Orkan discovers, maps, and monitors internet-facing assets and services from the outside in, building a live inventory of your external exposure.
That gap is where risk lives.
Over time, every organization loses sight of what it exposes
Reorganizations and acquisitions leave exposure that is easy to overlook and may no longer have clear ownership
Subdomains and DNS records stay long after their purpose is gone, and what they point to may still be live.
Your inventory has one version. The internet has its own.
Add your domains and verify ownership. Mapping starts from there. No further configuration required.
Orkan discovers internet-facing assets and services from the outside in, including assets that never made it into any inventory.
New assets are discovered automatically, and existing ones are rechecked continuously.
See how domains, services, and providers connect across an external footprint.
Search assets, inspect relations, and see what is currently present in scope.
No agents, no appliances, and no heavy setup. Nothing to install and nothing to maintain.
Unlimited discovery across all your domains. You choose which assets to actively scan.
You only pay for the assets you choose to actively scan, not for the assets Orkan discovers.
External attack surface management is the process of discovering, mapping, and monitoring an organization’s internet-facing assets and services from the outside in. It gives security teams a continuously updated inventory of external exposure.
Orkan starts with domains you provide, then discovers related subdomains, DNS zones, IP addresses, and internet-facing services. It builds a connected view of those assets, showing what each one is, how it relates to the wider footprint, and when it was observed.
Orkan finds previously unknown assets by combining public data sources with clues in what it has already observed. It uses certificate transparency, DNS history, web archives, public code references, and likely subdomain patterns, then analyzes certificate names, DNS targets, redirects, and hostnames sharing an IP address. DNS and service checks confirm what is currently visible from the public internet.
To get started, provide one or more primary domains—for example, your main website, a product domain, or a brand you manage. Each domain must be confirmed as part of your organization’s authorized scope before discovery begins. You can add more domains as your scope grows.
No. Orkan works from the outside in, so there are no agents, appliances, or other software to deploy in your environment. You access Orkan through the web, and it does not need access to your internal network to map your external footprint.
No. By default, Orkan discovers assets and uses lightweight requests on common web ports to identify publicly reachable services. These checks do not scan for vulnerabilities. Vulnerability scanning and other more thorough checks run only on assets you select. Broader port scanning—which probes the underlying IP address for additional services—requires authorization for that infrastructure, so Orkan does not scan shared cloud or hosting environments merely because your domain points to them.
Vulnerability scanners are primarily designed to assess known targets. Orkan starts one step earlier by continuously discovering and mapping what is actually visible from the internet, including forgotten and newly exposed assets. You can then choose which of those assets receive vulnerability scanning.
Yes. Once your scope and scanning choices are set, Orkan manages the recurring monitoring automatically. Discovery, DNS, service checks, and vulnerability scanning run at different intervals based on what needs refreshing, without requiring you to configure schedules or start individual checks. Continuous monitoring means ongoing checks rather than real-time observation of every asset.
Orkan uses low-impact scanning for production systems, but active scanning is never entirely risk-free. Its checks are designed to avoid changing the target system and run with strict limits on rate, concurrency, and execution time. Exploit attempts and authenticated testing are excluded.
For plan limits, one actively scanned asset is one domain or hostname you choose for active scanning. If app.example.com resolves to multiple IP addresses or exposes several services, it still counts as one asset. Orkan tracks the related infrastructure separately without increasing your active scanning count.
No. Discovery is unlimited across all your domains. Each plan includes active scanning for a set number of assets, and you choose which assets receive it. Because discovery itself does not affect the price, your cost remains predictable even when Orkan finds more assets.
If the gap between inventory and reality sounds familiar, Orkan helps you see where the two differ.
You provide the domains, and Orkan handles the rest. We'll walk through what shows up from the outside.
Set up a trial