Features
Seven risk categories. One scan.
SurfaceLoop discovers your internet-facing assets and scans them across every category that matters — simultaneously, continuously, from the outside.
01
Open Ports & Services
Discover and monitor open TCP ports and exposed services across your external attack surface.

02
Exposed Web Panels
Detect admin panels, management interfaces, and login pages exposed to the public internet.
Jenkins dashboard accessible without authentication
staging.example.com:8080
phpMyAdmin login page exposed to public internet
db.example.com
Fortinet SSL VPN login page — version fingerprint visible
vpn.example.com
Example findings from a real report
03
TLS & Certificates
Monitor TLS configuration, certificate expiry, weak ciphers, and chain-of-trust issues.

04
Security Headers
Check HTTP security headers including CSP, HSTS, X-Frame-Options, and Permissions-Policy.
Missing Content-Security-Policy — no XSS protection
app.example.com
Missing Strict-Transport-Security — vulnerable to SSL stripping
staging.example.com
Referrer-Policy not set — leaking URL paths to third parties
app.example.com
Example findings from a real report
05
Known Vulnerabilities (CVEs)
Scan for known CVEs and exploitable vulnerabilities using thousands of detection templates.
Palo Alto PAN-OS command injection — unauthenticated RCE via GlobalProtect
CVE-2024-3400 · 10
FortiOS out-of-bounds write — remote code execution, actively exploited
CVE-2024-21762 · 9.8
HTTP/2 Rapid Reset — denial of service via stream cancellation flood
CVE-2023-44487 · 7.5
Example findings from a real report
06
DNS & Email Spoofing
Validate SPF, DKIM, and DMARC configuration to prevent domain spoofing and phishing.
DMARC policy set to p=none — domain can be spoofed freely
example.com
SPF record includes +all — permits any server to send as your domain
example.com
DKIM selector 'default' uses 1024-bit key — upgrade to 2048-bit
example.com
Example findings from a real report
07
Subdomain Enumeration
Discover subdomains, shadow IT, forgotten services, and development environments exposed to the internet.
Read the full guide →Subdomain points to decommissioned S3 bucket — takeover possible
legacy.example.com
Development server with debug mode enabled — stack traces visible
test.example.com
Monitoring dashboard accessible without VPN — internal metrics exposed
grafana.example.com
Example findings from a real report
Across every category
Capabilities that apply to all seven.
Continuous scanning
Automated rescans on your schedule. New exposures trigger alerts the moment they appear — not at the next quarterly review.
Severity prioritisation
Findings ranked by real-world exploitability. Critical exposures surface first so your team fixes what matters.
Change tracking
Every scan compared against the last. See what opened, what closed, and what changed — with full history.
Alert routing
Findings delivered where your team works. Email, Slack, webhooks — configured per severity level.
Zero deployment
Pure external scanning from the attacker's perspective. No agents, no firewall changes, no internal access.
API access
Full REST API for every scan result. Integrate findings into your existing security tooling and workflows.
See what's exposed on your attack surface
Add your domains. SurfaceLoop scans all seven categories and shows you what to fix first.