Blog
Writing from the team that builds Maphra (External Attack Surface Management (EASM)) and AppSecD (Application Security Posture Management (ASPM)). The subjects follow the work: what
discovery turns up on real estates, why a finding was or was not worth paging somebody
about, and what actually changes when scanning becomes continuous instead of quarterly.
What we write about
- External attack surface — enumeration, attribution and the assets nobody remembered registering. Maphra discovers everything your organisation exposes to the internet, decides what actually matters, and proves exploitability — continuously, without an agent and without a credential.
- Exposure analysis — TLS and certificate posture, security headers, DNS hygiene and email authentication, and which of those matter when.
- Credential and brand exposure — breach corpora, look-alike domains and impersonating applications: the attack paths that never touch your network.
- Application security — SAST, DAST, SCA, secrets, IaC and API testing, and the difference reachability makes to a finding queue. AppSecD runs SAST, DAST, SCA, secret detection, IaC, container, Kubernetes and API security from one platform — wired into Git, gated at the pull request, and managed through a real vulnerability lifecycle.
- Vulnerability triage — deduplication, ageing, SLA, ownership and why a finding that is found, ignored and re-found is worse than one never found.
Individual posts are listed on this page. For reference material rather than writing,
see resources; for the platforms themselves, see
Maphra and
AppSecD.