HebeGuard maps the domains, cloud services and shadow IT you expose to the internet, then flags open services, leaked credentials and phishing sites in the order you should fix them.
Continuous attack surface monitoring, risk scoring and dark web monitoring, all working from the same live asset inventory.
Asset Discovery
External asset discovery for domains, subdomains, IPs, cloud assets and services, including shadow IT nobody signed off, kept in one live inventory.
Risk Scoring
Vulnerability prioritization by severity and exploitability, rolled into a 0–100 exposure score.
Dark Web Monitoring
Leaked credentials, compromised employee accounts, IOCs and phishing infrastructure linked to your domains.
Continuous Monitoring
New assets, configuration changes, expiring SSL certificates and look-alike domains are flagged the day they appear.
The platform
Tenviewsofyourexternalattacksurface
From asset inventory to dark web monitoring, each view below is one part of the same exposure report.
01Overview
One score, and the five that build it
The overview shows a single 0–100 exposure score, the five weighted sub-scores behind it, and signal cards for malware, phishing, reputation and brand-impersonation activity.
Unified 0–100 exposure score with a plain-language verdict
Exposure mix, severity split and a 12-month breach-probability estimate
globex-demo.test
Overview · Completed 31/08/2026 16:18:12
High
02Attack Surface
Every internet-facing asset, classified
HebeGuard discovers the subdomains, IPs, URLs and open ports anyone can reach from the public internet, including shadow IT nobody told security about. Each host shows live/dead status, TLS grade and the service banner an attacker would fingerprint first.
Subdomain, IP, URL and open-port discovery from passive + active sources
Live / dead status and per-host TLS grade (A+ → F)
Service and version fingerprints with an open-vs-filtered port map
Subdomain takeover detection for dangling DNS records
globex-demo.test
Attack Surface · Completed 31/08/2026 16:18:12
16 issues
03Recon & DNS
DNS, TLS and hosting, mapped to attack paths
WHOIS, DNS records, the full TLS certificate chain and hosting details, turned into the concrete routes an outsider could take from the open internet to a compromised host.
WHOIS, DNS records, nameservers and registration history
SSL/TLS certificate monitoring: full chain, grade, cipher flags and expiry countdown
Infrastructure correlated into ranked, outsider-reachable attack paths
globex-demo.test
Recon & DNS · Completed 31/08/2026 16:18:12
3 attack paths
04Vulnerabilities
Vulnerabilities ranked by real-world exploitability
Findings are ranked by CVSS severity, known active exploitation and public-exploit availability, then matched with CVE data for your detected stack. Secrets exposed in the same crawl, such as API keys, show up here too.
Findings scored by CVSS × exploitability, with confirmed / suspected status
CVE intelligence and known-exploited flags mapped to your tech stack
Exposed API keys and secrets surfaced from the same crawl
globex-demo.test
Vulnerabilities · Completed 31/08/2026 16:18:12
26 findings
05Security Posture
The controls that are missing or weak
Security headers, Content-Security-Policy, TLS configuration and DNSSEC, graded per host, so the gaps that make an exploit easier are as visible as the exploit itself.
Security headers and CSP graded per host, with fix guidance
TLS assessment flagging weak ciphers, old protocols and short expiry
DNSSEC and email-auth (SPF / DKIM / DMARC) verification
Third-party scripts and supply-chain risks found in your pages
globex-demo.test
Security Posture · Completed 31/08/2026 16:18:12
Grade D
06Threat Intelligence
IOCs and ATT&CK, correlated to you
Detections, threat-intel pulses, indicators of compromise and MITRE ATT&CK coverage, correlated across sources to show which campaigns and threat actors are touching your assets.
IOCs correlated across multiple threat-intelligence feeds
MITRE ATT&CK technique coverage grouped by tactic
Threat actors and campaigns linked back to your infrastructure
Brand protection and domain monitoring for typosquatting, homograph registrations, fake social channels and app-store clones. Each one comes with the DNS, logo-match and favicon-hash evidence behind it.
