Skip to content
Best Practices

CTEM in SecTepe SnapScan: Continuous Attack-Surface Validation & Passive OSINT

SecTepe Editorial
|
|
6 min read

An attack surface is not a photo but a film: new subdomains, changed services, freshly published CVEs shift the picture daily. A one-off annual pentest cannot keep up. SecTepe SnapScan answers this with a Continuous Threat Exposure Management (CTEM) approach – plus two new reconnaissance paths that close previously blind spots.

The CTEM Loop: Scope, Discover, Validate, Prioritize, Mobilize

Via the ScanSchedule model, scans can be repeated on a fixed cadence, so exposure is continuously revalidated. This follows the classic CTEM cycle:

  1. Scope – define what belongs to the attack surface.
  2. Discover – continuously discover assets and services.
  3. Validate – check what of it is actually exposed and exploitable.
  4. Prioritize – prioritize by real risk.
  5. Mobilize – turn the results into action: as GRC evidence in SecTepe.Core.

A dedicated KPI view at /console/ctem makes progress visible over time – not just the current scan, but the trend.

Passive OSINT Footprint Engine: Reconnoiter Without Touching

Not every reconnaissance is allowed to touch the target – for example in early proposal phases or with third-party assets. The new passive OSINT footprint engine therefore works purely passively: it gathers publicly available information about the attack surface without actively contacting the target. That is legally clean and still delivers a solid first picture of exposure.

Tor/Onion Scanning for Hidden Services

Some attack surface does not sit in the clearnet: leak portals, hidden services, exposed onion endpoints. SnapScan can now scan .onion targets over a SOCKS proxy (with its own Dockerfile.tor and Compose setup). This makes it possible to check whether your own services are inadvertently reachable over Tor – or whether infrastructure related to your company shows up on the dark web.

Note: the internal cloud security posture check (CSPM) is designed as a building block and is activated per cloud provider once a customer supplies credentials – an outlook, not a finished multi-cloud scanner.

Why These Belong Together

CTEM without good reconnaissance validates an incomplete scope; passive OSINT and onion scanning extend exactly that scope. Together with the AI pentest agent for depth and rapid response for new CVEs, this creates a loop that continuously keeps exposure small.

Conclusion

With scheduled repeat scans, a KPI view, and two new passive reconnaissance paths, SnapScan moves from a point-in-time tool to continuous exposure management. That is exactly what frameworks like NIS-2 expect when they demand "ongoing" risk monitoring.