Kervo AI
Platform/Know/External Attack Surface
Kervo AI · Know

Find everything you have facing the internet.

Kervo AI starts from your primary domains and builds the complete external picture, including the assets nobody remembers, without an asset list.

platform.kervo.ai / know / external-surface
Know / External surfaceliveacme-prodDISCOVERY FROM SEED DOMAINSacme.comacme.comseedwww.acme.comapi.acme.comstaging-old.acme.comshadow ITvpn-legacy.acme.com3 open portsmail.acme.comdev.acme-labs.ioacquiredcdn.acme.comportal.acme.comcert · 6d2,411assets+38new · 7d6exposedEXPOSED SERVICES4 openvpn-legacy:1194 · OpenVPN 2.4bastion-02:3389 · RDPsearch-01:9200 · Elasticsearch · no authjump-03:22 · SSH · password authCERTIFICATESexpiryportal.acme.com6dapi.acme.com41dwww.acme.com210dcdn.acme.com300dAlert raised at 14 days · portal.acme.com
Starts from seed domains
no inventory required
Continuous
new exposure flagged within the hour
Shadow IT surfaced
the assets that aren't on anyone's list
[ The problem ]

The problem with knowing your own footprint

Every organisation's external attack surface is larger than its inventory says. A campaign page outlives the campaign by two years. A demo staging environment never gets torn down. An acquisition brings four hundred hosts nobody has audited.

None are on the asset list, so none get scanned or monitored. Enumerating your domains is the first thing an attacker does, and they probably have a better inventory of your footprint than you do.

[ What Kervo AI does ]

What Kervo AI does

You provide your primary domains. Kervo AI builds the rest through DNS enumeration, certificate transparency logs, WHOIS and registrar data, ASN and IP range analysis, passive DNS and public cloud metadata. Each asset is fingerprinted: software and version, known CVEs, CDN or WAF, certificate and expiry.

Then it keeps watching. A new subdomain, a newly opened port or an asset flipping from private to public is flagged within the hour. Most organisations find 20 to 40% more assets than they had on record.

[ Capabilities ]5 capabilities
01

Automated asset discovery

Subdomains, IP ranges, cloud endpoints, CDN-fronted services, API gateways, mail infrastructure and acquired domains. Add an acquisition's seed domains and monitoring extends automatically.

02

Shadow IT detection

Exposed staging environments, internal tools that became internet-facing, forgotten microsites, dangling DNS records that can be claimed by someone else.

03

Service and port exposure

Continuous port scanning across discovered assets, with services identified, versions fingerprinted and known CVEs matched.

04

Certificate monitoring

Certificate inventory, expiry alerting before customers see errors, weak cipher detection, and transparency monitoring that catches certificates issued for your domains that you didn't request.

05

Exposure change alerting

A new subdomain, a port opening, an asset going public, authentication removed from an endpoint. Detected and alerted as it happens.

Read more

<!-- ### Acquired and subsidiary coverage

Multi-entity support so a group can monitor subsidiaries separately while seeing consolidated risk at the top. -->

[ How it works ]

How it works

Discovery is primarily passive, which is why first results arrive in hours. Active probing is lightweight, rate-limited and non-intrusive: enough to fingerprint services without affecting availability. Nothing attempts exploitation.

Discovered assets are reconciled against your known inventory, so the output distinguishes what you knew, what you didn't, and what needs a human to confirm ownership.

[ One data model ]

Why external discovery is more useful inside a platform

A standalone discovery tool tells you a subdomain runs an outdated service. Kervo AI adds that it authenticates against your identity provider, that a credential for a user with access appeared in a breach dump last month, and that the account reaches production data. One attack path, visible only because external, identity, dark web and cloud data share one model.

See how this fits into Know
[ FAQ ]External Attack Surface
What is external attack surface management?

Continuous, outside-in discovery and monitoring of an organisation's internet-facing assets, the same view an attacker has, including assets missing from the internal inventory.

What if we don't have an asset list?

That is the assumption. Kervo AI starts from your primary domains and builds the inventory itself.

How is this different from a penetration test?

A pentest is a point-in-time assessment by people. EASM is continuous, automated discovery. They complement each other.

Is scanning intrusive?

No. Discovery is largely passive, active probing is limited to lightweight fingerprinting, and nothing attempts exploitation.

Can we manage what's in scope?

Yes. Assets can be confirmed, disputed, marked out of scope or assigned to a business unit, and that flows into every report.

[ More in Know ]
Get started

Find out what's actually exposed.

We run discovery against your real domains during the demo. Most teams see something they didn't expect.