open port monitoring

Open port monitoring that shows what changed

A port scanner shows what is open now. SurfaceDiff shows which ports appeared, disappeared or changed since the previous scan.

Monitor verified domains for new public services, changed service fingerprints and unexpected exposure. No agent required.

Yesterday
203.0.113.24:6379
Not publicly exposed
Today
203.0.113.24:6379
Redis detected
New public serviceFirst seen today

A one-time port scan is already out of date

A scanner tells you what's open right now - a single point-in-time read. It doesn't tell you when a port appeared, because it never saw the "before". It doesn't show you the previous state to compare against. And it gives you no process for reviewing what you found or any record of the decisions made about it - run it again next month and you're starting from zero.

What SurfaceDiff detects

Newly opened ports
Closed ports
Service fingerprint changes on already-open ports
New public hosts
Timestamped evidence
Email alerts for detected changes

What changed - not the same scan again

ScanNormalizeSnapshotDiffIncidentAlert

You do not need another full list of ports. You need to know what changed.

Review incidents without hiding future changes

Reviewed, Resolved

These apply to one incident - the specific change that was detected. They record how that single event was handled. They don't change how future scans behave.

Mute

A separate mechanism for a specific, expected finding or exposure you've reviewed - for example, a port you intentionally keep open. Muting that stops it from re-alerting until it actually changes again.

Reviewing one incident never automatically silences a different future change - there is no single, catch-all "Accept" button that quietly mutes things you never looked at. See best practices for a real example of when muting a recurring finding makes sense.

Shared infrastructure without duplicate noise

50 customer domains1 shared server1 new port1 host-level incident

SurfaceDiff recognizes when monitored domains share the same server. A change on that server becomes one incident, not one repeated for every domain that happens to point at it.

Evidence and audit trail

Every incident keeps the previous state, the new state, when it was detected, its severity, who reviewed it, how it was handled, and an optional reason for the decision - a real record, not just today's dashboard view.

SurfaceDiff incident detail: a new port opened, showing shared-host scope, severity, status and detected timestampThe resulting open-port finding, with its service fingerprint and Alert / Mute controls

Example from infrastructure monitored by SurfaceDiff.

See what your current baseline looks like. Get a free scan

How it works

01

Verify a domain

02

SurfaceDiff creates a baseline

03

Recurring scans create new snapshots

04

Observed differences between snapshots become incidents and alerts

Who it's for

  • Small infrastructure teams
  • Hosting providers
  • MSPs
  • Agencies managing customer domains
  • Companies maintaining several internet-facing services

FAQ

Is this the same as an online port scanner?

No. An online port scanner shows the current state of a target when you run it. SurfaceDiff runs on a recurring schedule against domains you've verified, and compares each scan to the previous one - so what you see is what changed, not just a fresh snapshot every time.

Does SurfaceDiff scan the full TCP port range?

Yes, scans cover the full 1-65535 TCP port range, not just a common-ports shortlist.

Can it detect a service change on an existing port?

Yes. An already-open port gets its service fingerprinted, and a change there - for example a different service or version responding on the same port - becomes its own incident, separate from the port simply opening or closing.

Will an expected open port alert every day?

No. Mute that specific expected finding, with a reason, and it stays quiet on future scans until the exposure changes again.

Do I need to install an agent?

No. Monitoring is entirely external - nothing to install on your servers.

Why must I verify the domain?

SurfaceDiff only ever scans domains an account has explicitly added and proven ownership of via a DNS record. This is a scope boundary, not a formality - it's what keeps this a monitoring tool for infrastructure you manage, not a scanner of infrastructure you don't.

Does SurfaceDiff detect vulnerabilities or CVEs?

No. SurfaceDiff detects changes in public exposure. It does not currently perform CVE or vulnerability matching.

Related reading

Managing this for many client domains on shared servers? See the hosting-provider setup. For the broader picture beyond ports, see external attack surface monitoring.

Start with your own domain

Run a free scan to establish a real baseline, or create an account for recurring monitoring.