S4E
S4E looks at your organisation from the outside, the way an attack starts, and tells you what the internet can already reach.
The alternative
Detectify, Intruder and CyCognito. The scope each covers differs, and so does the size of team each assumes.
At a glance
- Category
- Continuous threat exposure management, CTEM
- Deployment
- Runs as a service. No agent, nothing installed
- Onboarding
- A domain. Ownership proof unlocks the deeper checks
- Modules
- Opservant Agent, Spark Alerts, Security Playbooks, browser extension
- Coverage
- Subdomains, open ports, TLS certificates and ciphers, SPF, DKIM, DMARC, DNSSEC, technology fingerprinting, known vulnerabilities
- Alerts
- Email and Slack
- Plans
- A free tier, then paid tiers
An asset nobody remembers creating was never entered in the inventory. That is the one an attacker finds first.
Reconnaissance happens from outside, before anything else does. Which domains resolve, which server was left running after the project ended, which port stayed open, which certificate expired, whether the mail domain can be spoofed because nobody finished the DMARC record. An inventory list cannot answer those questions, because the asset that matters is the one that never reached the inventory.
What separates S4E is who it was designed for. It is built for an organisation with a small IT team, no dedicated security staff, and a public footprint anyway. There is no agent and no deployment. You give a domain and discovery starts.
That last point is also why this is the easiest product in the portfolio for a partner to open a conversation with. There is a free tier, so a partner walks into a first meeting with findings about the prospect's own domain rather than with a capability list. The conversation starts from something the buyer can check, and no procurement step had to happen first.
How it works
- Internet-facing assets are discovered, including ones on no inventory
- Subdomains, ports, certificates and mail records are checked continuously
- Known vulnerabilities and misconfigurations are identified
- Findings are prioritised into one console
- Alerts arrive by email or into the channel the team already watches
- A new asset is brought into scope automatically when it appears
Who it is for
- Mid-sized organisations with no dedicated security team
- Estates with a shadow IT problem and an incomplete inventory
- E-commerce and service companies with a large public footprint
- Partners who want to offer continuous monitoring as a service
What we can point to
- A free tier anyone can verify the product with before buying
Where it sits
Exposure and vulnerability. Of the products in that area, S4E is the one that needs no access to anything. It starts from a domain name and works inward from the public internet, which is where an attack starts too. Cyberthint, in threat intelligence, also looks from outside, but it is watching what is being said and sold about you rather than what is reachable.