Typosquat and homograph domains with DNS + logo-match evidence
Fake social channels, scam content and app-store clones
Favicon-hash matching to catch pixel-copied phishing sites
globex-demo.test
Brand Monitoring · Completed 31/08/2026 16:18:12
12 signals
08Dark Web
Leaked data, matched back to the asset
Dark web monitoring for exposure you can’t see from inside your network: corporate mailboxes in breach data, infostealer logs, onion-forum posts and paste-site dumps, each tied to the account, host or dataset at risk.
Exposed mailboxes and infostealer credential logs
Onion-forum and paste-site mentions correlated to your assets
Breach-dump resale threads tracked with a new / resolved delta
globex-demo.test
Dark Web · Completed 31/08/2026 16:18:12
6 findings
09Phishing
Pages built to impersonate you
Phishing domain monitoring that combines live feeds, redirect-chain analysis, login-page inspection and signature rules to catch pages built to steal your users’ logins.
Live phishing-intelligence feeds
Redirect-chain analysis from the brand URL to the harvester
A single exposure score from five weighted layers, trended over time, with key findings, critical actions and positive signals written in plain language for leadership.
Weighted five-layer model with per-layer drill-down
Score trended over time with source-reliability weighting
Brand Reputation ReportImpersonating accounts, search-engine recon, public sentiment and certificate transparency.PDFXLS
Breached Data & Exposure ReportBreach intelligence, secrets leaked in code repositories and paste-site exposure.PDFXLS
Methodology
Continuousthreatexposuremanagement(CTEM)
HebeGuard runs all five CTEM stages on a daily cycle, so your exposure data is current between audits.
1ScopeAgree the domains, brands and business units that define your external perimeter.1 domain · 3 typosquats
2DiscoverEnumerate every asset, service and leaked secret an outsider can reach.12 subdomains · 17 URLs
3PrioritizeRank exposures by exploitability and business impact into one score.score 72
4ValidateConfirm the finding is real and reachable before it hits your queue.6 CVEs confirmed
5MobilizeRoute fixes to owners with context, SLAs and client-ready reporting.4 critical actions
↻ repeats every day
↻ repeats continuously
ASM engine · simulation
Watchadomainbecomeaprioritizedrisk
How the HebeGuard attack surface management engine turns one domain into a ranked list of risks. Step through it, click any node for detail, or let it play.
Start from what you already own
4seed domains
The domains and brands you already know about.
// simulation · illustrative dataAcme Corp · acme.example · live · re-runs every 24h
Dark Web Monitoring
Findleakedcredentialsbeforesomeoneusesthem
HebeGuard collects breach dumps, infostealer logs, pastes and onion-site mentions, keeps the records that name your domains or staff, checks they are real, and links each one to the asset it exposes.
Pipeline · runs continuously
01
Collect
New breach dumps, infostealer logs, paste drops and onion-site mentions are pulled in continuously from dark web, paste-site, code-repository and breach sources.
02
Match
Filter that firehose down to only the records that name your domains, corporate mailboxes or brand.
domain · email · brand
03
Verify & score
De-duplicate, confirm each record is real and current, then grade every hit HIGH / MEDIUM / LOW.
confidence graded
04
Correlate
Link each leak to the host, employee account or API key it exposes, and to any attack path it opens.
mapped to asset
05
Deliver & fix
Results appear in the Dark Web Monitoring tab the same day, with evidence and a fix: rotate, reset or take down.
same-day · with remediation
Output · lands in the Dark Web Monitoring tab
DASHBOARD / DARK WEB MONITORINGLIVE
G
globex-demo.test
Dark Web Monitoring · 31/08/2026 16:18
6 FINDINGS
2
Exposed emails & infostealer
CREDENTIAL EXPOSURE
3
Dark web intelligence
ONION / LEAK MENTIONS
1
Paste site monitoring
PASTE LEAK
// Leaked records · matched to globex-demo.test
admin@globex-demo.testbreach-dump-2024 · HIGH
svc-deploy@globex-demo.testRedLine stealer log · HIGH
billing@globex-demo.testcombolist · 2024-08 · MEDIUM
// Dark web intelligence · onion & leak mentions
"globex db dump for sale"Exploit forum
brand mention on leak siteLeak-site feed
API token in pastePaste site
correlated → 4 assets · 2 employees · 1 API key
Modules
Sixmodules,oneASMplatform
Every module reads from the same asset inventory, so a leaked password, an open port and a look-alike domain all show up against the same host.
