Do not scan first and sort later. CASP manually clarifies which public signals form a chain and which link is cheapest to break. Then you know whether an authorized penetration test, an IT security audit, or ongoing re-investigation is next.
FLAGSHIP · MANUAL · PASSIVE · DNS TXT · NDA
/ 01
Cyber Attack Surface Profiling (CASP)
Hybrid, passive OSINT investigation of your public attack surface by a named analyst with targeted automation. You see which public signals form attack chains — and get prioritized countermeasures in a signed management and technical report. Entry CASP Lite from EUR 7,500 or CASP Full EUR 19,900 (5 domains included).
Manually validated — no scanner dump
DETECT · COLLECT · PROTECT
Only owned or written-authorized domains
DNS TXT verification before start · NDA
Attack chains + prevention roadmap + score
Lite EUR 7,500 · Full EUR 19,900 · +Domain EUR 1,490
Authorized active testing when a system, web app, or cloud scope needs targeted verification. Penetration tests start only after written approval, clear rules of engagement, and reproducible evidence.
Structured assessment for security organization, controls, and evidence. Audits translate technical findings into verifiable actions for management, IT, customer questionnaires, and external review paths.
Executive Exposure for executives, founders, and key people: manual, passive OSINT on personal attack surface — from EUR 5,900 per person. Scope is named people, not domain packages. Optionally bundle with domain CASP.
from EUR 5,900 · 1 person · +EUR 2,900 each additional
Scope unit: person/role (not domain count)
Kickoff checklist: mandate, NDA, recipients, scope list
Drei Phasen, eine Untersuchung. Jeder Befund wird manuell ermittelt, quellenbasiert validiert, in Angriffsketten eingeordnet und mit Gegenmaßnahmen versehen — strikt passiv, ohne Scan und ohne Zugriff auf Ihre Infrastruktur.
/ 01 — DETECT
Discover
Manual identification of publicly available information across the approved scope: domains, subdomains, technology footprints, employee exposure, document leaks, credential breaches, and publicly visible organizational traces.
Surface web discoveryTechnology fingerprintingBreach database correlation
/ 02 — COLLECT
Triage
Konsolidierung und Korrelation verwertbarer Datenpunkte. Falsch-positive Befunde werden entfernt, Quellen nachvollziehbar dokumentiert, Risiken als realistische Angriffsketten formuliert — nicht als lose Liste.
Attackers often need only one entry. Defenders must secure everything. CASP models the chain and shows which link is fastest and cheapest to break — that is where prioritized measures start.
Strategic impact
DISCOVER
See what attackers see.
Validated visibility into your exposed attack surface based on publicly available information.
DISRUPT
Remove usable signals.
Prioritize exposed data and weak posture so teams can reduce the attack foundation deliberately.
DENY
Control recurrence.
Recurring cycles show whether risks return, disappear, or shift.
Review scope / 04
What the analyst reviews manually.
Sieben Kategorien, per Hand. No customer infrastructure is touched, scanned, or proxied. Only domains owned by the customer or with written authorization — verified by DNS TXT before start.
Assets & infrastructure
Owned domains, subdomains, IP ranges, ASNs, CIDR blocks, exposed services, and SSL/TLS posture.
Technologie-Footprint
Stack and version fingerprinting, end-of-life software, and exposed admin interfaces.
Domain & DNS-Posture
Registration data, DNS records, mail authentication, and clearly authorized domain relationships.
Credential & Email-Exposure
Leaked credentials in known breaches, exposed email patterns, and account takeover risk.
Document & data leaks
Public exposure of internal documents, source code, configuration, API keys, and secrets.
Human Footprint
Executives and key personnel, social-engineering vectors, and insider indicators.
Threat context
Industry-specific threat actors, recent incidents in adjacent organizations, and active campaigns.
Process & reports / 05
From approved scope to signed report and score.
Every engagement follows the same logic: clarify scope and authorization, investigate hybrid and passively, prioritize findings, hand over measures and score. Re-investigation cycles update score, findings, and trends as needed.
/ 01 — Tag 0–3
Onboarding
Scope for owned or authorized domains, brands, and relevant executives. Threat-model intake. Mutual NDA. DNS TXT verification of domain authorization before start.
Scope-DocDNS-TXTNDA
/ 02 — Tag 3–10
Investigation
Manual OSINT across all categories. Source corroboration, false-positive elimination, customer-specific attack chains, industry and role context.
Manual OSINTChain modelingContext mapping
/ 03 — Tag 10–14
Delivery
Intelligence report (exec + tech), briefing call, Breach Probability Score with baseline, prioritized prevention roadmap.
