Automated asset discovery
Subdomains, IP ranges, cloud endpoints, CDN-fronted services, API gateways, mail infrastructure and acquired domains. Add an acquisition's seed domains and monitoring extends automatically.
Kervo AI starts from your primary domains and builds the complete external picture, including the assets nobody remembers, without an asset list.
Every organisation's external attack surface is larger than its inventory says. A campaign page outlives the campaign by two years. A demo staging environment never gets torn down. An acquisition brings four hundred hosts nobody has audited.
None are on the asset list, so none get scanned or monitored. Enumerating your domains is the first thing an attacker does, and they probably have a better inventory of your footprint than you do.
You provide your primary domains. Kervo AI builds the rest through DNS enumeration, certificate transparency logs, WHOIS and registrar data, ASN and IP range analysis, passive DNS and public cloud metadata. Each asset is fingerprinted: software and version, known CVEs, CDN or WAF, certificate and expiry.
Then it keeps watching. A new subdomain, a newly opened port or an asset flipping from private to public is flagged within the hour. Most organisations find 20 to 40% more assets than they had on record.
Subdomains, IP ranges, cloud endpoints, CDN-fronted services, API gateways, mail infrastructure and acquired domains. Add an acquisition's seed domains and monitoring extends automatically.
Exposed staging environments, internal tools that became internet-facing, forgotten microsites, dangling DNS records that can be claimed by someone else.
Continuous port scanning across discovered assets, with services identified, versions fingerprinted and known CVEs matched.
Certificate inventory, expiry alerting before customers see errors, weak cipher detection, and transparency monitoring that catches certificates issued for your domains that you didn't request.
A new subdomain, a port opening, an asset going public, authentication removed from an endpoint. Detected and alerted as it happens.
<!-- ### Acquired and subsidiary coverage
Multi-entity support so a group can monitor subsidiaries separately while seeing consolidated risk at the top. -->
Discovery is primarily passive, which is why first results arrive in hours. Active probing is lightweight, rate-limited and non-intrusive: enough to fingerprint services without affecting availability. Nothing attempts exploitation.
Discovered assets are reconciled against your known inventory, so the output distinguishes what you knew, what you didn't, and what needs a human to confirm ownership.
A standalone discovery tool tells you a subdomain runs an outdated service. Kervo AI adds that it authenticates against your identity provider, that a credential for a user with access appeared in a breach dump last month, and that the account reaches production data. One attack path, visible only because external, identity, dark web and cloud data share one model.
Continuous, outside-in discovery and monitoring of an organisation's internet-facing assets, the same view an attacker has, including assets missing from the internal inventory.
That is the assumption. Kervo AI starts from your primary domains and builds the inventory itself.
A pentest is a point-in-time assessment by people. EASM is continuous, automated discovery. They complement each other.
No. Discovery is largely passive, active probing is limited to lightweight fingerprinting, and nothing attempts exploitation.
Yes. Assets can be confirmed, disputed, marked out of scope or assigned to a business unit, and that flows into every report.
We run discovery against your real domains during the demo. Most teams see something they didn't expect.