Attack Surface
12 subdomains
Live inventory of every internet-facing asset, subdomain and service.
api.globex-demo.test Alive · 443TLS A+
staging.globex-demo.test Alive · 6379Takeover
app.globex-demo.test Alive · 443TLS F
Vulnerabilities
26 open
Critical/High/Medium/Low findings with CVSS, known-exploited and exploit-available flags.
C 5H 8M 9L 4
SQL Injection · /api/v1/users9.8
Dark Web Monitoring
6 findings
Leaked credentials, brand mentions and compromised-employee alerts.
2 leaked records · breach-dump-20242h
50 emails on data broker · data broker9h
Phishing & Malware
5 lookalikes
Malicious infrastructure and look-alike domains targeting your brand.
acme-demo-secure.com · 100% matchTake-down
acme-demos.com · 96% matchWatch
Risk Engine
score 72
One 0–100 exposure score, mapped to ISO 27001 / PCI-DSS.
72/100
▲ worsened +6
ISO · A.8PCI · 11
Client Portal
multi-tenant
Per-client scoped views with tracked remediation tasks and SLA alerts.
globex-demo.test
Patch SQL injection · /api/v1/usersSLA 2d
Require auth on Redis · rotate credsSLA 4h
How it works
Liveinminutes
Three steps from a domain name to a prioritized, client-ready picture of your risk.
1
Connect
Enter a domain. No agent, no install, no firewall changes.
globex-demo.testScan ▸
no agent · no install · no firewall change
2
Analyze
Automated discovery maps your assets and services, then threat intelligence enriches each result.
Subdomain discovery
Service & CVE scan
Threat intel enrichment
3
Act
Prioritized fixes, alerts and shareable client-ready reports.
1 · Patch SQL injection · /api/v1/usersCritical
2 · Require auth on Redis · rotate credsHigh
Export client-ready report ▸
Why HebeGuard
Builttoclosethevisibilitygap
An attacker enumerates your whole external surface. A typical agent-plus-scanner stack sees a fraction of it.
Full bar = attacker's reach you see today what it misses
External assets & subdomains62%
Exposed services & ports54%
Validated vulnerabilities38%
Leaked credentials14%
Look-alike & phishing domains21%
Dark-web mentions9%
Average coverage of a typical stack33%· illustrative figures
No agentOne risk scoreMulti-tenant portalControl mappingDeploy your wayTenant-isolated
24/7
Monitoring
0–100
Risk score
0
Agents
Daily
Asset discovery
Who it's for
Securityteams,MSSPsandregulatedindustries
For in-house security teams, and for the MSSPs and vCISOs who manage external risk across many clients.
MSSPs & vCISOs
Run managed exposure programs across many clients with one platform, scoped reporting and branded client portals.
Multi-tenant ✓
Enterprises
Track the external footprint of every subsidiary and brand, with one risk score and continuous monitoring.
Full coverage ✓
Finance & Healthcare
Findings mapped to ISO 27001 and PCI-DSS controls, in reports you can hand straight to an auditor.
Compliance-aligned ✓
SaaS Companies
New subdomains and cloud services are picked up as you ship them, along with look-alike domains and leaked credentials.
Scales with you ✓
ISO 27001-alignedPCI-DSS-alignedTenant-isolated dataNo-agent architecture
FAQ
Attacksurfacemanagementquestions
What is external attack surface management (EASM)?
External attack surface management, often shortened to EASM or ASM, is the ongoing work of finding everything your organization exposes to the internet (domains, subdomains, IP addresses, cloud services, open ports and leaked credentials) and fixing the riskiest items first. HebeGuard automates the discovery and the ranking, and repeats both every day.
What does an attack surface management tool like HebeGuard monitor?
Subdomains, IP addresses, open ports and running services; SSL/TLS certificates and their expiry dates; DNS, SPF and DMARC records; security headers; subdomains at risk of takeover; exploitable vulnerabilities; typosquatting and look-alike domains; phishing pages; and leaked credentials on the dark web and paste sites.
