EZScan EASM

External Attack Surface Management

Passive & non-intrusive: this tool reads only publicly published DNS, Certificate Transparency, and registry data from directly inside your browser — it never scans ports, exploits, or brute-forces anything. Only assess assets you own or are authorized to test. Not a substitute for a licensed penetration test.

Attack Surface Discovery

See your attack surface the way an attacker does

Enter a target domain to passively discover subdomains, live assets, exposed technology, and real exposures across 9 security domains — no login, no agents, nothing installed on your infrastructure.

or
No login required. Nothing you scan is stored on a server.

Methodology & Scope

What this tool checks — 9 Assessment Domains

  • Outdated Web Versions: outdated web/CMS server version signals (honesty-first, requires manual verification — see below)
  • Web App Hardening: HTTP headers, auth-portal exposure, malicious-code checks (honesty-first)
  • TLS & Certificate Health: certificate expiry risk & issuer consistency from real Certificate Transparency log metadata
  • Exposed Network Services: exposed unsafe services (RDP/DB/SMB/FTP/Telnet) — honesty-first, real port scanning is impossible from a browser
  • Network Reputation Signals: real-time Spamhaus ZEN/DBL blacklist lookups (genuine passive DNS check)
  • Mail Authentication Controls: real SPF, DMARC, DKIM (best-effort), and MTA-STS checks
  • DNS Resilience & Integrity: real DNSSEC validation signal, CAA, nameserver redundancy, Certificate Transparency exposure, dangling-CNAME takeover risk
  • Hosting Isolation Posture: real cotenant/shared-IP inference from discovered assets vs. dedicated hosting
  • Historical Exposure Events: honesty-first — no free/no-auth breach-history API exists for a static tool

What this tool does NOT do — and why

  • No port scanning or service/banner grabbing — browsers have no raw socket access for any target, ever (a hard platform limitation, not CORS)
  • No live TLS handshake, cipher-suite, or protocol-version inspection — browsers don't expose this to JavaScript for any site, for any target, ever
  • No reading of HTTP status codes, response headers, or page content of arbitrary third-party sites — blocked by browser CORS/Same-Origin Policy for any site that hasn't explicitly opted in. Where the spec calls for this (security headers, exposed paths, software versions, malicious code), findings are honestly reported as "requires manual verification" rather than guessed or faked.
  • No historical breach-event lookup — no free, no-auth, CORS-enabled public API exists for this; reported honestly rather than fabricated
  • No subdomain brute-forcing or intrusive enumeration; no exploitation or active probing of any kind
  • No fabricated results for real scans: if a live API (e.g. crt.sh, Spamhaus) is unreachable, the affected check is shown as "Could Not Check" — never silently replaced with invented data. The "Load Sample Report" button is the only source of demo data, and it's always clearly labeled as a sample report for a fictional company.

All lookups use public, authentication-free, read-only data sources (DNS-over-HTTPS resolvers, public Certificate Transparency logs, Spamhaus DNSBL, and public IP registry/geolocation APIs). This tool provides a directional risk indicator only and should be complemented with authorized, professional security testing for a complete assessment.