QS-WAN · Digital Exposure

External attack surface management, run on a schedule

External attack surface management in QS-WAN means one monitored profile and a scan pointed at it. You list the company name, the primary domain, the extra domains, the public IPs and the email addresses worth watching. Findings come back in six categories, at five severities, with a risk score out of 100 for each target.

What it is

What attack surface management covers here

The profile is the scope. Company name, primary domain, additional domains, public IPs, email addresses. That list is what gets scanned, so it is a thing you maintain, not a thing you file.

Three depths

The depth is the trade. The shallowest is a quick pass and the deepest is a long one, and all three read the same profile.

Quick

Certificates, DNS and email authentication. The shallowest pass, and the fastest one.

Standard

Everything in Quick, plus vulnerabilities, exposed services and reputation.

Deep

Everything in Standard, plus data leaks, credentials and ransomware. It is the one that takes longest.

Findings land in six categories: Domains and Certificates, Vulnerabilities and Infrastructure, Data Leaks and Credentials, Reputation and Phishing, Malware and IOCs, and Ransomware. Each finding carries a severity, and each target carries a risk score out of 100.

Severity and score answer different questions. Severity is about one finding. The score is about one target, so a host with four moderate findings can outrank a host with one high one. Inside the fleet, that job belongs to risk scoring.

The mechanism

The same profile, and a depth that decides how far the pass goes

Press a depth and watch what the pass actually runs. The profile does not move, no port is opened, and nothing is installed on anything. What changes is how far the checks go.

The profile The depth What the pass runs Company profile Defines what gets scanned on every run Company namePrimary domainAdditional domainsPublic IPsEmail addresses on a clock QuickCertificates, DNS andemail authenticationStandardEverything in Quick, plusvulnerabilities, exposedservices and reputationDeepEverything in Standard, plusdata leaks, credentialsand ransomware In every passCertificatesrunsnot in this passDNSrunsnot in this passAdded by StandardVulnerabilitiesrunsnot in this passExposed servicesrunsnot in this passReputationrunsnot in this passAdded by DeepData leaksrunsnot in this passCredentialsrunsnot in this passRansomwarerunsnot in this pass What comes back Findings, grouped by target six categories · five severities · a risk score out of 100 per target Group by target or by severity, and compare with the scan before A schedule runs it from every hour to once a day. Nothing is installed on anything.

The same profile, three depths. Press one and watch how far the pass goes, and what it leaves for the next depth.

Quick. Certificates, DNS and email authentication, on every target in the profile. The six deeper controls belong to the other two depths.

The diagram reads left to right. On the left is the company profile, which defines what gets scanned on every run: company name, primary domain, additional domains, public IPs and email addresses. A channel carries the run out on a clock rather than on somebody remembering. In the middle are the three depths, with the description each one carries in the console: Quick runs certificates, DNS and email authentication; Standard adds vulnerabilities, exposed services and reputation; Deep adds data leaks, credentials and ransomware. On the right are the nine controls those descriptions name, in three groups, and each group is either running in this pass or waiting for a deeper one. Along the bottom, what comes back is a set of findings grouped by target, in six categories, at five severities, with a risk score out of 100 per target, and each scan can be compared with the one before it. The three buttons change the depth and nothing else: the profile does not move, no port is opened and nothing is installed on any machine.

The depth never changes the scope. All three passes read the same profile, so a Quick run and a Deep run disagree about how far they looked, never about what they were looking at. That is the part worth knowing before you pick one: a shallow pass is not a narrower list, it is a shorter question asked of the same list.

Why this exists

Four things that stay true until something looks

Somebody has to remember the certificate

Certificate expiry on the public site is a check somebody does by hand, when they remember. The calendar reminder gets moved to next week, and next week it gets moved again.

The DNS moved when the mail provider did

The record that changed on the Tuesday is the one nobody looked at until the week after. Email authentication is the part that quietly stops matching.

Leak news, then twenty minutes of guessing

You read it on a phone, then spend twenty minutes working out whether any of those addresses were yours, with no list to check them against.

“When did we last look” gets a shrug

There is no timestamp, because nothing wrote one. The honest answer is that somebody looked at some of it, at some point, and nobody wrote it down.

What you gain

One finding, two people reading it

If you run the network

You stop being the reminder system

Certificate expiry on the public site, DNS that changed when the mail provider did, an address that surfaced in a credential dump: every one of those is a check you did by hand when you remembered, or heard about from somebody else.

The scan does them on a clock instead, against the same list every time.

If you sign for it

An answer to what you expose, and to how you know

The assessor asks what the company exposes and how you know it.

The answer is a profile, the scans run against it, and a score out of 100 per target next to the severities behind it. That trail becomes audit evidence without anybody assembling it.

