bannerbanner
Icon Onyphe Powerful Features

Mapping Adversary Infrastructure at Internet Scale

Threat actors leave footprints. Command-and-control nodes, phishing infrastructure, malicious hosting: it all shows up in Internet scan data if you know where to look. ONYPHE gives CTI analysts current data and pivoting depth to find it, track it, and act on it.

Data freshness:
Weekly full-Internet scans, twice-weekly on the top 100 ports. Adversary infrastructure changes don't go unnoticed.

Pivot quickly: Move from an IP to an ASN to a hosting pattern in seconds.

Global vantage points: 
Scans from the US, Europe, and Asia surface infrastructure that looks different depending on where you're looking from.

Attack Surface Management

ONYPHE's ASM Edition adds asset tracking, alerting workflows, and
historical coverage on top of its vulnerability and risk datasets.

Slide Image
Slide Image
Slide Image

Vulnscan

160+ actively-exploited CVEs checked against your exposed services. Detection logic built in-house from sanitized public PoCs, covering every CVE on the CISA Known Exploited Vulnerabilities list.

Riskscan

Every exposed service checked against known-risky configuration baselines. RDP open to the internet, VPN endpoints with known weaknesses, admin interfaces in unexpected places. Flagged before attackers find them.

Continuous asset tracking

Your attack surface changes constantly. New subdomains appear, services get forgotten, acquisitions bring in unknown infrastructure. ONYPHE tracks your digital footprint and alerts your team when exposure changes.

Icon Onyphe real numbers by onyphe

Big Data, Fast

0.1 second

API response time

20+ billion

banners collected monthly

10+ billion

DNS entries monthly

4500+

ports scanned

See Beyond Your Own Perimeter

ONYPHE ASD data lets you map Internet exposure across your organisation, your supply chain, and anyone else that matters to your risk picture.

Your organisation and everyone connected to it

Most ASD tools only find what you point them at. ONYPHE scans the entire Internet, so you discover the assets you didn't know to look for.

IP-based ASM is obsolete

Identifying assets by IP address alone misses too much. ONYPHE binds every asset to a domain name, so you can pivot across an organisation's full infrastructure and surface exposure that IP-based approaches won't find.

Affordable plans Customer RelationshipsPlans that fit every stage Built to scale with your needs Control and Customization

Build your inventory your way

Your asset inventory can be as simple as a single domain name or as broad as thousands of domains, subject organisation fields, subnets, and ASNs. From that inventory, ONYPHE derives the full list of associated FQDNs and IP addresses, so you always have a current, accurate picture without maintaining exhaustive lists by hand.

Try it with a single domain

Stay on top of what's exposed

Once your inventory is defined, ONYPHE does the hard work. Query our API hourly to catch new findings as they emerge, or let ASM Edition stream alerts directly to your dedicated environment. Refreshing the inventory itself takes little effort. Most teams revisit it annually, so it adds minimal overhead to any security programme.

What is Attack Surface Discovery?

Attack Surface Discovery

Know what's exposed
Act before it matters

ONYPHE provides solutions dedicated to Attack Surface Discovery (ASD), Attack Surface Management (ASM) and Cyber Threat Intelligence (CTI).

Scanning at Internet-scale IPs and URLs since 2017.

Don't let unknown assets become your next breach vector. Contact us today!

Hunt Threats. Track Infrastructure.
Follow the Evidence.

Internet mapping and Passive DNS for analysts who need to find adversary infrastructure and follow it.

feature

No Easy Hiding Places.

Full URL scanning with redirect chain traversal, deep TCP and UDP port scanning across the IPv4 space, and hundreds of millions of IPv6 hosts scanned weekly. Adversary infrastructure has fewer places to hide than you might think.

feature

12 Months of Passive DNS

Domain infrastructure changes constantly. ONYPHE's 12-month Passive DNS database lets analysts reconstruct how adversary infrastructure evolved over time, connecting current indicators to historical patterns and past campaigns.

feature

Track. Pivot. Attribute.

Adversary infrastructure doesn't stay still, but it leaves traces. ONYPHE's deep Internet mapping lets analysts pivot across IPs, domains, and hosting patterns to track infrastructure across campaigns and connect current activity to past behaviour.

Icon Onyphe Frequently Asked Question

Questions about ONYPHE?

Our team can walk you through our products and help you work out which solution fits your needs.

Yes. API access is our primary use case. We provide a REST API that returns JSON.

We scan the full IPv4 address space (~3.8 billion unique IPs) and a significant portion of the IPv6 address space based on DNS-observed addresses, covering hundreds of millions of IPv6 hosts weekly. All data includes an IPv6 field indicating whether the record relates to an IPv4 or IPv6 address. DNS resolution is performed for both IPv4 and IPv6 across all relevant data categories.

We currently scan over 4,500 TCP ports, with the list growing regularly. The complete list is available in our documentation. New ports are added when they are observed being actively exploited in the wild.

Yes, we scan both TCP and UDP. For UDP, we send an application-layer payload, as this is the only reliable way to confirm a service is listening. For example, we send a DNS request to port 53/UDP, and if we receive a valid DNS reply, the port is confirmed open and the protocol is identified as 'dns'.

We operate scanners in Europe, the United States, and Asia. Scanning from multiple geographic locations allows us to capture different views of exposed infrastructure. Some assets present differently depending on where the request originates. Results can be filtered by scanner location.

Yes, through two sources. Our datascan category captures certificate data by negotiating TLS connections on relevant ports. We also index Certificate Transparency Logs (CTL), which are a valuable source of DNS-related intelligence and domain infrastructure visibility.

Yes. For synscan data, we provide OS fingerprinting (Linux, Windows, FreeBSD, SunOS, and others). In the datascan category, we identify software and hardware technologies using CPE normalisation, covering approximately 80,000 software products. We also perform CVE lookups to flag potential vulnerabilities. We only include CVEs that are remotely exploitable without authentication and carry a CVSS score of 7.5 or higher.

Yes. We use a tagging system to flag weaknesses such as open web directories, unauthenticated services, exposed databases, and many others. For example, filtering on 'tag:opendir' returns assets with open web directories, while 'tag:open device.class:database' surfaces exposed databases accessible without authentication.

Yes. We actively check for the presence and absence of critical vulnerabilities, specifically those being exploited by threat actors in the wild. We currently check for 160+ CVEs, with the list growing continuously. All checks are developed in-house based on public proof-of-concept code, and are strictly non-intrusive.

Yes. All data is enriched with geolocation, including an organisation field identifying the hosting provider or datacenter. We also include ASN information, forward DNS, and reverse DNS records.

Yes. We include the raw response data in full, up to 1MB per record. This field supports free-text search, making it possible to query response content much like a web search engine.

We currently identify 70+ protocols, with the goal of enabling accurate device and service classification. Protocol identification also means we detect services running on non-standard ports. For example, an SSH service running on a port other than the default 22.

Refresh rates vary by data category. Datascan is refreshed weekly. Vulnscan is refreshed weekly. Ctiscan is refreshed twice a week for the top 100 ports, and weekly for the remaining ports. Threatlist is refreshed daily. Other categories are updated on a continuous basis.

Yes. Historical depth varies by product: from one month for our CTI dataset up to four years for our ASM datasets. You can pivot on any field to identify previously observed data across the full history available for that dataset.

Yes. For full dataset access, we offer raw data feeds. Please contact us at sales[at]onyphe{dot}io for pricing. For partial exports, the Export API allows you to retrieve targeted subsets of data, while the Bulk API supports high-volume query workloads.