Reachable services, detected software and potential vulnerabilities.
Visuals show sample data.
Frequently asked questions
Yes. The exposure check is a free excerpt from the blacklens.io platform and comes with no obligation. You see the summary immediately in your browser and receive the report with hosts, services, vulnerabilities and dark web findings by email. On request we walk you through the results, or you start the 14-day trial with the full feature set.
The result is a summary of your domain's publicly visible attack surface. It lists the number of detected hosts and subdomains, exposed services, detected technologies, potential vulnerabilities, lookalike domains and dark web findings. Values that could not be determined for your domain are hidden instead of showing a misleading zero. The detailed report arrives by email.
No. The exposure check is a purely passive analysis: it evaluates publicly available sources such as DNS records, certificates, internet scanner data and breach and stealer databases. Active scans only run with your authorisation in the trial or as a customer. They run exclusively from scan infrastructure in Austria, Germany and Switzerland and from fixed source IP ranges.
The exposure check analyses the company domain behind your email address. With free-mail domains such as gmail.com the result would not show your company, so we do not accept these addresses. It also ensures that information about an organisation's attack surface only goes to people who use an address of that organisation.
Your email address and the result are stored in our CRM so we can send you the report and answer follow-up questions. Processing takes place exclusively in the EU. You only receive a newsletter if you sign up for it separately. All details on the processing are in our privacy policy.
The exposure check is a one-off snapshot from public sources. In the 14-day trial the full platform runs: continuous asset discovery, vulnerability scans with more than 200,000 tests, dark web monitoring, lookalike detection and alerts for your entire attack surface. You can also connect internal networks with Sentry and cloud accounts such as AWS, Azure or Microsoft 365.
An exposure check shows the entry points attackers look for before an attack: exposed VPN gateways, forgotten test systems, outdated software and leaked passwords. Access brokers sell such access on to ransomware groups. Knowing these points lets you close them before they are exploited. For continuous monitoring instead of a snapshot, attack surface management is the right approach.
See your attack surface within 24 hours.
We set up your workspace and walk you through the first findings.