How it works

How a finding gets made

You write the profile once

Name, domains, public IPs, addresses. It is the only part that needs a person, and you are the person who knows which domains still matter.

The schedule runs it without you

Automatic scans go from every hour to once a day, with a depth of their own, set apart from the depth you pick when you run one by hand. The screen names the time of the next run.

The findings arrive grouped

Group by target or by severity, filter, acknowledge what you have seen. Each scan is compared with the one before it, so “what changed since Tuesday” is a view rather than a memory.

Leak data

Dark web monitoring, and what that phrase covers here

The phrase gets used for several different things, so here is the one it means on this page.

Checked

The addresses you listed, against public leak and credential databases

The email addresses in the profile are checked against public data-leak and credential databases, and matches show up under Data Leaks and Credentials.

Deep is the depth that runs it. Quick and Standard do not, which is the whole reason the depth is a choice and not a setting somebody forgot.

Boundary

Public leak data, not a crawler inside closed forums

The honest boundary: that is public leak and credential data, matched against addresses you listed. If a vendor is selling you a crawler inside closed forums, this is not that.

When something has to come off somebody else’s server, the removal request goes out with the contact you set, your data protection officer or whoever holds that job, as the reply address. The reply reaches a named person, not a shared mailbox.

Where this earns its place

Four mornings this changes

The certificate nobody owned

A calendar reminder moved to next week stops being the control. The shallowest depth carries certificates, DNS and email authentication, so the expiry is named by the pass rather than by whoever happened to look.

What changed since Tuesday

The scans stay in history and each one is compared with the one before it. Group by target or by severity, acknowledge what you have seen, and the question becomes a view instead of a memory.

The assessor asks how you know

There is no folder to assemble the night before. You open the scan history and the profile it ran against, and the answer is already written, because it was written while you were doing something else.

Something has to come off somebody else’s server

The removal request goes out with the contact you set, your data protection officer or whoever holds that job, as the reply address. The reply reaches a named person.

Works better together

Where this sits in the rest of the console

These are not a related links box. Each one owns a piece of the same question, and this page only answers the part of it that faces outwards.

01

This page scores what faces the internet, one target at a time. Inside the fleet, the same job belongs next door.

02

A finding here is a sentence. A rule there is scoped at gateway, user or device level and signed in the console before it reaches anything.

03

The scan reads certificates from the outside, the way anyone else on the internet does. The ones you issue yourself are handled here.

04

The outside view has a limit at the edge of what is public. The inside view starts there.

It also shows up twice in the main console: the Security Dashboard carries a card with the perimeter checks, and Threat Floor shows open exposure findings with how many sources each one came from. The console holds both, and every feature is listed in one place.

What this does not do

The limits, because they are what make the rest believable

Nobody here watches it for you

There is no QuantumNova analyst reading your findings at two in the morning. You run the product, and the scan is all it does on its own.

It does not scan what you never listed

The profile is the scope. There is no discovery of assets you forgot, so the list deserves five minutes whenever something new goes live.

It does not take anything down

The removal request goes to the third party holding the data. Whether they act on it is theirs, and the product does not pretend otherwise.

Acknowledged means seen, not fixed

It moves a finding out of your way, not off the internet, and it comes back if the next scan still finds it.

Trends is the sector, not you

That tab pulls the industry picture from outside sources, including the public catalogue of actively exploited vulnerabilities. It is context for prioritising, never a statement about your own estate.

It does not fix what it finds

It names, scores and tracks. Enforcement is security policy management, certificates you issue yourself are certificate lifecycle management, and the inside view is network security monitoring.

Questions people ask

The ones that come up first

What is external attack surface management?

External attack surface management is tracking what your organisation exposes to the internet, from the outside in. Here it is a monitored profile of domains, public IPs and email addresses, scanned at one of three depths, with findings in six categories, five severities and a score out of 100 per target.

How long does a scan take?

Quick is a fast pass, Standard adds the vulnerability and reputation work, and Deep adds the leak and credential checks, which is why it is the longest of the three.

What counts as dark web monitoring here?

The addresses in your profile are checked against public data-leak and credential databases, and matches arrive under Data Leaks and Credentials. It is not a crawler inside closed forums.

Does it find assets I forgot about?

Only if they are in the profile. Scope is the list you maintain, and the limit is deliberate: a scan that wandered is one you cannot put in front of an auditor.

Bring us your domain. We will point a scan at it while you watch.

An engineer, a console shaped like yours, and as long as you need. You write the profile, pick a depth, and watch the findings come back grouped by target with a score on each one. It is free and there is nothing to sign.

Scroll to Top