Skip to main content
13 posts · ShadowMap Research

Notes from the operators' side.

Attack-surface trends, threat-actor profiles, and platform notes from the ShadowMap intelligence team. Published when there's something specific to say, not on a content calendar.

Blog

Latest posts

July 29, 2026

What a security rating does and does not tell you

A security rating compresses your external posture into a single letter. Four things the grade structurally cannot see, and how to use it as an index rather than an outcome.

cyber security ratingssecurity ratingsthird-party risk management
July 21, 2026

Source code leaks: what a public repository actually gives an attacker

The code is rarely the fastest thing in a leaked repository. What an attacker actually takes is the endpoints, the secrets and the architecture — and finding those in the noise is the whole job.

source code leaksecret detectiondata exposure monitoring
July 7, 2026

Switching external exposure vendors: the first thirty days

Replacing a digital risk protection or attack surface vendor is a data-migration project, not a procurement one. What to export, what to insist on, and what will look like a regression in week one.

External Exposure ManagementAttack Surface ManagementDigital Risk Protection
June 23, 2026

Digital risk protection is being absorbed. What replaces it?

Search demand for digital risk protection is receding while the problem itself grows. What the category got right, what it never covered, and what replaces it.

digital risk protectionexternal exposure managementCTEM
June 9, 2026

EASM, CAASM, vulnerability management, exposure management: which one do you actually need?

Four acronyms compete for the same budget line, and they are not interchangeable. The difference is architectural, and one question separates them: where does the data actually come from?

CAASMEASMExposure Management
May 27, 2026

Reconstructing a compromised device from seven artefacts

A password is one row; a device is a story. The seven artefact classes in a stealer log, what each one tells you that the password does not, and the response that follows from each.

account takeover preventionstealer logsinfostealer
May 13, 2026

Continuous pentesting, BAS, autonomous pentesting and CART: what actually validates external exposure

Breach and attack simulation, autonomous pentesting, continuous penetration testing and CART all promise proof. What each one actually validates — and where each one is blind.

continuous penetration testingbreach and attack simulationadversarial exposure validation
April 29, 2026

Stealer logs are not combolists, and the difference decides your response

A credential-exposure report shows two identical-looking rows. One is a resold combolist entry worth almost nothing; the other is an infostealer capture from a live device, and an active incident.

infostealerstealer logscredential exposure
April 21, 2026

How to scope a fourteen-day external exposure proof of concept

Most external exposure POCs test features that were never in doubt. What fourteen days can actually settle is whether a platform's picture of your organisation is correct — and how to measure that.

Attack Surface ManagementVendor EvaluationExposure Management
April 7, 2026

Prioritising external exposure you cannot patch this quarter

A leaked key, a typosquat, a vendor's weak posture, a credential in someone's browser: none of these has a CVE. Prioritising them needs a different method from vulnerability management.

threat exposure managementCTEMAI Review
March 24, 2026

Forty thousand leaked credentials, or eight? The number that matters

Credential exposure is not a volume problem. What a stealer log actually contains, how a leaked credential gets tested, and why the handful that still authenticate are the only ones that matter.

stealer logscredential exposuredark web monitoring
March 10, 2026

The external half of a CTEM programme

Every published treatment of continuous threat exposure management assumes agents and internal scope. Here is what the five stages look like from the outside, where an attacker actually starts.

CTEMexposure managementattack surface management
September 17, 2020

Investigating Chinese Intelligence Firm Zhenhua Data

Our investigation of Zhenhua Data with a detailed look at their operation and how the Chinese Intelligence Firm leverages public and private data sources to create actionable intelligence about a wide range of targets.

Security ResearchChinese IntelligenceZhenhua Data

Want us to look at your domain?

Everything above comes out of running this against real estates. Give us one apex domain and we'll send back a written snapshot of what is already visible from outside — no call required.