Understand what the internet exposes — and what can be validated from it.
zer0cipher discovers external assets, maps reachable services, evaluates common exposure conditions, and validates supported paths that could give an attacker a way in.
What is reachable, resolved, and worth a closer look.
Discovery starts from your authorized scope and fans out across the categories an outside attacker would enumerate first.
Your scopeAuthorized domains
DNS & subdomainsmail · vpn · app
InfrastructureIPs · open ports
Web surfaceslogins · admin paths
IdentitiesM365 · SPF / DMARC
TLS & metadatacerts · CVE signals
How the engagement works
Discover, evaluate, and watch for change.
01
Build the external picture.
DNS & subdomains
Related names, records, and certificate-transparency signals.
Ports & services
Reachable infrastructure and the technologies presenting it.
Web surfaces
Probe HTTP services, capture screenshots, and find exposed admin paths.
02
Evaluate perimeter weaknesses.
Identity paths
Microsoft 365 enumeration and authorized spraying within policy.
Mail & transport
TLS analysis, SPF/DMARC checks, and public metadata review.
Known exposure
Directory discovery and CVE scanning against reachable services.
03
Track supported changes.
Recurring views
Notice new assets, services, and certificate conditions over time.
Change signal
See what moved between deeper assessments, not a single snapshot.
No false certainty
Observations are not silently upgraded to proven exploits.
Where the boundary ends
What this test is, and what it is not.
Current product boundary
External Attack Surface testing evaluates internet-facing infrastructure and supported exposure paths. Credential testing runs only when authorized and within the engagement's configured risk policy. It is not a replacement for a dedicated manual web-application assessment — and full web-app testing, phishing, cloud, and Kubernetes are not current product claims.
NEXT STEP
See your external surface the way an attacker enumerates it.