Technical overview · Expose

Connect external discovery, threat context and verified closure.

A technical view of Expose coverage, authorised discovery, external exposure signals, prioritisation, ownership and the close–rescan workflow.

See the Expose buyer's guide

System flow

From authorised input to usable evidence.

This sequence shows how the principal technical activities connect. It is a capability flow, not a promise that every engagement uses every stage.

  1. 01

    Asset discovery

    Subdomains, IP addresses, ports, Certificate Transparency logs and DNS.

  2. 02

    Technology detection

    300+ fingerprints across frameworks and servers.

  3. 03

    Technical analysis

    Version tracking, CVE correlation and risk scoring.

  4. 04

    Credential scanning

    Breach databases and leaked-password detection.

  5. 05

    Dark-web monitoring

    Forums, paste sites, GitHub and Telegram monitoring.

Module specifications

What the technical capability covers.

The modules below retain the operational detail a technical evaluator needs when deciding whether the service fits their environment.

01

Asset discovery

Multi-source subdomain enumeration using SecurityTrails, Certificate Transparency logs and DNS resolution, with automatic deduplication and normalisation.

02

Port and service scanning

Quick and full port scans with service identification, banner analysis and protocol detection, followed by risk-scored exposure analysis for open ports.

03

Technology fingerprinting

300+ detection patterns across web servers, frameworks, CMS, CDN, analytics, cloud platforms and security tooling, with version-level vulnerability correlation.

04

SSL/TLS monitoring

Certificate health grading, expiry alerting, TLS-version detection, HSTS checks and identification of self-signed certificates.

05

Credential-leak monitoring

Continuous scanning of breach databases for leaked credentials associated with authorised domains, with severity-rated alerts and breach-source attribution.

06

Dark-web monitoring

Ongoing monitoring of dark-web forums, paste sites, GitHub and Telegram channels for leaked credentials, data dumps and mentions of the organisation.

Coverage, logic and outputs

The specification behind the workflow.

These details make the coverage and operating assumptions easier to evaluate. Items identified in the verification notice remain subject to sign-off before launch.

Technology detection coverage

  • Servers (20+) — nginx, Apache, IIS, LiteSpeed, Caddy, OpenResty and Traefik
  • Frameworks (100+) — React, Vue, Angular, Next.js, Laravel, Django, Spring Boot and Rails
  • CMS and commerce (50+) — WordPress, Drupal, Shopify, Magento, Ghost and WooCommerce
  • Cloud and CDN (25+) — AWS, Azure, GCP, Cloudflare, Akamai, Vercel and Fastly

Attack-surface risk score

  • 30% — high-risk assets: critical and high-severity exposures
  • 20% — critical ports: dangerous services exposed to the internet
  • 20% — leaked credentials: confirmed breaches with severity rating
  • 15% — SSL issues: expired or misconfigured certificates
  • 15% — port exposure: distribution of risky open ports

Monitoring and reporting

  • Scheduling: hourly monitoring, daily scans, weekly sweeps and monthly audits
  • Per-domain scan configuration
  • Attack-surface, SSL-health and port-exposure reports
  • Executive summary with PDF and JSON export

Boundaries and assumptions

Confirm the detail before work begins.

Technical coverage is shaped by the agreed scope, customer environment, service selection and authorised operating model.

See prices

Review the scope

Apply the technical model to your environment.

A relevant Pentesys specialist will review this overview, answer questions about boundaries, evidence and workflow, and explain the smallest proportionate next step.

Review this scope with a specialist Please do not submit credentials, secrets or sensitive evidence through the enquiry form.

Technical language, translated

Need a definition before going deeper?

The Pentesys glossary explains the security, testing and assurance terms used throughout this overview in plain English.

Browse the glossary

Trusted experience

Supporting recognised organisations.

Royal Ballet and Opera logo
Royal Ballet and Opera
Rightmove logo
Rightmove
Fortis logo
Fortis
Orange logo
Orange
Small Luxury Hotels of the World logo
Small Luxury Hotels of the World
AI Incumbency logo
AI Incumbency
Pentesys has continuously performed admirably during our collaboration, giving us faith in their knowledge. They delivered work that above our expectations by approaching each project with a deep understanding of our specifications. Their team demonstrated a remarkable degree of proficiency by effectively pinpointing weaknesses and offering practical suggestions to reduce possible hazards.
MDFortis Cyber Security Limited
Unlike previous pentests that produced generic outputs, this engagement gave us clear, prioritised actions with real-world attack scenarios. The platform visibility into assets, vulnerabilities and remediation progress has helped us mature our security posture significantly. The team were professional, responsive, and genuinely cared about improving our security rather than just ticking a box.
Head of ITHealthcare Technology Company
The red team and external attack surface management work highlighted blind spots we didn't know existed. What stood out was the strategic guidance alongside the technical delivery – helping us shape a longer-term security roadmap rather than a one-off engagement. This felt like a partnership, not just a transactional assessment.
CISOSaaS Provider
Pentesys has continuously produced excellent work. Their group demonstrated extraordinary technical proficiency by spotting crucial flaws and offering clever fixes that greatly strengthened our security stance. Their meticulous approach and attention to detail ensured that every facet of the project was covered in full.
IT Security SpecialistRightmove PLC
We engaged Pentesys and the team for a complex penetration test and adversary simulation. The quality of the technical findings, realism of the attack paths, and clarity of reporting were outstanding. The recommendations were practical and mapped clearly to business risk, which made board-level conversations much easier. We've since built Pentesys into our ongoing security assurance programme.
CTOUK Financial Services Provider

ACCREDITED TO THE HIGHEST INDUSTRY STANDARDS

Why CREST matters when choosing a provider