When the print dialog opens: choose "Save as PDF", then uncheck "Headers and footers" under More settings.
External Attack Surface
See Your Perimeter the Way an Attacker Sees It
Most organisations cannot list their own internet-facing assets. Forgotten subdomains, staging environments, exposed admin panels and outdated technologies accumulate quietly — and attackers find them before defenders do. RECON Essentials is external attack surface management: it discovers everything reachable from the public internet under your domain family, identifies what runs there, correlates it against live vulnerability intelligence, and turns the result into a single risk score a board can act on.
Key takeaways
- Discovery is continuous and repeatable — point it at a domain and it enumerates the full external footprint, including shadow infrastructure and delegated assets you have lost track of.
- Detection accuracy of 90–95% with cross-validation that drives false positives from roughly 20% down to under 10%, so the findings survive scrutiny.
- Vulnerability intelligence is aggregated from ten independent sources — including the European Union Vulnerability Database (EUVD) — so a CVE missed by one feed is caught by another.
- Every finding is scored for real business risk, not just raw severity. A medium-severity flaw on a payment system outranks a critical flaw on a disconnected asset.
- The output is a multi-language executive report with NIS2 classification and sector risk context — built for the supervisor and the board, not only the security team.
Who should read this
- CISOs and security leads who need a defensible, continuously updated view of their external attack surface.
- IT teams responsible for asset inventory, patching priorities and exposure reduction across many domains.
- Compliance and risk officers preparing NIS2 evidence and reporting on cyber risk to the board.
- Managed service providers and partners scanning portfolios of client domains from a single dashboard.
Discovery & Asset Inventory
You cannot defend what you cannot see. The first job of RECON is to build a complete, current inventory of everything your organisation exposes to the internet — across your entire domain family, not just the website you remember.
Watch the External Scan Run
The scan is not a black box. From the moment a domain is submitted, each phase reports live — subdomains found, hosts resolved, ports opened, technologies detected and CVEs correlated — up to the single risk score.
Every phase is documented and inspectable, so a technical buyer or auditor can follow exactly how a finding was reached — automated throughout, with no manual triage between the stages.
The Scan Pipeline
A single domain moves through a fixed sequence, from discovery to a scored report. Nothing is a black box — every stage is documented and inspectable, and the whole pipeline runs automatically.
Speed and rigour are not a trade-off here. Phases run concurrently and share a common cache of TLS and DNS results, so the work that would take an analyst hundreds of hours runs automatically — and every step can be opened, explained and defended to a technical buyer or an auditor.
Inside the Pipeline
The high-level pipeline expands into eight specialised phases. Many run in parallel and share a common cache of TLS and DNS results, so the work runs automatically — without the analyst weeks a manual exercise would take.
Passive collection of subdomains from open-source intelligence, certificate transparency and passive DNS, producing a validated list of live hosts.
HTTP/S probing and top-port scanning (up to port 1,000 in comprehensive mode) across every host, capturing services, banners and security headers.
Certificate-chain analysis and provider detection map your cloud and CDN footprint and flag outdated or expiring certificates.
Static analysis of headers, HTML and static assets matches detected technologies against the full signature library and extracts versions.
Modern single-page applications are rendered so client-side libraries and frameworks are detected at runtime, with versions, where static analysis cannot reach.
Detections of common technologies are confirmed by at least two independent techniques, driving the false-positive rate from around 20% to under 10%.
Each identified technology is correlated against six vulnerability databases in parallel — including the European EUVD — then enriched with four exploitation-intelligence sources, deduplicated and confidence-scored.
A single business-relevant risk score is computed, and an executive narrative with NIS2 classification and sector risk is generated in multiple languages.
Multi-Source CVE Intelligence
Any scanner can produce a list of CVEs. The hard part is producing a list that is complete, accurate and current. Every vulnerability database has blind spots, so RECON queries six vulnerability databases in parallel, then enriches the correlated results with four exploitation-intelligence sources — and deduplicates by CVE identifier, scoring confidence by how many sources agree.
A vulnerability recorded in one database may be absent from another. By cross-referencing a US government source, a major open-source feed, public advisory data, a European CSIRT feed and the EU's own vulnerability database, the chance of missing a critical CVE drops sharply — and European coverage is built in rather than bolted on.
How Ten Sources Combine
No single vulnerability database is complete. RECON fans every detected technology out across six vulnerability databases in parallel, then enriches the correlated results with four exploitation-intelligence sources — folding everything into one deduplicated, confidence-scored list.
Business Risk Scoring
A severity score tells you how bad a flaw could be in theory. It does not tell you what to fix first. A critical flaw on a disconnected test system is low business risk; a medium flaw on your payment gateway is high. RECON weighs four factors to turn a list of vulnerabilities into a single, defensible score from 0 to 10.
The Single Risk Score
Four weighted factors collapse a list of vulnerabilities into one number from 0 to 10. Here is how three example findings resolve into a single, defensible score.
A 9.1-severity vulnerability does not automatically produce a 9.1 risk score. After weighting the top findings by exploitability, exposure and technology criticality — and applying gentler decay to the most serious — three example flaws resolve to a single 6.9 / 10. The formula is documented and reproducible, so the number can be defended to a CISO or a board without hand-waving.
Reporting, NIS2 & Portfolio Scale
A scan is only useful if its findings reach the people who decide. RECON turns every scan into a board-ready report and places the risk in regulatory and sector context — then lets you do it across an entire portfolio of domains at once.
Severity in the Report
The executive report opens with the vulnerability picture at a glance: how many findings sit at each severity level, and how the total breaks down — the same view the board sees.
Severity is the starting point, not the verdict — every finding is re-weighted for business risk before it reaches the single score.
Sector Risk Context
A finding means more in some sectors than others. RECON frames your measured posture against annual breach rates by sector, so the risk score lands in the regulatory and threat context that applies to you.
Annual breach rate by sector
Sector breach rates drawn from IBM Cost of a Data Breach 2025, Sophos State of Ransomware 2025 and ENISA Threat Landscape 2025. Used to contextualise — not replace — your own measured technical posture.
Why It Matters & What It Replaces
External attack surface management is not another scanner to add to the pile. It consolidates work that is otherwise slow, partial and scattered across tools — and gives a security leader a single, current, defensible view of exposure.
Next steps
- Request a sample external scan report for one of your own domains and see the full output end to end.
- Book a no-commitment walkthrough of the dashboard and the documented risk methodology.
- Add RECON to your continuous external attack-surface monitoring programme across your domain portfolio.
Contact: [email protected] · orizon.one/recon · European, NIS2-native, EUVD-aware infrastructure.