Domains & DNS
Newly registered subdomains, dangling CNAMEs to SaaS tenants you cancelled, expired records still resolving, hijackable registrar logins.
Forewatch runs a 24/7 AI monitoring agent across every domain, subdomain, exposed cloud bucket, stale DNS record, dangling SaaS integration, and harvested credential your company touches. Every morning at 7am you get one plain-English brief: what changed overnight, what is most likely to be weaponised, and what to do about it with the smallest reasonable step.
3 things changed overnight. 1 is likely weaponisable.
No dashboards to log into, no jargon to triage, no Slack thread your security contractor starts at 11pm. The brief is a short, opinionated document: three things changed overnight, ranked, each with the smallest reasonable step back to green. Below is the actual layout — switch categories to see how the same shape covers different parts of your attack surface.
Newly registered, expired, dangling, hijackable
Sample records · real engagements anonymisedCNAME pointed to a marketing SaaS you cancelled 9 months ago
Weaponisable — Attacker re-registers the SaaS tenant and rides your brand.
Newly added subdomain exposing a marketing preview tool
Weaponisable — OAuth abuse against newsletter subscribers via misconfigured preview app.
2 wildcard certs still valid on zones without live traffic
Weaponisable — Mis-issuance by a CA — your users trust them for a year.
The external attack surface market is projected to grow from $1.32B in 2024 to $6.87B by 2030. The reason — every company is now a SaaS-and-cloud-and-API-sprawl company, and the stale-pivot / dangling-CNAME / forgotten-OAuth-app plays keep landing on the front page. Forewatch compresses the asset discovery, leak harvesting, dedupe, and triage playbooks enterprise EASM vendors charge six figures for into one background service.
Newly registered subdomains, dangling CNAMEs to SaaS tenants you cancelled, expired records still resolving, hijackable registrar logins.
Public S3, R2, GCS, Azure blobs that became world-listable after a Terraform drift; SAS-token leakage; old prod buckets still serving files.
Pastebins, stealer logs, GitHub history, employee pivots — surfaced and rotated, with SSO session revocation as the default first step.
Zapier and Make webhooks nobody owns, retired OAuth apps still refreshing, "Anyone with the link can edit" docs leaking runbooks.
Forewatch seeds an AI-driven enumerator across your domains, ASNs, login flows, and known SaaS footprint. It runs in the same way an attacker would: subdomain brute-force, CT-log watching, GitHub-code search, bucket-list scripts.
A billion raw signals means nothing. Forewatch folds every new event into a known-asset graph, deduplicates against the last 30 days, and tags anything genuinely novel so the brief only contains things that actually changed.
The morning brief is two pages, opinionated, ranked, each finding carrying the smallest reasonable remediation step. Tickets route into Jira, Linear, GitHub Issues, or plain email — whichever your team actually opens.
Gauntlet-tier EASM — Bitsight, CyCognito, Outpost24, ProjectDiscovery — assumes you have a SOC analyst on staff to wire, tune, and triage the platform. We reverse the assumption: a 10-person team should be able to log in on Tuesday, point Forewatch at their domains, and read their first brief on Wednesday.
Sources: ESG 2025 attack-surface survey · IDC EASM 2024–2030 forecast · internal customer pilots.
Pick the tier that covers your domain count. Every tier includes the morning brief, dupe-dedupe, and ticket routing into Jira, Linear, GitHub Issues, or plain email. Need deeper coverage or vendor risk scoring? Email us.
Solo founder or small SaaS, ≤ 6 monitored domains.
10–50-person teams wanting bucket, credential, and SaaS coverage too.
100+ employee orgs with multiple domains, brands, and subsidiaries.
Every tier includes daily plain-English brief and ticket routing. Pricing below enterprise EASM list price — no surprise renewal, no per-asset add-on, no SOC-analyst seat in the math.
If your question is not here, write to forewatch-7@polsia.app.
Neither in the traditional sense. An MSSP needs a SOC analyst; an EASM platform needs one to operate it well. Forewatch runs the discovery, dedupe, and brief-generation logic on its own, so a 10-person team can use it without hiring security headcount. If you already have a SOC, Forewatch complements them by removing the boring first-lap enumeration work.
A short, opinionated document. Every changed item gets ranked (critical / high / medium / low), each finding has a one-paragraph weaponisation explanation, and each carries a single smallest reasonable step back to green. Tickets route into Jira, Linear, GitHub Issues, or plain email — whichever your team actually opens. See a sample layout in the brief section above.
Enumeration runs continuously. CT-log watching is near-real-time. Stealer-log harvesting polls every 6 hours. The brief at 7am covers the prior 18-hour window.
Passive by default — Forewatch observes what is already publicly exposed and what an attacker would see. We do not run brute-force login attempts, exploit chains, or denial-of-service tests. A scoped active-mode is available on Scale if you want us to probe specific surfaces, run with full authorisation and audit log.
The brief is one document per morning — that is it. If you turn on Slack alerts, you control the channel and threshold. We do not push marketing email and we do not have a sales-development team working the trial. The product is the conversation.
They each cover parts of this surface well, at enterprise price points and with an operating model that assumes you have a SOC analyst on staff. Forewatch is opinionated about the SMB/launching-team shape — same discovery, same dedupe, same brief-shaped output, no analyst in the math.
We start every engagement with a 20-minute call, then run a free three-week pilot across the assets you already have. No setup fee, no contract, no SOC analyst in the loop.