Continuous Threat Exposure Management

We Index the Internet. Your External Security Runs on It.

The domains you register, the certificates you issue and the passwords employees save all leave traces, and so do your vendors and the lookalikes built to copy you. Deepinfo indexes those traces continuously and shows your team which ones are exposures, before someone else reads them.

Last 24 hours, from our index 239,918 new domains registered 383 CVEs published 1 added to CISA KEV Internet Insights

Among the 10,000+ organizations working from Deepinfo data

  • Turkish Airlines
  • Turkcell
  • Aselsan
  • Bitsight
  • Wiley
  • Albaraka
  • Invicti
  • Türksat
  • Havelsan
  • Beko
  • Istanbul Airport
  • Tüpraş
  • Hes Kablo
  • DHMİ
  • TCDD
  • Türk Kızılay
  • PTT
  • Konya Metropolitan Municipality
  • Fatih Municipality
  • EntryZero
  • Boğaziçi University
  • Yıldızlar Holding
  • QIIB
  • Schmetterling
  • Oceanit
  • Solmaz
  • İHH
  • Burulaş
  • Doco

External Attack Surface Management

Map Everything You Own on the Internet. Especially What You Forgot.

Start from one domain. The platform discovers the subdomains, IP addresses, certificates, open ports and technologies behind it, then keeps scanning all of them. Findings arrive scored, with evidence your team can hand to an owner.

From one domain

acme.example, seen from the public internet. A site plan of your campus, roofs only: the hosts in your inventory inside its boundary, and past it one host nobody listed, with what EASM finds on each.
  1. Inside a surveyed boundary that is your inventory: www, mail, api, staging, shop, blog, each a building with its name on its roof.
  2. Asset discovery: past the boundary, a hut nobody listed, vpn-legacy.acme.example at 203.0.113.24, not in inventory: 3389/tcp · RDP open, critical.
  3. Continuous scanning: the api tower, api.acme.example: Certificate expires in 6 days, medium.
  4. Risk detection: the shop, shop.acme.example: PHP 7.4 · end of life, high.
  5. Risk scoring: the staging shed, staging.acme.example, runs Apache httpd 2.4.49: CVE-2021-41773, CVSS 9.8, listed in CISA KEV, critical.
  6. Remediation: the same CVE, owner assigned, marked as resolved, then verified resolved after the rescan.

Layer by layer

One asset

www.acme.example 198.51.100.10

  1. WHOIS

    registrar · renews in 41 days

  2. IP WHOIS

    AS64500

  3. DNS

    A 198.51.100.10 · MX mail.acme.example

  4. SSL

    *.acme.example · expires in 6 days Medium

  5. Ports

    443/tcp · TLS 1.3

  6. Web data

    nginx 1.25 · login page

  7. HTTP

    200

Every layer checked

In the platform

  • All assets 1,562
  • Domains 3 (selected)
  • Subdomains 1,312
  • IP addresses 247

Domains

  • grade A acme.example (opened on its record)
    • grade A www.acme.example
    • grade B shop.acme.example
    • grade C vpn.acme.example
    • grade A mail.acme.example
    • 1,280 more
  • grade A acme-eu.example
  • grade C acme-labs.example

grade A acme.example

Last check 2 hours ago

  • Overview (selected)
  • Issues
  • Subdomains
  • Technologies
  • Open ports
  • Vulnerabilities
  • Asset info

Info

IP addresses

  • 203.0.113.10
  • 203.0.113.11
  • 203.0.113.12
  • +5 more

Insights

Issues
38
Subdomains
1,284
Technologies
23
Open ports
46
Vulnerabilities
7

Brand Risk Protection

Find the Domains Built to Look Like You.

A convincing phishing page needs a convincing address. The platform matches newly seen domains against your brand names, down to letters from other alphabets that the eye cannot tell apart. When one resolves, your team sees its DNS, certificate and HTTP evidence and can request a takedown.

Built to pass as you

  1. acme.example

    Yours

    Listed as your own

  2. acme-login.example

    Domain · contains

    Serves a copy of your login, with a certificate

    Confirmed · to Managed Takedown

  3. аcme.example

    Domain · confusable_exact

    Its “а” is Cyrillic

    Suspicious · in review

  4. acrne.example

    Domain · fuzzy

    “rn” reads as “m” · its mail server: mail.acrne.example

  5. AcmeSupport

    App store

    Its publisher is not you

  6. acmesupport

    acrne-support.example/sign-in

    Search ad

    Leads to a login page

Third-Party Risk Management

Your Vendors’ Exposures Are Yours Too.

A questionnaire tells you what a supplier believes about itself. The platform scans each third party with the engine and layers it runs on your surface, and scores them all on one scale. When a vendor slips, you see it in the next scan, not the next annual review.

  1. acme.example

    Yours · your own surface

    A

  2. payroll.example

    Vendor · linked to you

    C→D

    • remote.payroll.example · 3389/tcp newly open Critical · not on the vendor’s list
    • docs.payroll.example · CVE-2021-41773 Critical KEV
    • The way in: payroll.example → acme.example. Their exposure becomes yours.
  3. cloud-hosting.example

    A

  4. cdn-provider.example

    A

  5. logistics-co.example

    B

  6. law-firm.example

    C

Under Every Module Is an Index We Built.

