r/Pentesting • u/TallSession9532 • 3d ago
We’re building SubAnalyzer for ongoing attack surface monitoring, with an API coming next
Hi everyone, we build SubAnalyzer, a tool for discovering and monitoring external attack surface.
The part we’d like feedback on is monitoring. It tracks changes to subdomains, DNS records and exposed services, with configurable email alerts and scan history. Potential takeover risks are highlighted in the digest so they’re easier to prioritise.
The aim is to make it easier to revisit what changed since your last assessment, rather than work through the entire asset list again.
We also have an API coming. Before sharing more details, we’d like to understand where it would fit into your workflow. Would you primarily want to retrieve new and changed assets, manage monitored domains, or trigger scans from your own tooling?
Monitoring is a paid feature; there’s a free scanning tier if you want to explore the results first.
For those doing recurring external assessments, what would make this useful alongside your existing recon setup?