Disruptors ASM

Everything a hacker sees. Checked before they find it.

Disruptors ASM maps your entire public attack surface the same way an attacker would — then correlates every finding against live exploit data, threat intelligence and 90+ individual checks across seven factors.

7

Factors

90+

Individual checks

40+

Intelligence sources

600+

Vendor signatures

Per domain, per month

Continuous
£50 / domain / month

Base rate. Volume discounts apply per domain across bands, not as a cliff.

  • Unlimited subdomains scanned at no extra cost
  • All seven factors and 90+ checks on every scan
  • Scheduled rescans, change diffing and alerts
  • Board-ready PDF reports and CSV export
  • Related-domain discovery and portfolio roll-up
  • Compliance framework mapping on every finding

Volume discounts

110 domains

£50

per domain / month

1120 domains

£40

per domain / month

2150 domains

£30

per domain / month

51+ domains

Custom

per domain / month

Estimate your monthly cost

Estimated monthly cost

£50

Band: 1–10 @ £50/domain

Add independent validation days

Users can accept risks and submit version numbers inside the platform, and the projected score reacts — but nobody marks their own work. Validation days buy the time of a CREST-accredited pen test company to independently verify those claims and sign off your report. The day rate falls as the pack size rises. These days are a professional service: we scope them on a call and invoice them directly, rather than selling them through the checkout.

Request validation days

1 day

£1,250

£1,250 / day

2 days

£2,300

£1,150 / day

5 days

£5,500

£1,100 / day

10 days

£8,400

£840 / day

20 days

£16,000

£800 / day

Indicative prices, excluding VAT, invoiced on agreed scope. Validation covers verifying findings, remediation claims and accepted risks; ongoing offensive penetration testing is delivered by our separate Radar service and quoted after a scoping call.

Visibility

See what attackers see

An outside-in view of your entire public footprint — including the subdomains, services and cloud assets that internal inventories miss.

Prevention

Close the window before it's used

Most breaches trace back to a known, unpatched weakness that sat exposed for months. Regular scanning shrinks that window from months to days.

Assurance

Evidence, not guesswork

A documented, repeatable record of your external posture — useful for the board, for insurers, and for proving due diligence.

What every scan checks

Seven factors, 90+ individual checks, correlated across 40+ intelligence sources. Passive by default — nothing sent to your systems beyond what any visitor's browser already sends.

01 — Network Security

Every reachable service, every open port, every known appliance vulnerability — mapped against what is actually being exploited in the wild right now.

  • Live open-port scanning — real-time TCP connect scan at report time, not cached data
  • CVE correlation against the national vulnerability database, cross-referenced with government-tracked actively-exploited vulnerabilities
  • High-risk appliance detection — Citrix, Fortinet, Palo Alto, Pulse Secure, VMware, matched to their specific CVEs
  • DNS zone transfer (AXFR) test, DNSSEC signing and CAA record checks
  • Certificate Transparency mining — surfaces internal-only hostnames leaked in public cert logs
  • TLS certificate health — expiry countdown, wildcard single point-of-failure, unexpected issuer
  • TLS protocol & cipher-suite analysis — deprecated TLS 1.0/1.1, weak or insecure ciphers, forward secrecy, Heartbleed/POODLE/FREAK/Logjam/DROWN
  • Multi-source IP intelligence across independent internet-scanning providers
  • Botnet C2 matching and cloud/CDN infrastructure filtering so shared hosting is never mistaken for your own server

02 — Application Security

Every subdomain, every login page, every leaked file — the deepest factor in the platform, built to catch exactly the kind of mistake that turns into a breach headline.

  • Subdomain discovery across 11 independent sources, confirmed live vs. historical
  • WAF detection, HTTPS enforcement, HSTS and full security header audit
  • Deep CSP analysis — enforced vs. report-only, dangerous directives, cross-origin isolation
  • 50+ sensitive file/path probes (.git, .env, DB dumps, SSH keys, cloud credentials) — every hit content-verified
  • Admin panel and login portal discovery across the main domain and every subdomain, with hardening checks
  • API & GraphQL exposure scanning — Swagger discovery, CORS misconfiguration, introspection, JS bundle endpoint mining
  • Cloud storage bucket enumeration and dangerous HTTP method testing
  • Source-code analysis — leaked secrets, unpinned third-party scripts, hardcoded API keys
  • JS library vulnerability scanning and ~50 self-hosted panel fingerprints
  • Subdomain takeover detection across ~35 abandoned service providers
  • Exchange/mail-server fingerprinting for ProxyLogon/ProxyShell-class attacks
  • AI system & LLM endpoint detection, named platform fingerprinting (Log4Shell, Struts, Confluence, SharePoint, Drupal)

03 — Email Security

Email is still the most common way in. Every layer of anti-spoofing protection is tested — not just whether a record exists, but whether it is configured to work.