Many platforms rent their view of the internet. We collect ours, resolve it and keep it with its history. That data powers each module, and your analysts and developers can query it directly.

  1. Collect

    • Domain registrations and WHOIS
    • DNS records
    • SSL certificates
    • Port scans TCP · UDP
    • Web data and HTTP
    • Breach data, infostealer logs, dark web sources
  2. Resolve

    • Every name to the addresses it points to
    • Every CVE, enriched CVSS · EPSS · CISA KEV
    • Every finding matched to your domains, people and brands
    • Every issue scored and prioritized
  3. Keep

    • Every record, with its history
    • WHOIS history and daily domain deltas
    • DNS records, traced back in time

Read by every module EASM CTI BRP TPRM DSIand by your own code, through the REST API

400M+ domains

Registered domains across every TLD, with registration, WHOIS history and daily deltas.

Domain Search · Feeds · WHOIS

2B+ subdomains

Subdomains discovered and resolved to the IP addresses they point to.

Subdomain Finder · Feeds

200B+ DNS records

Every observed DNS record, kept with its history, so infrastructure can be traced back in time.

DNS Lookup · DNS History · Reverse IP · Reverse MX · Reverse NS

30B+ SSL certificates

Certificates collected and indexed. The names a certificate covers often reveal hosts nobody announced.

SSL Lookup

Query it

One REST API over the whole index: lookups, reverse lookups, history, discovery and vulnerability search.

Request

curl "https://api.deepinfo.com/v1/lookup/dns?domain=deepinfo.com&type=A,MX" \
  -H "apikey: $DEEPINFO_API_KEY"

Response

200 OK · application/json
{
  "fqdn": "deepinfo.com",
  "requested_types": ["A", "MX"],
  "responses": [
    {
      "type": "A",
      "conn_status": "success",
      "rcode": "NOERROR",
      "values": ["104.26.10.21", "104.26.11.21", "…"],
      "raw": "deepinfo.com. 300 IN A 104.26.11.21\n…",
      "server": "8.8.8.8"
    },
    {
      "type": "MX",
      "conn_status": "success",
      "rcode": "NOERROR",
      "values": ["1 aspmx.l.google.com", "5 alt1.aspmx.l.google.com", "…"],
      "…": "…"
    }
  ],
  "servers": ["8.8.8.8"],
  "check_date": "2026-09-22T12:25:59Z"
}

Cyber Threat Intelligence

Some of It Is Already Out There.

Breach dumps, infostealer logs, dark web forums and markets. The platform reads them for your domains, your employees and your customers, and ties each finding to a device, an account or a person your team can act on.

One infected laptop

ACME-LT-masked

Infostealer log

j.masked · Windows 11 Pro x64 · en-GB · an employee laptop, its log sold on a dark web market

  1. Infected device CTIone device, counted once:

    HWIDmasked

  2. [Passwords]41 saved

  3. Your SSO login CTIwith its password:

    URLhttps://sso.acme.example/login

    USER j.masked@acme.example

    PASS masked

  4. The host nobody listed EASMand now its password:

    URLhttps://vpn-legacy.acme.example

    USER j.masked

    PASS masked

  5. Session cookies CTIpast the password and MFA:

    [Cookies]1,208 · 36 sensitive

  6. [Autofill] · [Tokens]312 · 4

  7. Password reuse CTIone password, many sites:

    SamePassword63%

Tied to one device, one account and one person, so your team resets the right login and cleans the right laptop.

Issue openednewly_detected

Every Finding Gets a Score, an Owner and a State.

Vulnerabilities are ranked with CVSS, EPSS and CISA KEV together, so the top of the list is what attackers are most likely to use. Each issue then moves from state to state until a rescan confirms it is gone. If the signal comes back, the issue reopens by itself.

Found

Open

The team decides

The rescan verifies

newly detected

orreappeared

unresolved

marked as resolved

closed by decision, kept on record

  • risk accepted
  • ignored
  • marked as false positive
  • not applicable

verified resolved

rescan confirms the fix

Around each issue

Notifications

New, reappeared and changed findings, delivered instantly, hourly, daily, weekly or monthly.

Reports

From the executive summary to issue detail, as PDF, on demand or on a schedule.

Compliance Mapping

Each issue classified against OWASP, PCI DSS, HIPAA, CWE, CAPEC and WASC.

In use

10,000+

organizations work from Deepinfo data, on the platform and through the API. Banks, airlines, telecom operators, defense manufacturers, public institutions and security vendors among them.

Customer stories
  • Turkish Airlines
  • Turkcell
  • Aselsan
  • Bitsight
  • Wiley
  • Albaraka
  • Invicti
  • Türksat
  • Havelsan
  • Beko
  • Istanbul Airport
  • Tüpraş

Start With Your Own Record.

A scoped walk-through of the Deepinfo Platform, run against your own domains.