswork
A documented, repeatable record of your external posture — useful for the board, for insurers, and for proving due diligence.
What every scan checks
Ten factors, 90+ individual checks, correlated across 40+ intelligence sources. Passive by default — nothing sent to your systems beyond what any visitor's browser already sends.
01 — Network Security
Every reachable service, every open port, every known appliance vulnerability — mapped against what is actually being exploited in the wild right now.
- Live open-port scanning — real-time TCP connect scan at report time, not cached data
- CVE correlation against the national vulnerability database, cross-referenced with government-tracked actively-exploited vulnerabilities
- High-risk appliance detection — Citrix, Fortinet, Palo Alto, Pulse Secure, VMware, matched to their specific CVEs
- DNS zone transfer (AXFR) test, DNSSEC signing and CAA record checks
- Certificate Transparency mining — surfaces internal-only hostnames leaked in public cert logs
- TLS certificate health — expiry countdown, wildcard single point-of-failure, unexpected issuer
- TLS protocol & cipher-suite analysis — deprecated TLS 1.0/1.1, weak or insecure ciphers, forward secrecy, Heartbleed/POODLE/FREAK/Logjam/DROWN
- Multi-source IP intelligence across independent internet-scanning providers
- Botnet C2 matching and cloud/CDN infrastructure filtering so shared hosting is never mistaken for your own server
02 — Application Security
Every subdomain, every login page, every leaked file — the deepest factor in the platform, built to catch exactly the kind of mistake that turns into a breach headline.
- Subdomain discovery across 11 independent sources, confirmed live vs. historical
- WAF detection, HTTPS enforcement, HSTS and full security header audit
- Deep CSP analysis — enforced vs. report-only, dangerous directives, cross-origin isolation
- 50+ sensitive file/path probes (.git, .env, DB dumps, SSH keys, cloud credentials) — every hit content-verified
- Admin panel and login portal discovery across the main domain and every subdomain, with hardening checks
- API & GraphQL exposure scanning — Swagger discovery, CORS misconfiguration, introspection, JS bundle endpoint mining
- Cloud storage bucket enumeration and dangerous HTTP method testing
- Source-code analysis — leaked secrets, unpinned third-party scripts, hardcoded API keys
- JS library vulnerability scanning and ~50 self-hosted panel fingerprints
- Subdomain takeover detection across ~35 abandoned service providers
- Exchange/mail-server fingerprinting for ProxyLogon/ProxyShell-class attacks
- AI system & LLM endpoint detection, named platform fingerprinting (Log4Shell, Struts, Confluence, SharePoint, Drupal)
03 — Email Security
Email is still the most common way in. Every layer of anti-spoofing protection is tested — not just whether a record exists, but whether it is configured to work.
- DMARC presence, enforcement strength and deep tag analysis including the DMARCbis npt tag
- SPF validation — dangerous +all detection and DNS lookup counting against the 10-lookup hard limit
- DKIM discovery across ~25 selector conventions, key-strength and Ed25519 analysis
- BIMI verification, MTA-STS enforcement and TLS-RPT reporting checks
- Live SMTP encryption testing — STARTTLS, handshake, TLS version, certificate expiry
- Open mail relay testing — safe, no message content ever sent
- Mail server reputation across 5 independent blacklists, every mail IP checked
- Subdomain email-spoofing sweep across every subdomain, not just the main domain
04 — Credential Exposure
Passwords tied to your domain do not stay secret forever — this factor finds out where they have already surfaced.
- Breached-account search with named breach detail per account
- Independent cross-reference against a second, separately-maintained leak database
- Paste-site monitoring for published stolen credentials
- Public code-repository secret search across credential-related keywords
- Director-level exposure via Companies House officers — candidate addresses never stored or logged
05 — Brand & Phishing
Impersonation happens on infrastructure you do not own. This factor watches for it anyway.
