See your perimeter the way attackers do
Enter a domain. We map every subdomain, IP, open port, product, and known vulnerability — in minutes. No signup. No agent. No surprises.
Scan data is encrypted in transit, never shared with third parties.
External Attack Surface Analyzer is a free reconnaissance tool by SOCRadar that maps an organization's internet-exposed infrastructure from an attacker's perspective. Security engineers enter a domain name to trigger automated enumeration of associated subdomains, related domains, open network ports, running web technologies and frameworks, and discovered CVEs across the entire external perimeter. Findings surface forgotten development environments, shadow IT provisioned outside central IT oversight, expired SSL certificates, and services running with misconfigured defaults. Unlike commercial EASM platforms requiring lengthy onboarding, this tool delivers an initial attack surface snapshot in minutes — no account registration, sensor installation, or API key required. Ideal for pre-engagement assessment, continuous monitoring gap analysis, and rapid situational awareness during active incidents.
Subdomain Discovery
Enumerate forgotten subdomains, dev environments, and shadow IT exposed to the public internet.
Technology Fingerprinting
Identify web servers, frameworks, CDNs, and version strings across every reachable host.
Open Port Mapping
Surface every open TCP port and running service across IPs and subdomains.
Vulnerability Matching
Cross-reference detected products + versions against known CVEs and exploit availability.
F.A.Q.
Find answers to common questions about external attack surface management
See Your Attack Surface Through the Eyes of Threat Actors
Continuous discovery, monitoring, and prioritized risk scoring across every subdomain, IP, port, and product surface. Free Edition gives you the full report and ongoing alerts.