Notes from the operators' side.
Attack-surface trends, threat-actor profiles, and platform notes from the ShadowMap intelligence team. Published when there's something specific to say, not on a content calendar.
Blog
Latest posts
What a security rating does and does not tell you
A security rating compresses your external posture into a single letter. Four things the grade structurally cannot see, and how to use it as an index rather than an outcome.
Source code leaks: what a public repository actually gives an attacker
The code is rarely the fastest thing in a leaked repository. What an attacker actually takes is the endpoints, the secrets and the architecture — and finding those in the noise is the whole job.
Switching external exposure vendors: the first thirty days
Replacing a digital risk protection or attack surface vendor is a data-migration project, not a procurement one. What to export, what to insist on, and what will look like a regression in week one.
Digital risk protection is being absorbed. What replaces it?
Search demand for digital risk protection is receding while the problem itself grows. What the category got right, what it never covered, and what replaces it.
EASM, CAASM, vulnerability management, exposure management: which one do you actually need?
Four acronyms compete for the same budget line, and they are not interchangeable. The difference is architectural, and one question separates them: where does the data actually come from?
Reconstructing a compromised device from seven artefacts
A password is one row; a device is a story. The seven artefact classes in a stealer log, what each one tells you that the password does not, and the response that follows from each.
Continuous pentesting, BAS, autonomous pentesting and CART: what actually validates external exposure
Breach and attack simulation, autonomous pentesting, continuous penetration testing and CART all promise proof. What each one actually validates — and where each one is blind.
Stealer logs are not combolists, and the difference decides your response
A credential-exposure report shows two identical-looking rows. One is a resold combolist entry worth almost nothing; the other is an infostealer capture from a live device, and an active incident.
How to scope a fourteen-day external exposure proof of concept
Most external exposure POCs test features that were never in doubt. What fourteen days can actually settle is whether a platform's picture of your organisation is correct — and how to measure that.
Prioritising external exposure you cannot patch this quarter
A leaked key, a typosquat, a vendor's weak posture, a credential in someone's browser: none of these has a CVE. Prioritising them needs a different method from vulnerability management.
Forty thousand leaked credentials, or eight? The number that matters
Credential exposure is not a volume problem. What a stealer log actually contains, how a leaked credential gets tested, and why the handful that still authenticate are the only ones that matter.
The external half of a CTEM programme
Every published treatment of continuous threat exposure management assumes agents and internal scope. Here is what the five stages look like from the outside, where an attacker actually starts.
Investigating Chinese Intelligence Firm Zhenhua Data
Our investigation of Zhenhua Data with a detailed look at their operation and how the Chinese Intelligence Firm leverages public and private data sources to create actionable intelligence about a wide range of targets.
Want us to look at your domain?
Everything above comes out of running this against real estates. Give us one apex domain and we'll send back a written snapshot of what is already visible from outside — no call required.