Discover · Exposure
SurfaceX
A domain-scoped external-exposure snapshot prototype for analyst review.
What it is
A domain-scoped external-exposure snapshot prototype for analyst review.
Decision this supports
Decide whether a limited DNS, certificate-transparency and HTTPS observation warrants validation.
Current, bounded capabilities
- Performs a narrow local snapshot using public DNS, certificate-transparency and HTTPS observations.
- Presents the resulting observations for analyst review.
- Can print the current browser view.
Limitations
The AI mode does not collect target evidence and must not be treated as a verified finding source; this is not continuous EASM.
Next safe action
Validate any observation with authoritative evidence before remediation or escalation.
How it works
Authorized target → provider observations → source attribution → analyst interpretation → validation action.
Input / scope
An authorized public domain and observation timestamp; private targets, IPs, ports, paths, credentials, queries, and fragments are out of scope.
Observable output
Point-in-time observations labeled by source: certificate transparency, DNS-over-HTTPS, or HTTPS.
Human decision
The analyst validates each observation with the provider or authoritative evidence before escalation.
Troubleshooting
- Provider unavailable: record the failed source and retry later.
- No records: treat absence as an observation, not proof of safety.
- Redirects or certificate mismatch: validate the endpoint and certificate independently.
Sources and review
SurfaceX is not continuous EASM, does not publish coverage or accuracy metrics, and AI mode is not a verified finding source.