Attack surface · External exposure

What the attacker sees
of you, before he does.

Cartographie continue de votre exposition sur Internet : sous-domaines oubliés, services ouverts, DNS de messagerie incomplet, identifiants volés par les infostealers — et, pour ceux-là, la coupure du compte dans votre annuaire depuis le portail.

Subdomain discoveryExposed servicesSPF · DKIM · DMARCCredentials stolen by infostealerAD / LDAP blocking
0
agent to install
External
the attacker's view
Continuous
retrieved at each scan

An attacker starts with what is public: a forgotten certificate, a staging sub-domain, an admin console left open, a corporate password sold on the dark web. The module does this reconnaissance for you, continuously, and hands you the same list — paired with the action that closes each finding.

How it works

From threat to evidence, in real time.

The module captures the signal, SYLink AI correlates it and decides — you keep control.

Internet
What is public
Attack surface
Discovery + exposure
SYLink AI
Prioritise what is genuinely risky
Door closed
Before exploitation
Capabilities

The technology, in detail.

What the module actually does — functions, not promises.

Discover what really exists

  • Subdomains via certificate logs (crt.sh)
  • Close domain name variants and TLDs
  • DNS validation of each name found
  • Domain registrant (RDAP / WHOIS)
  • Retrieved at each scan: nothing expires

Services exposed on the Internet

  • Open ports seen from outside
  • Identified services (Shodan, LeakIX)
  • Administration ports flagged as critical
  • What has opened since the last scan

Domain hygiene

  • SPF, DKIM and DMARC checked per domain
  • Identified impersonatable domains
  • TLS certificates and expiry dates

Credentials stolen by infostealers

  • Corporate identifiers found in password thief dumps
  • Mapping to your real directory accounts
  • Company domains monitored, not just known addresses
  • Tracking: detected, resolved, pending

Disable the account, without opening the directory

  • Revoking access for a credential found in a leak
  • Account disablement, expiry or forced password reset
  • Executed in local LDAP by the AD agent, which polls commands over outbound HTTPS — no inbound traffic to the directory
  • Identity and cloud messaging via connector: Entra ID / Microsoft 365, Okta, Keycloak, JumpCloud
  • Protected accounts refused (krbtgt, Administrator), with rollback on every write
Use cases

What is it actually for?

Close a console left open

An admin port exposed by mistake after a migration: detected from the outside, with the remediation step attached.

Find forgotten subdomains

Certificates leak staging and pre-production names that nobody maintains — and that the attacker finds straight away.

Prevent impersonation of your mailbox

Without DMARC, anyone writes to your clients in your name. The module shows which domains are spoofable, and which are covered.

Close a stolen account before it is used

A staff member's password appears in an infostealer dump. The account is matched to your directory and disabled from the portal — the order is executed via LDAP locally by the agent, and remains reversible.

The method, in four steps
From raw signal to defensible evidence.
Detect
Understand
Decide
Prove
01The module captures the raw signal — traffic, behaviour or indicator.signal captured
Specifications
PerimeterYour domains and their sub-domains
Discoverycrt.sh, TLD variants, DNS, RDAP/WHOIS
ExposureOpen ports, Shodan, LeakIX
EmailSPF, DKIM, DMARC
LeaksCredentials stolen by infostealer
RemediationAD/LDAP natively — cloud identity and messaging via connector
Garde-fousAUTO protection, authorised role, armed agent — action cancellable
InstallationNone for external visibility; AD agent for remediation
Natively integrated with
SYLink AI — exposure prioritisation
SYLink WAF — protection of discovered domains
Automated pentest — offensive verification
AD agents — accounts affected by a leak
Compliance module — NIS2 exposure evidence
Sovereign

Driven by SYLink AI, hosted 100% in France (HDS v2), with no Cloud Act exposure. Every decision is logged and defensible under NIS2 and DORA.

Live in under 48 hours

Ready to see what is really
happening on your network?

First trial free, no credit card, no commitment. On your existing infrastructure.

Cookie settings

We use cookies to improve your experience on our site. By continuing to browse, you accept our privacy policy and our use of cookies under the GDPR.