ShadowTrackr

Start a free trial

Attack surface management use cases

See what we can do for you.

Hunt down phishy versions of your websites

Hunt down phishy versions of your websites

Phishing is one of the major attack vectors. When your clients or employees get phished, they receive a link to a website looking like yours. Attackers collect accounts and passwords on the fake website and use those to get into your systems. ShadowTrackr scans the internet for website looking like yours and alerts you when things get phishy. This way you can warn your users in time.

Monitor in which clouds your assets appear

Monitor in which clouds your assets appear

The days when you could ask IT where your data was are over. Anyone can setup a website in a cloud somewhere. Larger organizations often have policies specifying which clouds you can use. We match all your assets against cloud providers and send you a weekly overview. So if you said “Azure West Europe only” and your site appears in Japan West too, you’ll know.

Screenshot of vulnerabilities found in internet exposed assets

Find vulnerabilities in internet exposed assets

Attackers continuously scan the internet for vulnerable websites and servers, and that includes your assets. We look at your assets in the same way and warn you when we find a weak spot. Note that ShadowTrackr does only passive reconnaissance. We do not fire off any actual exploits (which would be illegal in most countries).

Set up custom alerts to track insecure hosts

Set up custom alerts to track vulnerable hosts

Your hosts can expose unintended information to the internet, like configuration information for Redis or MySQL. Or worse, they might have an unpatched vulnerability exposed to the internet. If so, our scanner nodes flag it as a problem. Not only will this appear as an event an in reports, so can also set custom alerts which sent warning emails or call webhooks.

Know when your assets are blacklisted

Know when your assets are blacklisted

The good guys on the internet publish many blacklists: hacked servers, spamming servers, C2 servers. If your assets appear on a blacklist, you’re in trouble. Visitors might no longer see your website, and clients no longer receive your emails. We check your assets against these blacklist and alert you when we find something.

Find breached passwords for public accounts

Find breached passwords for public accounts

Most websites list email addresses. You need to for your business. Attackers know this and gather them. Next, they search dataleaks for matching passwords and try to log in to your systems. ShadowTrackr does the first two steps too, but instead of trying to log in we warn you that you need to change the password.

Reduce your dependency on non-European suppliers

Reduce dependency on non-European suppliers

Just like it is is hard to track your online assets, it is hard to track all suppliers of those assets. ShadowTrackr does that for you in the Supplier Dependency Report. For each supplier we also track where they are European companies or not. If you want to reduce your dependency on non-European countries, this is the report you need.

Track exposed databases and remote login services

Track exposed databases and remote logins

Mistakes happen. Due to a simple configuration error a database with client data can be exposed to the internet. Or a remote login that should have been behind a VPN is somehow accessible for the entire internet. We continuously scan your assets, track all changes and alert you when things go bad.