Setting Up Your First Attack Surface Scan

A 20-minute walkthrough for getting your root domain into continuous, outside-in monitoring on the CyberNova platform.

Before you start

This walkthrough gets a root domain into continuous monitoring on the CyberNova Attack Surface Monitoring platform. It takes about 20 minutes and doesn’t require any agents, credentials, or network access — scanning is entirely outside-in.

Step 1: Add your root domain

From the platform dashboard, choose Add Asset and enter your organization’s root domain (for example, yourcompany.com). CyberNova automatically discovers subdomains, DNS records, and associated IP ranges from public sources — you don’t need to list them manually.

Step 2: Let discovery run

Initial discovery typically surfaces the first batch of assets within minutes. The platform continues to expand its map over the following hours as it correlates certificate transparency logs, DNS records, and routing data.

Step 3: Review your first findings

Findings are scored by exploitability and business impact, not just severity. Start with anything marked Critical or High — these are exposures an attacker would find first.

  • Open ports on unexpected services
  • Expired or misconfigured TLS certificates
  • Forgotten subdomains pointing to decommissioned infrastructure
  • Cloud storage buckets with public read access

Step 4: Connect it to your workflow

Under Integrations, connect Splunk, Microsoft Sentinel, Jira, or ServiceNow so new findings create tickets automatically instead of living only in a dashboard. From here, scanning is continuous — no need to re-run it manually.