Skip to content

External attack surface

Attack surface management from the attacker's view

blacklens.io discovers every internet-facing domain, IP, service and technology, scores each asset and reports changes before someone else exploits them.

Attack surface management from the attacker's view
Technology Fingerprints
1000+
Monitored Assets
1 Mio+
top-level domains in lookalike detection
357
product versions for technology matching
2.1M+

Every asset, including the forgotten ones

You provide a domain, an IP or a network. blacklens.io expands the scope on its own and finds hosts, services, web applications and technologies.

Newly discovered assets+4 since yesterday
beispiel-gmbh.atRoot domain
vpn.beispiel-gmbh.atFortiGate SSL-VPN 7.0.12Critical
dev-old.beispiel-gmbh.atGitLab 15.2Shadow ITHigh
mail.beispiel-gmbh.atExchange Server 2019Medium
203.0.113.24OpenSSH 8.9NewInfo

Visuals show sample data.

  • Discovery in five steps

    Host, service, web, technology and lookalike, each step building on the one before.

  • Technology inventory as CPE

    The basis for real-time CVE matching in the early warning system.

  • Tags and CSV export

    Tag assets individually or in bulk and export any list as CSV.

Score it, don't just list it

A long asset list helps no one. blacklens.io shows what is exposed, vulnerable or not yet monitored.

Progresslast 90 days
Critical findings143
Exposed services3821

Visuals show sample data.

Spot lookalike domains, prepare the takedown

Phishing often starts with a domain that resembles yours. blacklens.io checks spelling variants of your domains daily, takes screenshots and assesses every hit.

Lookalike domainschecked daily
beispiel-gmbh-login.comImpersonation
beispiel-gmbh.coSuspicious
beispiel-gmbh.shopParked
Abuse report ready5 of 5 criteria

Visuals show sample data.

  • AI verdict with confidence

    Impersonation, suspicious or parked, backed by signals such as a password field.

  • Pre-filled abuse report

    Once five evidence criteria are met, you send it to the registrar or hosting provider.

  • The list stays current

    Lookalikes that stay inconspicuous for 60 days are removed automatically.

Frequently asked questions

External attack surface management (EASM) is the continuous, automated discovery of every system of a company that is reachable from the internet: domains, subdomains, IP addresses, open services, web applications and the technologies in use. Unlike a one-off scan, EASM runs continuously and reports changes such as new hosts, new services or expiring certificates. blacklens.io adds vulnerabilities, dark web signals and lookalike domains to that view so the inventory becomes a prioritised task list.

See your attack surface within 24 hours.

Start with one domain. We set up the workspace and walk through the first findings with you.

  • 14 days free, all features
  • No credit card required
  • We walk you through your first findings