Assess external exposure across your organisation and supply chain.
Vigil evaluates customer-authorised domains through phased discovery and intelligence checks covering external assets, exposed services, vulnerability context, leaked data and relevant threat activity. Results are prioritised for technical review and remediation planning.

Common sources of external exposure
Unmanaged assets with relevant vulnerabilities
Older subdomains, test portals, VPN appliances and vendor-managed hosts may remain externally observable and require validation against current vulnerability context.
Third parties with privileged connectivity
Logistics providers, managed-service providers and payroll vendors may hold credentials or network access that should be considered in exposure reviews.
Periodic assessments with limited current evidence
Questionnaires provide useful governance evidence but may not reflect changes in externally observable assets between review cycles.
How Vigil assesses it
Discover → correlate → prioritise → act — a repeatable, authorised assessment workflow with technical evidence and an executive risk summary.
- 01 · Discover
Assets and attack surface
Subdomains, IPs, services, technologies, certificates, cloud storage and code repositories — 132+ OSINT and CTI modules.
- 02 · Correlate
Leak, brand and threat data
Discovered assets are joined with credential leaks, phishing domains, underground mentions and vendor breaches from the rest of the platform.
- 03 · Prioritise
CVE, MITRE ATT&CK and potential attack paths
Vulnerability records with CVSS and KEV context are matched to observed technologies; relevant findings can be mapped to ATT&CK and reviewed as potential attack paths.
- 04 · Act
Risk score, remediation plan and report
Prioritised recommendations, indicators and governance references are included in technical outputs and can be routed into supported case-management tools.

Module feed and phase progress for one domain, then findings, ATT&CK mapping, attack paths and the prioritised action plan.
What changes for your team
An external view of the attack surface
External discovery can identify observable assets that require confirmation against the organisation’s inventory.
Current evidence for supplier review
Authorised supplier assessments can supplement onboarding and periodic questionnaires with externally observable findings.
Outputs for different stakeholders
Executive summaries, technical findings and governance references are produced from the same assessment evidence.
Questions we get asked
Is the scan intrusive?+
CTI Scan is OSINT- and intelligence-driven: it discovers and correlates from public and collected data. It is not a penetration test and does not exploit targets.
Can we scan our suppliers?+
Yes — any domain you are entitled to assess. A common pattern is to scan critical vendors at onboarding and then on a regular schedule.
How long does a scan take?+
Initial automated analysis typically completes within 5–10 minutes. Duration and coverage depend on the size and structure of the authorised scope; technical and executive outputs are generated when processing completes.
Review the external-risk assessment methodology.
Review the assessment methodology and representative outputs. Customer-domain assessments are performed only after scope and authorisation are confirmed.
