Automated reconnaissance across your hosts and public footprint, followed by baseline scanning for open ports, exposed storage, and TLS problems — and across the domains and DNS records that point at them.
Perimeter Audit
Everything you have exposed to the internet.
Hosts, ports, services, storage — and the names and delivery path that lead users to them. Keel Formal maps the perimeter the way an attacker first encounters it, as a list of things that answer, and sorts it into the things that should and the things that should not.
Every host, port, and service you have exposed.
Including the staging box from last quarter and the bucket someone made public to debug something. We enumerate the whole public footprint — the parts nobody has logged into for a year included — and check each one against what reaching it would let somebody do.
- Asset discovery Subdomain enumeration, DNS sweeps, and reconnaissance across your public footprint to find the hosts you have and the ones you forgot you had.
- Exposed services Open ports, running services, and admin interfaces reachable from the internet — databases, dashboards, and internal tooling that was never meant to be public.
- Exposed data Public cloud storage buckets, open directories, backups, and configuration files left readable by anyone who knows the URL.
- Known vulnerabilities Outdated and unpatched software on anything exposed, checked against publicly known exploits — and then verified by hand, so you get confirmed exposure rather than scanner noise.
- Encryption in transit TLS configuration, certificate validity and issuance controls, and any endpoint still accepting a weak or expired connection.
- Edge protection WAF and Cloudflare configuration — whether the rules do what you assume, and whether the origin can simply be reached directly, around them.
And the names and delivery path that lead users there.
The hosts are one half of the perimeter. The other half is the route a user takes to reach them — a domain name, a DNS answer, and a bundle served from somewhere. Control any one of those and the protocol never has to be attacked at all, so the same audit covers them.
- Registrar and DNS Registrar account security and transfer locks, DNSSEC, registrar-level 2FA, and who inside the company can change a record.
- Domain inventory Forgotten subdomains, dangling records pointing at deprovisioned hosts, and lookalike registrations already in circulation.
- Delivery path CDN and hosting account access, build-to-deploy integrity, TLS and certificate issuance controls, and CAA records.
- Frontend integrity Content Security Policy, subresource integrity, third-party scripts on signing pages, and detection when the served bundle changes.
How it works
Every automated finding is reviewed and validated by an engineer, and the edge configuration is checked directly. You are not handed a scanner report.
You receive a complete inventory of what you have exposed, what each item risks, and what to decommission, lock down, or patch first.
Typical scope
Every internet-facing server, port, and interface that answers a stranger.
Buckets, directories, and backups reachable by anyone who knows the URL.
Primary and secondary names, registrar accounts, and every record that resolves.
The accounts able to change what is served at your domain.
Lookalike domains, impersonation, and the paths users take to find you.
Why this exists
The registrar was hijacked and the frontend swapped. Users signed on what looked like the real site.
CoW Swap · $1.2M (read the incident write-up)