What problem does it solve?
Automated recon and ASM tools keyword-match on brand names, so for targets whose name is a common word, reports are dominated by assets belonging to unrelated same-named companies. Testing these assets wastes the engagement and risks attacking innocent third parties outside scope.
Core Features & Use Cases
- Ownership Verification Matrix: Per-source verification rules for GitHub repos, cloud buckets, mobile apps, breach combos, typosquats, and forum hits, requiring concrete ownership signals rather than scanner keyword matches.
- Soft-404 Detection: A curl-based control comparing suspected .env/.git/actuator exposures against junk-path responses to discard catch-all false positives.
- Triage Workflow: A five-step process covering canonical domain anchoring, per-asset verification, severity re-baselining, explicit quarantine logging, and meta-finding reporting.
- Use Case: You receive an ASM report showing hundreds of Criticals for a dictionary-word brand. Apply the ownership checks to quarantine unrelated repos, buckets, and apps, then re-baseline severity counts against only confirmed assets before testing anything.
Quick Start
Triage this ASM report and separate confirmed owned assets from same-named third-party collisions before I start testing.