product image
product image

Attack Surface Monitor

$29/ month
14 day trial

Self-hosted attack surface discovery & exposure monitoring

Attack Surface Monitor discovers your internet-facing assets from your own server, the way an attacker sees you, and tells you what changed.

Features

  • Passive discovery: subdomains via Certificate Transparency and DNS; keeps only assets that resolve
  • Exposure checks: reachable databases (Postgres/MySQL/Mongo/Redis), open RDP/VNC/Telnet, full open-port inventory
  • The daily diff: new subdomain or opened port = new finding; closed ones auto-resolve
  • Honest coverage: behind a wildcard certificate CT hides subdomains — the report says so rather than passing off a small number as the whole surface (v0.1.1)
  • Every finding carries the fix; bursts become one digest
  • Ownership gate: no probing until you prove control via DNS TXT or HTTP file

Server requirements

  • Linux x86-64; single binary or Docker; ~10 MB binary, ~10 MB RAM idle, SQLite file — no database server
  • Minimum host: 1 vCPU, 512 MB RAM, 200 MB disk; more assets = more scan time, not RAM
  • Dashboard 127.0.0.1:8423; outbound DNS/HTTPS to CT logs and your own domains only

Tiers. Free: 1 domain, webhook + syslog alerts (GitHub, v0.1.1). Pro: 10 domains, custom interval, scan-now, email/Slack/Telegram. Team: unlimited, PagerDuty/MS Teams, priority support. 14-day trial.

Offline activation, no phone-home.

Delivery. Automatic: key by Whop DM after checkout; download in the Downloads tab.

Whop sells paid licences only. Free: github.com/nizartuanku/attack-surface-monitor