External attack surface management
Know what is visible around your verified domains.
Bring observed hostnames, network services, web responses and security findings into one place. Review what changed, what needs attention and how each result was found.
Domain verification and plan eligibility determine access. Active checks require separate target authorization.
The problem
External assets change faster than an inventory spreadsheet.
A newly observed host, an exposed service or a changed web response can matter only when your team knows which domain it belongs to and how reliable the observation is. LeakData keeps that context beside the finding so the next review starts with evidence.
Inside the workspace
From discovery to a clear next step.
Each view is tied to your verified domain and shows its own available evidence and scan state.
Asset inventory
Review observed hostnames and related assets, including new and no-longer-observed entries. Search and filter the inventory to focus a review.
Services and web responses
Inspect recorded network services and web observations for an asset when those checks have produced evidence.
Security findings
See severity, evidence and affected asset context together, then review a finding through the workspace's triage flow.
Scan activity and coverage
Follow queued and completed work, review run history and see when discovery was limited or could not finish.
Change context
Compare observed inventory and finding changes over time instead of treating each run as an isolated list.
Team access
Invite colleagues into an eligible workspace with role-based access so the right people can inspect and review results.
How it works
Start with a domain you control.
The workspace separates domain ownership, observation and any approved active checks.
- 01
Verify the domain
Add a domain through monitoring and complete its ownership check before it becomes an EASM target.
- 02
Review discovery
Inspect observed assets, source evidence and the status of available discovery work.
- 03
Prioritize findings
Open the asset and service context for findings that need a closer look, and record your review.
- 04
Track change
Return to run history and change views to see what appeared, changed or was no longer observed.
Clear boundaries
Know what a scan did and did not establish.
Discovery is evidence from specific sources and runs. The workspace shows its coverage and limitations rather than implying that every internet asset has been found.
What the workspace shows
- Results linked to verified domains and the observation that produced them.
- Scan state, freshness and limited or failed coverage where applicable.
- Approved active findings only for targets within the granted scope.
What it does not promise
- A missing result does not prove an asset or vulnerability is absent.
- Active checks are not run against arbitrary IPs or shared infrastructure without explicit approval.
- This workspace is not a penetration test or a guarantee of complete vulnerability coverage.
Who it helps
One view for the people responsible for exposure.
Start with a verified domain and use the evidence at the level your role needs.
Security teams
Review findings, evidence and scan limitations before assigning a response.
Infrastructure owners
Trace an observed host or service back to the domain and decide whether it belongs in the estate.
Risk owners
Understand the direction of exposure and where a deeper technical review is needed.
Questions
Before you start
The most important boundaries of the service are visible from the first visit.
Do I need to verify a domain?
Yes. EASM workspaces are tied to verified domains and available to eligible accounts. The workspace guides you to add a domain when none is ready.
Will LeakData actively test every discovered IP?
No. Active target checks require a separate authorization and are limited to its approved scope. Passive discovery and active findings are identified separately.
Does an empty finding list mean the domain is safe?
No. Results depend on the sources, scope and completion state of each run. Review coverage and freshness before drawing a conclusion.
Can colleagues review the same workspace?
Eligible teams can invite members with workspace roles. Available actions depend on each member's permissions.
Put the evidence to work
See the surface your team can verify.
Open your workspace to review a verified domain, or talk with us about enterprise access and scope.