

Threat actors leave footprints. Command-and-control nodes, phishing infrastructure, malicious hosting: it all shows up in Internet scan data if you know where to look. ONYPHE gives CTI analysts current data and pivoting depth to find it, track it, and act on it.
Data freshness:
Weekly full-Internet scans, twice-weekly on the top 100 ports. Adversary infrastructure changes don't go unnoticed.
Pivot quickly: Move from an IP to an ASN to a hosting pattern in seconds.
Global vantage points:
Scans from the US, Europe, and Asia surface infrastructure that looks different depending on where you're looking from.
ONYPHE's ASM Edition adds asset tracking, alerting workflows, and
historical coverage on top of its vulnerability and risk datasets.
160+ actively-exploited CVEs checked against your exposed services. Detection logic built in-house from sanitized public PoCs, covering every CVE on the CISA Known Exploited Vulnerabilities list.
Every exposed service checked against known-risky configuration baselines. RDP open to the internet, VPN endpoints with known weaknesses, admin interfaces in unexpected places. Flagged before attackers find them.
Your attack surface changes constantly. New subdomains appear, services get forgotten, acquisitions bring in unknown infrastructure. ONYPHE tracks your digital footprint and alerts your team when exposure changes.
ONYPHE ASD data lets you map Internet exposure across your organisation, your supply chain, and anyone else that matters to your risk picture.
Most ASD tools only find what you point them at. ONYPHE scans the entire Internet, so you discover the assets you didn't know to look for.
Identifying assets by IP address alone misses too much. ONYPHE binds every asset to a domain name, so you can pivot across an organisation's full infrastructure and surface exposure that IP-based approaches won't find.
Your asset inventory can be as simple as a single domain name or as broad as thousands of domains, subject organisation fields, subnets, and ASNs. From that inventory, ONYPHE derives the full list of associated FQDNs and IP addresses, so you always have a current, accurate picture without maintaining exhaustive lists by hand.
Once your inventory is defined, ONYPHE does the hard work. Query our API hourly to catch new findings as they emerge, or let ASM Edition stream alerts directly to your dedicated environment. Refreshing the inventory itself takes little effort. Most teams revisit it annually, so it adds minimal overhead to any security programme.
ONYPHE provides solutions dedicated to Attack Surface Discovery (ASD), Attack Surface Management (ASM) and Cyber Threat Intelligence (CTI).
Scanning at Internet-scale IPs and URLs since 2017.
Internet mapping and Passive DNS for analysts who need to find adversary infrastructure and follow it.

Full URL scanning with redirect chain traversal, deep TCP and UDP port scanning across the IPv4 space, and hundreds of millions of IPv6 hosts scanned weekly. Adversary infrastructure has fewer places to hide than you might think.

Domain infrastructure changes constantly. ONYPHE's 12-month Passive DNS database lets analysts reconstruct how adversary infrastructure evolved over time, connecting current indicators to historical patterns and past campaigns.

Adversary infrastructure doesn't stay still, but it leaves traces. ONYPHE's deep Internet mapping lets analysts pivot across IPs, domains, and hosting patterns to track infrastructure across campaigns and connect current activity to past behaviour.
Our team can walk you through our products and help you work out which solution fits your needs.
Yes. API access is our primary use case. We provide a REST API that returns JSON.
We scan the full IPv4 address space (~3.8 billion unique IPs) and a significant portion of the IPv6 address space based on DNS-observed addresses, covering hundreds of millions of IPv6 hosts weekly. All data includes an IPv6 field indicating whether the record relates to an IPv4 or IPv6 address. DNS resolution is performed for both IPv4 and IPv6 across all relevant data categories.
We currently scan over 4,500 TCP ports, with the list growing regularly. The complete list is available in our documentation. New ports are added when they are observed being actively exploited in the wild.
Yes, we scan both TCP and UDP. For UDP, we send an application-layer payload, as this is the only reliable way to confirm a service is listening. For example, we send a DNS request to port 53/UDP, and if we receive a valid DNS reply, the port is confirmed open and the protocol is identified as 'dns'.
We operate scanners in Europe, the United States, and Asia. Scanning from multiple geographic locations allows us to capture different views of exposed infrastructure. Some assets present differently depending on where the request originates. Results can be filtered by scanner location.
Yes, through two sources. Our datascan category captures certificate data by negotiating TLS connections on relevant ports. We also index Certificate Transparency Logs (CTL), which are a valuable source of DNS-related intelligence and domain infrastructure visibility.
Yes. For synscan data, we provide OS fingerprinting (Linux, Windows, FreeBSD, SunOS, and others). In the datascan category, we identify software and hardware technologies using CPE normalisation, covering approximately 80,000 software products. We also perform CVE lookups to flag potential vulnerabilities. We only include CVEs that are remotely exploitable without authentication and carry a CVSS score of 7.5 or higher.
Yes. We use a tagging system to flag weaknesses such as open web directories, unauthenticated services, exposed databases, and many others. For example, filtering on 'tag:opendir' returns assets with open web directories, while 'tag:open device.class:database' surfaces exposed databases accessible without authentication.
Yes. We actively check for the presence and absence of critical vulnerabilities, specifically those being exploited by threat actors in the wild. We currently check for 160+ CVEs, with the list growing continuously. All checks are developed in-house based on public proof-of-concept code, and are strictly non-intrusive.
Yes. All data is enriched with geolocation, including an organisation field identifying the hosting provider or datacenter. We also include ASN information, forward DNS, and reverse DNS records.
Yes. We include the raw response data in full, up to 1MB per record. This field supports free-text search, making it possible to query response content much like a web search engine.
We currently identify 70+ protocols, with the goal of enabling accurate device and service classification. Protocol identification also means we detect services running on non-standard ports. For example, an SSH service running on a port other than the default 22.
Refresh rates vary by data category. Datascan is refreshed weekly. Vulnscan is refreshed weekly. Ctiscan is refreshed twice a week for the top 100 ports, and weekly for the remaining ports. Threatlist is refreshed daily. Other categories are updated on a continuous basis.
Yes. Historical depth varies by product: from one month for our CTI dataset up to four years for our ASM datasets. You can pivot on any field to identify previously observed data across the full history available for that dataset.
Yes. For full dataset access, we offer raw data feeds. Please contact us at sales[at]onyphe{dot}io for pricing. For partial exports, the Export API allows you to retrieve targeted subsets of data, while the Bulk API supports high-volume query workloads.