An attack surface is not a photo but a film: new subdomains, changed services, freshly published CVEs shift the picture daily. A one-off annual pentest cannot keep up. SecTepe SnapScan answers this with a Continuous Threat Exposure Management (CTEM) approach – plus two new reconnaissance paths that close previously blind spots.
The CTEM Loop: Scope, Discover, Validate, Prioritize, Mobilize
Via the ScanSchedule model, scans can be repeated on a fixed cadence, so exposure is continuously revalidated. This follows the classic CTEM cycle:
- Scope – define what belongs to the attack surface.
- Discover – continuously discover assets and services.
- Validate – check what of it is actually exposed and exploitable.
- Prioritize – prioritize by real risk.
- Mobilize – turn the results into action: as GRC evidence in SecTepe.Core.
A dedicated KPI view at /console/ctem makes progress visible over time – not just the current scan, but the trend.
Passive OSINT Footprint Engine: Reconnoiter Without Touching
Not every reconnaissance is allowed to touch the target – for example in early proposal phases or with third-party assets. The new passive OSINT footprint engine therefore works purely passively: it gathers publicly available information about the attack surface without actively contacting the target. That is legally clean and still delivers a solid first picture of exposure.
Tor/Onion Scanning for Hidden Services
Some attack surface does not sit in the clearnet: leak portals, hidden services, exposed onion endpoints. SnapScan can now scan .onion targets over a SOCKS proxy (with its own Dockerfile.tor and Compose setup). This makes it possible to check whether your own services are inadvertently reachable over Tor – or whether infrastructure related to your company shows up on the dark web.
Note: the internal cloud security posture check (CSPM) is designed as a building block and is activated per cloud provider once a customer supplies credentials – an outlook, not a finished multi-cloud scanner.
Why These Belong Together
CTEM without good reconnaissance validates an incomplete scope; passive OSINT and onion scanning extend exactly that scope. Together with the AI pentest agent for depth and rapid response for new CVEs, this creates a loop that continuously keeps exposure small.
Conclusion
With scheduled repeat scans, a KPI view, and two new passive reconnaissance paths, SnapScan moves from a point-in-time tool to continuous exposure management. That is exactly what frameworks like NIS-2 expect when they demand "ongoing" risk monitoring.