Domains and subdomains
The registered domains an organisation owns, and the subdomains beneath them. See.Tech enumerates subdomains from passive DNS and certificate transparency logs, which routinely surfaces hosts nobody has a record of.
External Attack Surface Management
External Attack Surface Management, or EASM, is the practice of identifying and assessing the internet-facing assets, technologies and weaknesses that can be observed and targeted from outside an organisation.
See.Tech is an agentless EASM platform. It starts from a domain name, maps what that organisation exposes to the public internet, and returns findings scored by real-world severity. There is no software to install, no appliance, and no access to an internal network.
The external attack surface
An external attack surface is everything about an organisation that is reachable, or discoverable, from the public internet. It grows without anyone deciding that it should.
The registered domains an organisation owns, and the subdomains beneath them. See.Tech enumerates subdomains from passive DNS and certificate transparency logs, which routinely surfaces hosts nobody has a record of.
Publicly reachable IP addresses and the services listening on them, along with the software versions those services disclose.
The MX, SPF, DKIM and DMARC configuration that determines whether an outsider can impersonate the domain in email.
SSL/TLS protocol support, cipher strength, certificate validity, and expiry dates, tracked with alerts as expiry approaches.
Credentials tied to the domain that have appeared in breach corpora or on dark web sources.
Lookalike and typosquatted domains registered to impersonate the organisation, which are part of its attack surface even though it does not own them.
Comparison
These are different jobs, not competing products. A vulnerability scanner examines hosts you already control and already know about. EASM examines what the internet can reach, including the assets nobody registered.
| Traditional vulnerability scanner | See.Tech external assessment | |
|---|---|---|
| Deployment | Often requires agents, credentials or an appliance | Agentless. A domain name is all that is required |
| Perspective | Inside-out, across a known asset inventory | Outside-in, from the public internet |
| Scope | Primarily software vulnerabilities on managed hosts | Vulnerabilities plus credentials, email, DNS, TLS, reputation and brand risk |
| Asset knowledge | You supply the asset list | Assets are discovered from public information |
| Third parties | Generally not practical without access | A supplier can be assessed the same way as your own domain |
| Output | Technical findings | Technical findings plus a consolidated risk score and executive reporting |
Most organisations need both. Neither view can see what the other sees.
An honest boundary
See.Tech is not the right tool for every organisation, and pretending otherwise would waste your time.
Enterprise EASM suites are a better fit where an organisation needs discovery across tens of thousands of assets, deep integration into an existing SOC and ticketing estate, extensive workflow automation, or dedicated attack surface reduction programmes with staff assigned to them.
Questions
External Attack Surface Management, or EASM, is the practice of identifying and assessing the internet-facing assets, technologies and weaknesses that can be observed from outside an organisation. It answers the question an attacker asks first: what is reachable, and what is weak?
An external attack surface is everything about an organisation that is reachable or discoverable from the public internet. That includes domains and subdomains, internet-facing hosts and services, email infrastructure, certificates, publicly exposed credentials, and domains registered to impersonate the brand.
See.Tech does not. Assessment is entirely external and requires no software installation, no appliance, no VPN and no credentials. A domain name is enough to begin. Some enterprise EASM suites do pair external discovery with internal agents; See.Tech does not need one.
A vulnerability scanner assesses hosts you already control and have listed, usually with credentials or an agent, and reports software vulnerabilities. EASM assesses what the internet can reach, discovers assets you did not list, and covers a wider range of exposure including credentials, email authentication, DNS, TLS and brand impersonation.
No. See.Tech identifies and scores weaknesses but never exploits them, and assessments are non-invasive. A penetration test proves exploitability by attempting it, usually by hand, against a defined scope. The two are complementary: an external assessment is a well-evidenced place to point a penetration test.
Yes. Because assessment uses only publicly available information and requires no access, a supplier can be assessed the same way as your own domain. You remain responsible for ensuring you are authorised to assess a given domain, and every scan records an authorisation acknowledgement against the user who ran it.
Pricing is credit-based. Bundles start at US$36 for 10 scan credits, and individual scans cost between 1 and 10 credits depending on depth. Credits do not expire and can be spent across any scan type.
Start here
A See.Tech assessment starts from a domain name. Nothing is installed, no credentials change hands, and the first findings come back in hours.
Let's talk about protecting your brand, your customers, and your reputation. Our team is ready to show you exactly how See.Tech can help, starting today.