See your organisation the way an attacker sees it.

Maphra — Autonomous external attack surface management

See your organisation the way an attacker sees it.

Maphra discovers everything your organisation exposes to the internet, decides what actually matters, and proves exploitability — continuously, without an agent and without a credential.

Maphra is an autonomous External Attack Surface Management platform. It starts from nothing more than a domain name and works outward the way an attacker would: enumerating subdomains, resolving infrastructure, fingerprinting live services, and attributing each discovered asset back to the organisation that owns it. Discovered surface is then classified, analysed and prioritised, so a security team sees the handful of exposures that are genuinely reachable rather than an undifferentiated asset inventory. Maphra also watches the parts of the attack surface that sit outside the perimeter entirely — leaked credentials in breach corpora, look-alike domains, impersonating applications and brand abuse — because those are attack paths that no internal scanner can see. It runs continuously rather than as a quarterly exercise, and every finding carries the evidence that produced it.

From the outside in: What can an attacker reach without any credentials? Category: External Attack Surface Management (EASM). The platform runs at https://maphra.dedsecops.com.

What Maphra covers

  • External Attack Surface Management — Continuous discovery and attribution of internet-facing assets — subdomains, hosts, services, certificates, cloud endpoints and the shadow IT nobody registered.
  • Threat Intelligence Hub — Advisories, CVE feeds and exploit intelligence correlated against the assets you actually operate, so a CVE only raises an alarm when it touches your surface.
  • Vulnerability Management — Findings deduplicated across scans, tracked through new / reopened / fixed, with ownership, ageing and SLA rather than a re-issued PDF.
  • Breach & Brand Monitoring — Credential exposure in breach corpora, dark-web mentions, look-alike domains and impersonating apps — the attack paths that never touch your network.
  • Comprehensive Security Analysis — TLS and certificate posture, security headers, DNS hygiene, email authentication and misconfiguration checks across every discovered asset.

The chain, step by step

  1. Reconnaissance

    What happens: An attacker starts with your domain and no access. They enumerate subdomains, scrape certificate transparency logs and map your DNS to find everything you own — including the assets you forgot.

    How Maphra answers it: Maphra runs the same enumeration continuously and attributes each asset back to your organisation, so the forgotten staging host shows up on your inventory before it shows up on theirs. (Asset discovery & attribution)

  2. Finding the way in

    What happens: They fingerprint live services looking for an unpatched version, an exposed admin panel, a stale TLS configuration or a subdomain pointing at a deprovisioned cloud bucket.

    How Maphra answers it: Every discovered asset is fingerprinted and checked for exposure: service versions, certificate and TLS posture, security headers, DNS hygiene and takeover-prone records. (Comprehensive security analysis)

  3. Credentials without hacking

    What happens: Often there is no exploit at all. A staff password from an unrelated breach still works, or a look-alike domain harvests one from a customer.

    How Maphra answers it: Breach corpora are monitored for your domains, and brand monitoring watches for look-alike domains and impersonating applications targeting your users. (Breach & brand monitoring)

  4. Proving it is real

    What happens: A scanner listing a theoretical CVE tells you nothing. The attacker only cares about what actually works against your specific deployment.

    How Maphra answers it: Active checks validate exploitability against the live asset within an explicit scope boundary, so a finding arrives with evidence rather than a severity guess. (Autonomous validation)

  5. Deciding what to fix first

    What happens: A team drowning in ten thousand findings fixes the wrong ones, and the reachable critical stays open.

    How Maphra answers it: Findings are deduplicated, correlated with exploit intelligence and ranked by real reachability, then tracked to closure with ownership and SLA. (Vulnerability management)

Inside Maphra

  • Discovery that keeps going — Attack surface is not a document you produce once a year. Maphra re-runs discovery on a schedule, diffs the result against the last known surface, and tells you what appeared, what changed and what quietly disappeared. Subdomain and host enumeration · Service and technology fingerprinting · Certificate transparency monitoring · Change detection between runs
  • Exposure analysis with the evidence attached — Each asset is examined for the things that actually get organisations breached — expired or weak TLS, missing security headers, permissive DNS, exposed panels — and each finding carries the raw response that produced it. TLS and certificate posture · Security header analysis · DNS and email authentication · Evidence retained per finding
  • Breach and dark-web exposure — Credentials leak in breaches that have nothing to do with you, and get reused against you. Maphra tracks your domains across breach corpora and surfaces the accounts that need a reset. Credential exposure by domain · Dark and deep web mentions · Alerting on new exposure
  • Brand and impersonation monitoring — Look-alike domains and impersonating applications are an attack path against your customers that never touches your infrastructure. Maphra watches for both. Look-alike domain detection · Impersonating application discovery · Continuous brand surveillance
  • Risk scoring you can defend — A score is only useful if you can explain it to an auditor. Risk is derived from the observed exposure and its reachability, and the inputs stay visible. Reachability-weighted scoring · Trend over time · Per-asset breakdown
  • Reporting for the people who ask — Board, auditor and engineer need different things from the same data. Reports are generated from the same evidence projection rather than re-keyed. Scheduled and on-demand reports · Evidence-backed findings · Multiple audiences from one dataset

Maphra at a glance

Category
External Attack Surface Management
Deployment
Agentless — starts from a domain name
Cadence
Continuous, scheduled and on-demand
Access
No credentials into your estate required

Maphra questions

What does Maphra need to get started?
A domain name. Maphra works from the outside in, so it needs no agent, no credential into your estate and no network access. Discovery begins from public data the same way an attacker would begin.
How is Maphra different from a vulnerability scanner?
A scanner tests a list of assets you give it. Maphra finds the assets first — including the ones nobody remembered — attributes them to your organisation, then analyses them. The discovery step is the product.
Does Maphra attack our systems?
Active validation runs only inside an explicit scope boundary you define, and the scope gate prevents active checks from reaching third-party hosts that merely appear in your surface.
How does Maphra handle findings that are not real?
Every finding carries the evidence that produced it, and findings are deduplicated across scans and tracked through new, reopened and fixed states rather than re-reported each run.

Log in to Maphra · Full Maphra detail