external attack surface monitoring

Know what changed on your domains since yesterday - not just what's exposed today.

SurfaceDiff continuously monitors the domains you manage - subdomains, DNS, open ports, TLS certificates, and web services - on a schedule you control, and turns each scan into a diff against the last one. Unchanged findings stay quiet. Observed differences between snapshots become incidents, with evidence attached.

Managing this across many client domains on shared servers? See the hosting-provider setup.

Yesterday
staging.example.com
No DNS record - not part of the attack surface
Today
staging.example.com
Resolves - live web application running
New public hostFirst seen today

What most attack-surface monitoring actually gives you

A one-off scan is out of date the next day

A report from last quarter tells you nothing about the port that opened last Tuesday. Attack surfaces change on their own - a deploy, a forgotten staging subdomain, a certificate renewal nobody checked - and a point-in-time scan can't see any of it.

Internet-wide index tools aren't watching your schedule

Shodan-style tools index whatever they've already crawled, on their timetable, whether or not you asked. Useful for a quick lookup, not the same job as a tool that scans your domains when you tell it to and alerts you when the next scheduled scan detects a change.

Every change looks like an alert, until it's all noise

Tools that re-report the same open port or the same subdomain every single scan train you to stop reading alerts entirely - right before the one that mattered shows up.

How SurfaceDiff does it

Scans your domains, not the whole internet

SurfaceDiff only ever scans a domain your account has explicitly added and verified ownership of. No surprise scanning of infrastructure you don't have a relationship with, and no depending on someone else's crawl schedule.

Consistent coverage, every scan

Subdomains, DNS records, open ports, TLS certificates, and live web services are normalized into one structured snapshot, covering the same monitored areas consistently on every run.

Diffed against last time, not reported from scratch

Each new snapshot is compared to the previous one. A port that was open last week and is still open today isn't an incident - a port that just opened is. You get told what changed, with evidence, not the full state again.

Evidence kept, not just today's state

Every incident keeps the previous state, the new state, when it was detected, and who reviewed it - a real record, not just what the dashboard happens to show today.

Review incidents without hiding future changes

Acknowledge, Ignore, Resolve

These apply to one incident - the specific change that was detected. They record how that single event was handled. They don't change how future scans behave.

Mute

A separate mechanism for a specific, expected finding or exposure you've reviewed - for example, a port you intentionally keep open. Muting that stops it from re-alerting until it actually changes again.

Reviewing one incident never automatically silences a different future change - there is no single, catch-all "Accept" button that quietly mutes things you never looked at.

A typical setup

Add a domain and verify ownership with a DNS TXT record - the same verification step runs whether it's your only domain or your fiftieth. SurfaceDiff runs a baseline scan, then keeps scanning on schedule. From then on, the dashboard and your inbox only hear about what actually changed: a new subdomain, a port that opened, a certificate that's about to expire, a service that disappeared.

New to the concept? What is external attack surface management (EASM)? covers the background, or see how this compares to an internet-wide index like Shodan.

See your own attack surface, not a demo of someone else's

Run a free scan on a domain you own, or add it directly and get a real baseline in minutes.