- Automated lookalike-domain generation — homoglyphs, omission, TLD swaps, transposition
- Registration monitoring — newly-registered variants flagged as phishing-campaign indicators
- Capability assessment — live site vs. parked page vs. mail-ready infrastructure
- Business Email Compromise pattern detection on finance/payroll/invoice terminology
- Malicious URL and screenshot scanning with reputation verdict
- Social and video platform brand monitoring with negative sentiment flagging
- AI web-search discovery of lookalike and impersonating domains beyond generated permutations
- Historical footprint analysis — surfaces subdomains that should have been retired
06 — Known-Malicious Infrastructure
Every discovered asset is checked against the same threat-intelligence feeds security teams pay for — and corroborated across sources before anything is escalated.
- Actively-exploited vulnerability cross-reference — confirmed exploitation, not theoretical risk
- Malware-hosting domain, malicious-site blocklist and botnet C2 checks
- Exploitation-probability scoring and IP abuse reputation
- Spam blacklist checks across multiple independent DNSBL zones
- Campaign-infrastructure correlation — 3+ sources flagging one asset is treated as known-campaign infrastructure
- Multi-source corroboration — two independent sources agreeing escalates confidence automatically
07 — Company & Compliance Intelligence
Business context plus a compliance benchmark against the standards your auditors, insurers and customers ask about. The passive scan marks where you could be out of compliance; AI verify then confirms or clears each one, so you know for sure rather than guessing.
- Benchmarked against: Cyber Essentials, Cyber Essentials Plus, ISO 27001/27002, ISO 27701, NIST CSF 2.0, NCSC CAF, SOC 2, PCI DSS, GDPR Art. 32, DORA, NIS2, OWASP Top 10, OWASP API Top 10 and MITRE ATT&CK
- Passive scan flags every control where the evidence suggests you could be out of compliance
- AI verify re-tests each flagged control and marks it confirmed, refuted or inconclusive — no free-floating maybes
- Every finding mapped to the specific clause or control it affects, ready for an audit pack
- Companies House lookup — status, incorporation age, registered address, SIC codes, registered officers
- AI web-search discovery of related, subsidiary and trading-name domains — auto-added to your portfolio for review
- GDPR technical indicators — consent mechanism, privacy policy, pre-consent tracking
- ICO registration likelihood estimate and trading-status verification
- PCI DSS technical indicators — payment processor detection, direct card-collection flagging
- Third-party verified-service classification
- Public code-repository organisation intelligence — repo/member counts, abandoned repositories
Fingerprinting
Security vendor & technology stack ID
600+ passive signatures identify which security and IT vendors you already have in place — not just your gaps.
Frameworks
Compliance framework mapping
Every finding is mapped to the compliance obligation it affects, not left as an isolated technical detail.
Narrative
Business risk-scenario translation
Dozens of granular findings collapse into 10 board-level risk narratives — Source → Event → Consequence — built for a non-technical executive or investor audience, not just an engineer.
Beyond the scan
Where this goes when you need more than a passive read.
Deliverable
Full PDF report
Executive summary, factor-by-factor scorecard, full findings table, dedicated CVE tables, attack-surface network map and world-map infrastructure view, exposure-path narratives, company intelligence and a methodology checklist.
Tracking
Scheduled monitoring
Rescan diffing that surfaces exactly what changed since last time — new or removed assets, ports, CVEs, storage buckets, lookalike domains and leaked credentials.
Automated verification
Verified findings
Accepted risks, corrected version numbers and "we've fixed it" claims all move your projected score. Active Mode re-tests those claims automatically and marks each finding confirmed, disproven or still open, so the score you show is evidence-backed.
Ongoing penetration testing
Disruptors ASM finds the questions; Disruptors Radar answers them on an ongoing basis. Radar is a separate subscription service on its own site — ongoing offensive testing across your estate, with auditor-ready reports and new risks caught as they emerge rather than once a year.
Ready to upgrade?
Speak to our team to activate paid monitoring, discuss volume pricing, or add ongoing active testing to your account.
Prices in GBP and exclude VAT where applicable. Credits are prepaid, valid for 12 months from purchase, shared across your workspace and non-refundable once spent.

