HOW IT WORKS

One platform. Every external signal. Zero agents.

The ASM platform continuously ingests from ~40 threat sources, correlates them through a purpose-built engine, and delivers prioritised, deduplicated findings into your existing security workflow.

AGENTLESSCONTINUOUSSIEM-NATIVE
PLATFORM ARCHITECTURE

Continuous Signals to Actionable Defense

How data flows through the ASM ingestion pipeline, core engine, and your security stack.

01 · INGESTION SOURCES (~40 FEEDS)
DNS & Passive DNS
Certificate Transparency Logs
Dark Web Sources (250+)
Ransomware Sites (120+)
WAF & App Probes
Vendor Graph
02 · CORRELATION ENGINE

ASM CORE ENGINE

Real-time threat processing & entity resolution

1Deduplicate findings per real exposure
2Correlate vendor breaches to your assets
3Attach MITRE ATT&CK TTPs & confidence
4Score by EPSS, CVSS & CISA KEV
03 · ACTIONABLE OUTPUTS & DESTINATIONS
Live Client Dashboard
SIEM & Webhooks (STIX/TAXII)
Jira & ServiceNow Tickets
Slack & PagerDuty Alerts
Managed Takedowns SLA
LAYER 1 · INGESTION

Continuous Global Threat Vector Coverage

How ASM observes the internet-facing surface and dark web without touching your internal network.

DNS & Passive DNS

Live map of every subdomain, historical zone files included. Powers Subdomain Takeover and CertPulse.

Certificate Transparency

Every certificate issued for your domain in near-real-time. Powers CertPulse and rogue cert alerts.

Dark Web Sources

250+ forums, marketplaces, paste sites, and Telegram channels. Powers Card, Customer, and Employee Leaks.

Ransomware Leak Sites

120+ groups' leak blogs polled continuously. Powers RansomeHive real-time alert feed.

WAF & App Probes

Non-disruptive signature payloads to verify defence-in-depth posture. Powers WAFlyzer and Header Health.

Vendor Graph

Supplier list enriched with domain and product identifiers. Powers Third-Party Leak monitoring.

LAYER 2 · CORRELATION

How the ASM Core Transforms Raw Feeds

01

DEDUPE

One finding per real-world exposure — not one per scan run. Reduces noise by up to 90%.

02

CORRELATE

When a vendor or third-party is breached, we infer which of your assets or credentials are affected.

03

ENRICH

Attach MITRE ATT&CK TTPs, campaign attribution, and confidence scores before routing.

LAYER 3 · SCORING

Exploit-Aware Composite Prioritisation

We combine four distinct risk signals into a single actionable score per finding.

CVSS Severity

Base severity metrics from NVD and CVE records.

EPSS Probability

Statistical probability of exploitation in the wild over 30 days.

CISA KEV Catalog

Automatic priority boost for anything in the Known Exploited Vulnerabilities list.

Public Proof-of-Concept

Presence of weaponised POC code on GitHub or ExploitDB shifts priority to Critical.

INTEGRATIONS

Seamless Output Destinations

Stream threat signals directly into your existing security workflow and ticketing systems.

Client Dashboard

Real-time web application at /client/*

SIEM & Webhooks

Splunk, Sentinel, Elastic, STIX/TAXII

Ticketing Systems

Jira, ServiceNow, PagerDuty

Managed Takedowns

24x7 removal service for phishing & brand abuse

QUALITY & RE-CHECK

Continuous Cadence & Analyst Oversight

01

Re-check Cadence

DNS zones verified daily, dark web sources every 15 minutes, ransomware blogs continuously polled.

02

Analyst Review Gate

High-priority findings pass through an analyst sign-off before customer alerts fire to suppress false positives.

03

Evidence Trail Retention

Raw response headers, DNS zone snapshots, and redacted breach records are archived per finding for audit.

DEPLOYMENT MODEL

Zero Friction. Instant Value.

100% Agentless

No software inside your network or endpoints. Zero deployment overhead.

No Firewall Changes

All observation is external. Nothing needs to be opened in your perimeter.

SaaS Hosted & Multi-Region

Enterprise SaaS architecture with regional data options for compliance.

DATA GOVERNANCE

Data Handling & Security Controls

Encryption in Transit

TLS 1.3

Encryption at Rest

AES-256-GCM

Retention Windows

30 / 90 / 180 / 365 days

Regional Storage

EU · US · India

Access Controls

SAML 2.0 / OIDC SSO

Audit Logging

Immutable Action Log

COMPLIANCE

Designed for Enterprise Risk Frameworks

SOC 2 Type II Controls

Platform security procedures aligned with Trust Services Criteria.

ISO 27001 Alignment

Information security management controls across platform infrastructure.

GDPR-Aligned Processing

Data processing agreements and regional data isolation supported.

FREQUENTLY ASKED QUESTIONS

Frequently Asked Questions

No. ASM is 100% agentless. All observation is external, operating from public DNS, CT logs, threat feeds, and dark web ingestion.

See the platform end-to-end.

Request a personalised architecture walkthrough with our engineering team.