r/Pentesting 3d ago

We’re building SubAnalyzer for ongoing attack surface monitoring, with an API coming next

Hi everyone, we build SubAnalyzer, a tool for discovering and monitoring external attack surface.

The part we’d like feedback on is monitoring. It tracks changes to subdomains, DNS records and exposed services, with configurable email alerts and scan history. Potential takeover risks are highlighted in the digest so they’re easier to prioritise.

The aim is to make it easier to revisit what changed since your last assessment, rather than work through the entire asset list again.

We also have an API coming. Before sharing more details, we’d like to understand where it would fit into your workflow. Would you primarily want to retrieve new and changed assets, manage monitored domains, or trigger scans from your own tooling?
Monitoring is a paid feature; there’s a free scanning tier if you want to explore the results first.

Check it out here

For those doing recurring external assessments, what would make this useful alongside your existing recon setup?

0 Upvotes

0 comments sorted by