Domains, subdomains & IP ranges
Identification of domains, subdomains, DNS records and ranges in scope – including entries discovered from public sources and certificates.
HybridSense AI orchestrates a curated stack of discovery, scanning and validation tools into a single external “run”. Instead of one-off scans, each run becomes a repeatable, explainable data point – so you can track progress over time.
Designed for both: traditional perimeters that need reliable monthly checks, and mixed IT/OT environments where an exposed gateway can affect physical processes.
Before we talk about vulnerabilities, we need to agree on what the outside world can actually see. HybridSense AI builds an inventory of exposed assets and services for each run, then compares it to the previous baseline.
Identification of domains, subdomains, DNS records and ranges in scope – including entries discovered from public sources and certificates.
Lightweight, safe port and service discovery to understand which services are reachable, and how they identify themselves to the internet.
Each run is compared to the previous baseline to surface new services, retired systems and configuration changes that may carry risk.
HybridSense AI prioritises checks that have a clear external impact: exposed admin interfaces, weak or broken TLS, default credentials, outdated components and unsafe configurations on gateways and remote access.
Focused on internet-facing web apps and APIs, including authentication, encryption and common misconfigurations.
External view of VPN endpoints, remote access portals and bastions – often the first stop for attackers targeting internal systems.
High-level checks on MX configuration and external posture to support phishing and spoofing risk assessments.
Focused on gateways, MQTT brokers, management portals and remote support paths that sit between the internet and OT or facilities networks.
Runs are carefully scoped and scheduled. You retain full control of timing, aggressiveness and which Vectors are active – especially important when OT is nearby.
We agree on targets, regions, maintenance windows and any zones that must be excluded or treated with extra caution (e.g. live OT gateways).
Asset and service discovery runs first, keeping activity as light as possible while building a useful picture of your perimeter.
For each in-scope Vector (Web, VPN, Email, OT edges, etc.) we run appropriate checks, tuned to avoid unnecessary noise or instability.
Where permitted, we can safely validate selected critical issues to confirm impact, always within agreed safety limits and windows.
Results are normalised, prioritised and exported into formats suitable for NEO dashboards, SIEM, ticketing and executive reporting.
The same engine serves small businesses, large enterprises and critical infrastructure – the difference is in scope, guardrails and depth per Vector.
| Scenario | Typical scope | Frequency | Primary Vectors |
|---|---|---|---|
| Small / branch perimeter | 1–2 domains, a few internet-facing services | Monthly or quarterly | Web, VPN / remote access, Email |
| Enterprise perimeter | Multiple domains, regions and environments | Monthly with ad-hoc runs on change | Web, VPN, Email, cloud edge & SSO |
| OT / SCADA & facilities | Gateways, telemetry paths, support access, portals | Quarterly or aligned with process windows | OT edges, Web, VPN, vendor access paths |
For AI risk, PQC and GRC specialists, HybridSense AI can quietly power the external technical view – leaving you free to focus on governance, strategy and business alignment.
Runs can be branded under your organisation while we operate the engine and reporting in the background.
Structured outputs for ingestion into your own portals, dashboards and GRC tooling.
From one-off perimeter reviews to ongoing programmes aligned with your own frameworks and methodologies.