Resources

Guides and methodology

Plain-English material on external attack surface management and how Disruptors ASM reaches its conclusions.

Reading

Frequently asked

Is the scan intrusive?
No. Passive scanning uses only publicly available data and standard, non-intrusive requests. Anything that touches a target more aggressively runs under Active Mode, which you explicitly authorise per finding.
How is this different from a vulnerability scanner?
A vulnerability scanner tests assets you already know about. Attack surface management finds the assets you have forgotten — the staging subdomain, the exposed bucket, the lookalike domain — and then assesses them.
How often should we scan?
On a schedule. External footprints change every time someone spins up a host, renews a certificate or publishes a new service. Monitoring plans re-scan on a schedule and track what changed since last time.
Do findings get verified?
Yes. Findings are cross-validated across independent sources and confirmed by response content signatures, never by an HTTP 200 alone. Active Mode adds exploit-level evidence on demand.

This report is based on publicly available data and may include false positives. Active testing via Disruptors Radar confirms which findings are genuinely exploitable.