Skip to content

SERVICE 02

Continuous monitoring of your exposed surface and your providers’, with every alert validated by the team

Continuous monitoring of your published external surface, with a baseline set at the start and every change tracked from there. In-house tooling takes on the repetitive steps and the team validates each alert before it goes out. You get a notification for every confirmed critical finding and a report on how your surface changed.

  • In-house tooling
  • CVE
  • Leaked credentials
  • Cybercrime forums
  • Phishing
  • Telegram
  • 24/7
  • Bespoke integration
  • Providers

Technical scope

  • Continuous discovery of assets, subdomains and exposed panels, with in-house tooling that tests what it finds for vulnerabilities
  • Vulnerabilities and CVEs affecting what you have published, tracking those already under active exploitation
  • Internal panels reachable from outside that should not be
  • Files, backups and paths published by mistake
  • Credentials from your organisation leaked in breaches and traded in access markets
  • Domains registered to impersonate you: cybersquatting, typosquatting and certificates issued in your brand’s name
  • Phishing campaigns using your brand or your domains
  • Crimeware forums and channels where access to companies like yours is traded
  • Threat groups and actors active on Telegram, tracking those that mention your sector
  • Exposed surface of the providers included in the scope, watched just like your own
  • Tracking of every change against the agreed baseline
  • Round-the-clock monitoring, every day of the contracted period
  • Manual validation of every alert before it goes out

The remaining sources we watch are part of our method and are not listed here.

Deliverables

  • Notification through the agreed channel as soon as the team confirms a critical finding
  • Exposure summary inside each report, with how your surface changed over the period
  • Alerts confirmed by someone on the team, not by the tooling
  • A single point of contact on the team monitoring your surface
  • Report with an executive summary for management, for each agreed period

Your providers, inside the scope

Much of what comes in from outside does not arrive through your domain but through a third party in your supply chain. That is why the agreed scope can include the providers your service depends on, watched to the same standard as your own surface.

  • Hosting, platform and service providers that keep your operation running, with the same baseline and the same tracking as your own assets
  • Credentials and access to your organisation leaked through a third party
  • Published breaches affecting one of your providers, with notice as soon as it is confirmed to reach you
  • Provider domains and brands used to impersonate them in campaigns targeting your staff
  • Changes to the exposed surface of every provider included in the scope

Every provider enters the scope in writing, and only with whatever authorisation each case calls for.

Integrations

Monitoring does not replace what you already have deployed: it connects to it. Each deployment is resolved with a bespoke integration, built around the systems your organisation already runs, so their alerts enter the same flow as the rest of the monitoring.

  • Alerts from your EDR or antivirus, brought into the same flow and handled alongside the rest of the monitoring
  • Output from your vulnerability scanners, filtered and prioritised by the team before it reaches your organisation
  • Your asset inventory, so the baseline starts from what your organisation already has on record
  • Delivery of confirmed findings where your team already works: email, corporate chat or ticketing system
  • Cloud consoles and event management platforms, where the agreed scope covers the telemetry they already collect

The point is to stop alerts piling up with nobody reviewing them: they come into one flow, someone on the team validates them, and only what is confirmed goes out. The list is not closed. If your environment runs a system that carries signal, it is assessed and agreed in writing before it is integrated.

Service phases

PHASE 01

Baseline

An initial inventory of the exposed surface, agreed in writing as the baseline. The team tracks every change from that point on.

Initial inventory
PHASE 02

Ongoing monitoring

The team monitors your surface throughout the contracted period. In-house tooling takes on the repetitive steps. CTI coverage extends to forums, marketplaces and the dark web.

Change alert
PHASE 03

Manual validation

The tooling gathers the data. Someone on the team confirms the finding, sets its priority, and only then does the alert go out.

Confirmed finding
PHASE 04

Periodic reporting

The team reports critical findings as soon as it confirms them. The rest goes into the periodic report, along with how your surface changed.

Trend report

Frequently asked questions

How is continuous monitoring set up?

Continuous monitoring runs on a recurring term. The monitored scope and the reporting frequency are agreed in writing before the work starts.

What exactly is monitored?

Your exposed surface and what moves around it. On your side: domains, subdomains and panels that appear, change or disappear against the baseline, internal panels reachable from outside that should not be, files and paths published by mistake, credentials from your organisation leaked elsewhere, and domains registered to look like yours. On the attacker side: phishing campaigns using your brand, forums and channels where access is traded, and the groups active in your sector. We follow how those groups operate so we can reproduce their techniques against the systems we audit before they do, and what we learn from one actor feeds the defence of every other client. The detail of the remaining sources is part of the tooling and is not published.

Can monitoring affect service availability?

Monitoring is limited to observing your published surface, with no intrusive testing and no load on your systems. Any active check is agreed in writing, with an execution window and a notification channel.

Published findings of this kind

Request scope and terms

Tell us which assets you want tested. We reply within 24 hours.

Request an auditCall