Report (PDF)Briefing 60–90 minScore + Roadmap
/ 04 — Recurring
Re-investigation
After Lite or Full: one run per chosen interval (30 / 90 / 180 days or ad-hoc). Net-new, re-verification, score and trend — EUR 4,500 per run.
Technical findings reportPDF · complete · security team
Attack scenariosNarrative + diagrams · both audiences
Prevention-RoadmapPrioritized actions · security team
Breach Probability Score1.0–10.0 · getrendet · C-Suite
Compliance evidenceNIS2 · DORA · ISO 27001 · SOC 2
Briefing-Call60–90 Minuten · zielgruppenoffen
BREACH PROBABILITY SCORE
1.0–10.0
Scale · SECURED to CRITICAL
SECUREDCRITICAL
A board-grade single metric for public breach exposure — signed by the analyst and updated each cycle. Management and security share the same status over time.
8.0–10.0CRITICAL — immediate action
6.0–7.9HIGH RISK — multiple exposures
4.0–5.9MODERATE — manageable risk
2.0–3.9LOW — proactive posture
1.0–1.9SECURED — minimal visibility
Warum CASP / 06
Why manual reconnaissance belongs before scanners and one-off tests.
Scanners produce volume. Pentests actively test an approved scope. Audits review governance. CASP sits before that: it places public information into realistic attack chains and shows which next test or evidence path is worth it.
Automated ASM tools
Broad hit lists, often noise — without business priority or a resilient chain.
CASP → CASP validates manually and translates findings into risk and action logic. Nothing raw from the tool.
Penetration Tests
Valuable with a clear scope — but active and costly when the test space is unclear.
CASP → CASP sharpens the test space first and avoids unnecessary active tests.
Classic audits
They review processes and evidence — not what attackers can combine publicly.
CASP → CASP adds outside-in evidence and prioritized technical findings.
TXTScope verificationbefore every analysis starts
1named analystvon Scope bis signiertem Report
3target audiencesmanagement, IT, and compliance
Which test when? / 07
Which engagement answers which risk.
Threat class
CASP
Pentest
Audit
Leaked credentials & data breaches
·
·
Exposure of domains, DNS, and subdomains
·
·
Webapp-Schwachstellen (SQLi, IDOR, SSRF)
·
·
Cloud-Misconfigurations (S3, IAM, Lambda)
·
Executive & employee exposure
·
·
Document & source leaks
·
·
Compliance & NIS2 / DORA / ISO 27001 / SOC 2
·
·
Typical use cases
Control ongoing exposurePrioritize credential leaksExecutive & key-person exposureM&A: public risks before purchase or investmentCover holdings, brands, and PE portfoliosEvidence NIS2 · DORA · ISO 27001 · SOC 2Post-incident: outside-in posture after an incident
Evidence for NIS2, DORA, ISO 27001, and SOC 2 — outside-in and traceable.
CASP does not replace legal advice, a certification audit, or a pentest. It delivers repeatable, signed evidence: which external attack surface is visible, which risks follow, and which measures were pursued.
NIS2
Make risk management and technical measures provable.
CASP supports NIS2 preparation by documenting external exposure, usable attack paths, priorities, and countermeasures. This does not replace legal advice, but it creates resilient evidence for risk and action communication.
public attack surface
prioritized countermeasures
management and technical report
DORA
Make ICT risks and third-party exposures tangible for financial actors.
For DORA-relevant organizations, CASP documents the publicly visible digital attack surface, usable attack chains, and prioritized remediation — as outside-in evidence for ICT risk management and supervisory communication. Not a legal opinion and not an audit substitute.
ICT-relevant exposure overview
Attack chains with priority
signed report per cycle
ISO 27001
Provide input for risk analysis, asset visibility, and treatment.
An ISMS needs traceable risks and documented treatment. CASP complements that work with an outside-in view of external assets, DNS/domain posture, credential exposure, and remediation history.
Exposure-Register
Finding history
Remediation recheck
SOC 2
Answer trust questions about security controls more concretely.
For SOC 2 and customer questionnaires, CASP provides traceable evidence that external attack surface is reviewed, assessed, and improved regularly. It is not a replacement for attestation, but an operational evidence component.
repeatable re-investigation
score and trend
signed report
Frame: Strikt passiv. Nur eigene oder schriftlich autorisierte Domains. DNS-TXT-Verifikation vor Start.
Next step
Ready for a scope meeting?
Entry CASP Lite from € 7.500 oder CASP Full € 19.900 (5 Domains inkl., +€ 1.490 je weitere). Re-Investigation € 4.500 pro Durchlauf — Abstand 30 / 90 / 180 Tage oder ad-hoc. Report in ≤14–21 Tagen nach Onboarding und Freigabe. Wir starten mit Domains, NDA und DNS-TXT — nicht mit einem Blind-Scan.