  • DMARC presence, enforcement strength and deep tag analysis including the DMARCbis npt tag
  • SPF validation — dangerous +all detection and DNS lookup counting against the 10-lookup hard limit
  • DKIM discovery across ~25 selector conventions, key-strength and Ed25519 analysis
  • BIMI verification, MTA-STS enforcement and TLS-RPT reporting checks
  • Live SMTP encryption testing — STARTTLS, handshake, TLS version, certificate expiry
  • Open mail relay testing — safe, no message content ever sent
  • Mail server reputation across 5 independent blacklists, every mail IP checked
  • Subdomain email-spoofing sweep across every subdomain, not just the main domain

04 — Credential Exposure

Passwords tied to your domain do not stay secret forever — this factor finds out where they have already surfaced.

  • Breached-account search with named breach detail per account
  • Independent cross-reference against a second, separately-maintained leak database
  • Paste-site monitoring for published stolen credentials
  • Public code-repository secret search across credential-related keywords
  • Director-level exposure via Companies House officers — candidate addresses never stored or logged

05 — Brand & Phishing

Impersonation happens on infrastructure you do not own. This factor watches for it anyway.

  • Automated lookalike-domain generation — homoglyphs, omission, TLD swaps, transposition
  • Registration monitoring — newly-registered variants flagged as phishing-campaign indicators
  • Capability assessment — live site vs. parked page vs. mail-ready infrastructure
  • Business Email Compromise pattern detection on finance/payroll/invoice terminology
  • Malicious URL and screenshot scanning with reputation verdict
  • Social and video platform brand monitoring with negative sentiment flagging
  • AI web-search discovery of lookalike and impersonating domains beyond generated permutations
  • Historical footprint analysis — surfaces subdomains that should have been retired

06 — Known-Malicious Infrastructure

Every discovered asset is checked against the same threat-intelligence feeds security teams pay for — and corroborated across sources before anything is escalated.

  • Actively-exploited vulnerability cross-reference — confirmed exploitation, not theoretical risk
  • Malware-hosting domain, malicious-site blocklist and botnet C2 checks
  • Exploitation-probability scoring and IP abuse reputation
  • Spam blacklist checks across multiple independent DNSBL zones
  • Campaign-infrastructure correlation — 3+ sources flagging one asset is treated as known-campaign infrastructure
  • Multi-source corroboration — two independent sources agreeing escalates confidence automatically

07 — Company & Compliance Intelligence

The business context that turns a technical finding into a real answer to "does this actually matter for us?"

  • Companies House lookup — status, incorporation age, registered address, SIC codes, registered officers
  • AI web-search discovery of related, subsidiary and trading-name domains — auto-added to your portfolio for review
  • GDPR technical indicators — consent mechanism, privacy policy, pre-consent tracking
  • ICO registration likelihood estimate and trading-status verification
  • PCI DSS technical indicators — payment processor detection, direct card-collection flagging
  • Third-party verified-service classification
  • Public code-repository organisation intelligence — repo/member counts, abandoned repositories

Fingerprinting

Security vendor & technology stack ID

600+ passive signatures identify which security and IT vendors you already have in place — not just your gaps.

WAF/CDNVPN/ZTNAIdentity/SSOPAMNACRMMBackupSIEM/XDREDRDLP/CASBVuln MgmtBrand ProtectionDeceptionMobileOT/IoTAwareness TrainingTrust CentresSupply Chain

Frameworks

Compliance framework mapping

Every finding is mapped to the compliance obligation it affects, not left as an isolated technical detail.

Cyber EssentialsISO 27001/27002NIST CSF 2.0NCSC CAFSOC 2OWASP Top 10OWASP API Top 10MITRE ATT&CKGDPR Art. 32ISO 27701

Narrative

Business risk-scenario translation

Dozens of granular findings collapse into 10 board-level risk narratives — Source → Event → Consequence — built for a non-technical executive or investor audience, not just an engineer.

Beyond the scan

Where this goes when you need more than a passive read.

Deliverable

Full PDF report

Executive summary, factor-by-factor scorecard, full findings table, dedicated CVE tables, attack-surface network map and world-map infrastructure view, exposure-path narratives, company intelligence and a methodology checklist.

Tracking

Continuous monitoring

Rescan diffing that surfaces exactly what changed since last time — new or removed assets, ports, CVEs, storage buckets, lookalike domains and leaked credentials.

Independent validation

Third-party verification

Accepted risks, corrected version numbers and "we've fixed it" claims all move your projected score — but they are self-reported. Validation days buy CREST-accredited testers to independently check those claims and sign them off, so your report is verified by a third party. Continuous offensive testing is our separate Radar service.

Ready to upgrade?

Speak to our team to activate paid monitoring, discuss volume pricing, or add ongoing active testing to your account.

Pricing shown in GBP and excludes VAT where applicable. All plans are billed monthly unless otherwise agreed.