Know what you own, not what you documented
External attack surface mapping (EASM) finds everything reachable from the internet, documented or not, then lets you test any of it in one click.
Your inventory is a spreadsheet. Your attack surface is not
The staging box left running since 2023 is not in it. Nor is the acquired subsidiary whose DNS still points at live infrastructure, or the certificate expiring in eleven days on a subdomain nobody owns. A CMDB records what was requested through a process. Attackers do not work from that list. They build their own.
An asset that is not in your inventory is not in your scope, not in your pentest, and not in your risk report. It is still on the internet.
Auditors ask for a complete asset inventory. Acquirers ask what they are buying. Neither accepts “as far as we know”.
One root domain in. No agents, no credentials. Every asset is one click from a full authenticated test, so visibility and validation share a platform.
From one root domain to a ranked, testable inventory
Four stages, each one picking up where the last left off. Jump to any of them.
Find the infrastructure your team stopped thinking about
One root domain in. Historical DNS surfaces hosts your team assumed were decommissioned years ago.
- Subdomain enumeration from one root. The full connected surface, including shadow IT nobody registered.
- Historical DNS cross-referencing. Dormant and abandoned hosts surfaced, then live-checked.
- Technology fingerprinting. What each asset is running, without a credentialed scan.
- Multiple roots and custom scoping. Add subsidiaries, and toggle anything you do not own out of scope in one click, right in the asset table, no ticket required.
- Monitoring coverage, visible at a glance. See exactly which domains are actively monitored and which are not, so a gap doesn't hide in a sea of green.
Know which exposures are already a problem
A list of assets still leaves you guessing what to fix first. Here, every asset arrives already graded.
- TLS and certificate grading. Protocol strength, cipher suites and expiry, scored A+ to F per asset.
- Full certificate forensics. Issuer, validity period, MD5, SHA1 and SHA256 fingerprints, and serial number, not just a letter grade.
- Every cipher suite named and rated. Each TLS 1.2 and 1.3 cipher suite in use on a host, flagged as recommended or not.
- HTTP and redirect behaviour. Request type, response code, response time, redirect chain and content length, captured per host.
- Screenshot and geographic location, where available. Visual proof of what's exposed on hosts that allow it, plus country, timezone and whether it's your origin server or a CDN edge.
- Standard, high-risk and unusual ports flagged per host. Not just whether a port is open, but whether it's one that shouldn't be.
See the estate, not just the asset
Individual grades roll up into one estate-wide view: what your whole estate looks like today, and where it's trending.
- Estate-wide TLS and cipher posture. Every weak cipher suite and deprecated protocol, counted across all hosts at once.
- Email security per domain. SPF, DMARC, MX and mail-related TXT records, so a phishing gap can't sit unnoticed on a domain nobody watches.
- Certificate expiry as a trend. Next expiry date plotted 90 days back and forward, live on the dashboard.
- Who runs, issued and registered what. Tech stack, certificate issuer and registrar for every asset, tied to ownership so a subsidiary or shadow registration stands out instead of blending into the totals.
- Geography, explained. Asset counts by country on a live map, with a note when a location is a CDN edge rather than your origin.
- Every grade failure in one view. Everything below an A in one place, and a clean all-clear when there's nothing to fix.
From “we found it” to “we tested it” without leaving the page
This is the part most attack surface tools do not have. Any asset, one click from a full test. The inventory you hand an auditor becomes the same one your team tests from.
- Launch a test from the asset view. AI-native DAST, vulnerability assessment, or a scoped expert-led engagement.
- Auto-queue new assets. Newly discovered infrastructure goes for assessment as it appears.
- Criticality tagging, Mission Critical to Negligible Impact. Set once on the asset, inherited by every finding raised against it.
- Compliance mapping happens at test time. Mapping does not log or score findings on its own; launch a test on any asset and what comes back is mapped automatically to CWE, OWASP and the PCI DSS, HIPAA and ISO 27001 controls it violates.
AISO™ reads the backlog before you do
Discovery finds the assets. AISO writes the decisions: what is exposed now, what is about to break, and where remediation is slipping.
Your AI Security Officer, offering real-time insights and risk-based decision support.
Imminent SSL/TLS Certificates Expiry
8 SSL/TLS certificates will expire in the next 30 days, which could lead to service disruptions and security risks.
Inefficiencies in Vulnerability Remediation Cycles
MTTR for certain critical vulnerabilities exceeds 7 days, indicating inefficiencies in your current remediation process.
Unrestricted Hacker Access Through Unpatched Exploits
10 vulnerabilities allow unauthenticated exploitation and have public exploits already available.
Zero-Day Vulnerabilities Jeopardize Security
Multiple unpatched vulnerabilities could grant attackers unauthorized access to critical systems.
