open port monitoring

Open port monitoring that shows what changed

A port scanner shows what is open now. SurfaceDiff shows which ports appeared, disappeared or changed since the previous scan.

Monitor verified domains for new public services, changed service fingerprints and unexpected exposure. No agent required.

Yesterday
203.0.113.24:6379
Not publicly exposed
Today
203.0.113.24:6379
Redis detected
New public serviceFirst seen today

A one-time port scan is already out of date

A scanner tells you what's open right now - a single point-in-time read. It doesn't tell you when a port appeared, because it never saw the "before". It doesn't show you the previous state to compare against. And it gives you no process for reviewing what you found or any record of the decisions made about it - run it again next month and you're starting from zero.

What SurfaceDiff detects

Newly opened ports
Closed ports
Service fingerprint changes on already-open ports
New public hosts
Timestamped evidence
Email alerts for detected changes

What changed - not the same scan again

ScanNormalizeSnapshotDiffIncidentAlert

You do not need another full list of ports. You need to know what changed.

Review incidents without hiding future changes

Acknowledge, Ignore, Resolve

These apply to one incident - the specific change that was detected. They record how that single event was handled. They don't change how future scans behave.

Mute

A separate mechanism for a specific, expected finding or exposure you've reviewed - for example, a port you intentionally keep open. Muting that stops it from re-alerting until it actually changes again.

Reviewing one incident never automatically silences a different future change - there is no single, catch-all "Accept" button that quietly mutes things you never looked at.

Shared infrastructure without duplicate noise

50 customer domains1 shared server1 new port1 host-level incident

SurfaceDiff recognizes when monitored domains share the same server. A change on that server becomes one incident, not one repeated for every domain that happens to point at it.

Evidence and audit trail

Every incident keeps the previous state, the new state, when it was detected, its severity, who reviewed it, how it was handled, and an optional reason for the decision - a real record, not just today's dashboard view.

How it works

01

Verify a domain

02

SurfaceDiff creates a baseline

03

Recurring scans create new snapshots

04

Real changes become incidents and alerts

Who it's for

  • Small infrastructure teams
  • Hosting providers
  • MSPs
  • Agencies managing customer domains
  • Companies maintaining several internet-facing services

FAQ

Is this the same as an online port scanner?

No. An online port scanner shows the current state of a target when you run it. SurfaceDiff runs on a recurring schedule against domains you've verified, and compares each scan to the previous one - so what you see is what changed, not just a fresh snapshot every time.

Does SurfaceDiff scan the full TCP port range?

Yes, scans cover the full 1-65535 TCP port range, not just a common-ports shortlist.

Can it detect a service change on an existing port?

Yes. An already-open port gets its service fingerprinted, and a change there - for example a different service or version responding on the same port - becomes its own incident, separate from the port simply opening or closing.

Will an expected open port alert every day?

No. Mark it as an expected exposure once, with a reason, and it stays quiet on future scans until it actually changes again.

Do I need to install an agent?

No. Monitoring is entirely external - nothing to install on your servers.

Why must I verify the domain?

SurfaceDiff only ever scans domains an account has explicitly added and proven ownership of via a DNS record. This is a scope boundary, not a formality - it's what keeps this a monitoring tool for infrastructure you manage, not a scanner of infrastructure you don't.

Does SurfaceDiff detect vulnerabilities or CVEs?

No. SurfaceDiff detects changes in public exposure. It does not currently perform CVE or vulnerability matching.

Related reading

Managing this for many client domains on shared servers? See the hosting-provider setup. For the broader picture beyond ports, see external attack surface monitoring.

See what's open on your own domain, not a demo

Run a free scan on a domain you own, or create an account for ongoing monitoring.