How is attack surface management different from vulnerability management or penetration testing?
Vulnerability scanners and penetration tests (VAPT) check the targets you hand them, usually once a quarter or once a year. Attack surface management starts from your domain name, finds assets you may not know about, and keeps checking them daily. Many teams use both: HebeGuard between tests, and VAPT for depth.
What is the difference between EASM and CTEM?
EASM (external attack surface management) is the discovery side: finding everything you expose to the internet. CTEM (continuous threat exposure management) is the wider program that also prioritizes, validates and fixes those exposures in a repeating cycle. HebeGuard does both, discovering your external assets and running the five CTEM stages on them every day.
Does HebeGuard find shadow IT and third-party risks?
Yes. Discovery works outward from your domain through certificate transparency logs, passive DNS and subdomain enumeration, so it finds sites and services nobody registered with IT. It also flags the third-party scripts and services your pages load, which are a common source of supply-chain risk.
How does HebeGuard detect typosquatting and phishing domains?
It generates look-alike versions of your domain, including typos and homograph (Unicode) variants, and checks DNS to see which are registered and live. Live domains are compared against your logo and favicon, and phishing-intelligence feeds flag pages already serving phishing. It also watches certificate transparency logs, social media and app stores for accounts impersonating your brand. Together with dark web monitoring, this covers most of what digital risk protection (DRP) tools do.
Can small businesses use HebeGuard for dark web monitoring?
Yes. All HebeGuard needs is your domain, so there is no agent to deploy and no infrastructure to run. It checks breach data, infostealer logs, paste sites and dark web sources for your domains and staff email addresses, and each alert names the exposed account and the fix, such as resetting a password.
How can we reduce our external attack surface?
Start with an accurate inventory, because you can’t secure assets you don’t know about. Then remove what you no longer need: old subdomains, test servers, dangling DNS records and unused open ports. Patch the exposed services attackers can exploit first, fix weak TLS and missing security headers, reset leaked credentials, and keep watching for new assets. HebeGuard handles the discovery and daily monitoring, and tells you which of these to do first.
Do we need to install an agent?
No. HebeGuard works entirely from outside your network. You give us a domain and discovery starts. Nothing gets installed and no firewall rules change.
How is the 0–100 risk score calculated?
Each finding is weighted by severity, exploitability (CVSS score, known active exploitation and public exploit availability) and how exposed the affected asset is. Those roll up into one score that trends over time and maps to ISO 27001 and PCI-DSS control families.
Can MSSPs and vCISOs manage several clients from one account?
Yes. The Client Portal is multi-tenant. Each client is a separate tenant with its own data, users and branded reports, and you manage all of them from one console.
Where does HebeGuard look for leaked data?
Dark web and Tor sites, ransomware leak sites, paste sites, public code repositories and known breach data. Each record is matched against your domains and employee emails, so an alert names the specific account or host at risk.
How is our data isolated?
Tenants are logically isolated, so one client can’t see another’s assets, findings or reports. You can run HebeGuard on your own server or use our hosted service.
How quickly do we see results?
Initial discovery and a first exposure score typically arrive within the first scan cycle. After that, monitoring is continuous and new exposures are flagged daily.
Can companies in Malaysia, Indonesia and other countries use HebeGuard?
Yes. Scans run from the internet against your public-facing assets, so HebeGuard works the same for a company in Kuala Lumpur, Penang, Jakarta, Surabaya, Chennai or London. HebeSec Technologies has offices in Karaikudi, Tamil Nadu, India (+91 95660 22629) and Rawang, Selangor, Malaysia (+60 12-675 7536).
How does HebeGuard help with data breach rules in Malaysia and Indonesia?
Malaysia’s amended Personal Data Protection Act (PDPA) and Indonesia’s Personal Data Protection Law (UU PDP, Law No. 27 of 2022) both require companies to report personal data breaches quickly. HebeGuard helps you find out early: it alerts you when staff or customer credentials appear in breach data, infostealer logs or paste sites, and shows which account or system is exposed. It does not replace legal advice on what to report.
We reply within one business day
See what an attacker can see of your company.
Send us your primary domain. We'll map your external attack surface and walk you through what we find.