Vulnerabilities Lacking Patches Pose Immediate Risk
Active vulnerabilities identified with no patch currently available, increasing your attack surface.
Vulnerabilities Enable Lateral Movement or Privilege Escalation
A number of new vulnerabilities allow lateral movement across systems and privilege escalation.
Imminent SSL/TLS Certificates Expiry
8 SSL/TLS certificates will expire in the next 30 days, which could lead to service disruptions and security risks.
Inefficiencies in Vulnerability Remediation Cycles
MTTR for certain critical vulnerabilities exceeds 7 days, indicating inefficiencies in your current remediation process.
Unrestricted Hacker Access Through Unpatched Exploits
10 vulnerabilities allow unauthenticated exploitation and have public exploits already available.
Zero-Day Vulnerabilities Jeopardize Security
Multiple unpatched vulnerabilities could grant attackers unauthorized access to critical systems.
Vulnerabilities Lacking Patches Pose Immediate Risk
Active vulnerabilities identified with no patch currently available, increasing your attack surface.
Vulnerabilities Enable Lateral Movement or Privilege Escalation
A number of new vulnerabilities allow lateral movement across systems and privilege escalation.
Fits into the stack you already run.
Attack surface mapping vs the tools you run now
| Manual inventory / CMDB | Standalone discovery tool | Siemba, unified | |
|---|---|---|---|
| How assets are found | Recorded when requested | Automated external discovery | Continuous automated external discovery, plus historical DNS for dormant infrastructure |
| Access required | Internal and credentialed | Varies by vendor | None: no agents, no credentials, no network access |
| Freshness | As current as the last update | Scheduled scans | Rescanned every 8 hours once monitoring is on, not a weekly or monthly scan |
| Exposure detail | Hostname and owner | Ports and services | TLS and cipher grade A+ to F, certificate expiry, technology fingerprint, screenshot, geo |
| What you can do about it | Raise a ticket | Export a CSV | Launch a full authenticated test on any asset, in one click |
| Where findings go | Nowhere | A separate console | One list shared with assessment, autonomous testing and manual pentest, de-duplicated at ingest |
| Compliance evidence | Manual mapping | Basic tagging | Not native to discovery; launch a DAST run on any asset and the findings map to CWE, OWASP and the PCI DSS, HIPAA and ISO 27001 controls they violate |
How Siemba compares
vs a standalone EASM or discovery tool
Most EASM tools find assets and stop. You still need a scanner, a dynamic testing tool and a pentest vendor to do anything about what turned up, plus four consoles to reconcile. Here, discovery is the front of one pipeline that ends in a verified fix.
vs your cloud provider’s inventory
It knows what is in your accounts. It does not know about the subsidiary’s DNS, the contractor’s landing page, or the host migrated off three years ago that is still resolving.
See your external attack surface before you talk to anyone
Enter one root domain. You get the inventory an attacker would build: subdomains, live hosts, technology fingerprints, TLS grades and certificate expiries. No sales call required.
The outcomes security teams get from Siemba
Four disciplines, one risk model
Mapping finds it. Assessment ranks it. Autonomous testing proves it. Certified engineers go deeper when the stakes demand it. One shared findings list across all four, de-duplicated at ingest, is the payoff.
Vulnerability Assessment
Findings ranked by live exploit intelligence and reachability, not severity alone.
Learn more →AI-Native DAST
Drop a URL. Authenticated testing behind MFA, with evidence on every finding.
Learn more →Expert-Led Pentesting
Certified in-house testers on web, API, cloud, network, mobile and AI systems.
Learn more →API Security Testing
REST, GraphQL and SOAP, tested for the authorisation gaps that leak data.
Learn more →The Full Platform
All four disciplines, one workflow, one risk model, one proof of closure.
Learn more →Pricing scales with your estate, not per seat
Automated assessment, mapping and autonomous testing come on one subscription. Expert-led engagements are scoped per application.
The questions you'll actually ask
What is external attack surface mapping (EASM)?
What's the difference between attack surface mapping and vulnerability management?
What's the difference between EASM and CAASM?
Why does attack surface mapping matter?
Do I need EASM if I already run penetration tests?
Is EASM necessary for a small company?
Does this need agents, credentials, or network access?
How is this different from the asset inventory we already have?
How do you handle assets we don't actually own?
Can we use this for subsidiaries or M&A due diligence?
Does mapping actually test anything, or just find it?
How quickly do we see the first inventory, and how often does it refresh?
Is attack surface mapping the same thing as external attack surface mapping?
How is the A+ to F certificate grade calculated?
Someone is mapping your attack surface today. Make sure it’s you first
Point Siemba at one domain and see the inventory an attacker would build. No contract, no agents, no sales call.
Download Sample Report
Enter your work email and your download will start instantly.
Thanks for providing your email.
Your report should already be downloading. If you don't see it, check your downloads folder, or try again in a few minutes.