Map your external attack surface

Subdomains and hosts indexed per domain — split by network reachability, with open ports, CVE counts, and domain-grouped views.

You're on the list. We'll reach out about enterprise access.

Assets in BreachQuery

BreachQuery Assets — external hosts and ports for acme.com

What Assets delivers

Subdomains tab

DNS and certificate-discovered subdomains with reachability classification.

Hosts tab

External IPs and hostnames with open port tags and CVE counts.

Reachability split

Filter all, reachable, or discovered-only assets.

Port visibility

See which services are exposed without leaving the assets view.

Domain groups

Expand each monitored domain to review its full asset inventory.

Feeds the Breach Graph

Every asset becomes a node in your domain's attack-path map.

Three steps on Assets

Discover assets

Monitoring pulls index subdomains and hosts from external intelligence.

Classify reachability

Open ports mark a host reachable; DNS-only findings stay discovered-only.

Investigate further

Jump to CVEs, Incidents, or the Breach Graph for deeper context.

Built for enterprise teams

Attack surface management

Maintain a living inventory of what's exposed per domain.

Shadow IT discovery

Find forgotten subdomains and services before attackers do.

M&A diligence

Snapshot external assets for acquired domains on day one.

Infrastructure handoff

Give platform teams reachable host lists with port details.

Common questions

What's the difference between subdomains and hosts?

Subdomains are hostname discoveries; hosts are IPs and resolved endpoints with port data.

Why are some assets non-reachable?

They were discovered via DNS or certificates but have no open ports detected.

How often are assets refreshed?

On the same 24-hour monitoring cycle as credentials and CVEs.

Do assets link to incidents?

Yes — the Breach Graph connects assets to credential and CVE findings.

Request enterprise early access

Join the waitlist — be first to run Assets for your organization.