ScanReview
Second path after EASM: map your attack surface with free tools — and know when managed monitoring is simpler.
Most small businesses should start with external attack surface management (EASM) — know what is internet-facing and when it changes. Open-source tools can map and test that same surface for free, but only if someone will install, schedule, interpret, and maintain the stack. This directory is for that DIY path.
Choose tools, install dependencies, configure targets safely, manage credentials, set schedules, and avoid noisy or risky scans.
Raw ports, banners, templates, CVE hints, and logs still need a human to decide what matters and what is expected.
False positives, duplicates, stale services, and informational noise can hide the few changes that need action.
Updates, scheduling, retention, report formatting, alert routing, and ownership when findings are unclear never stop.
Use the directory by job, not by “collect every tool.” For EASM-style work, start with discover → inspect → validate. Exploitation and heavy web testing are optional later steps, not the SMB starting line.
Find internet-facing systems, subdomains, and public signals — the discovery half of external attack surface work. 28 tools across 6 categories.
Browse tools →Ports, services, directories, and infrastructure detail — what is actually reachable on the assets you found. 24 tools across 7 categories.
Browse tools →Ethical validation frameworks for findings you already understand. Not the first step for most founders. 23 tools across 7 categories.
Browse tools →DAST, proxies, APIs, and app-focused checks once the external surface is known. 15 tools across 7 categories.
Browse tools →Managed EASM providers handle scheduling, diffs, and alerts. Compare tiers — or read when DIY should graduate.