
Asset discovery is where ShadowTrackr shines. Give it a starting point — a domain, a URL, an IP address, a subnet, or a mixed list of all of the above — and it starts mapping your related infrastructure automatically. No manual tagging of asset types required; ShadowTrackr sorts that out itself. Within minutes, the first results start appearing on your events timeline.
Finding an asset is the easy part. Knowing whether it actually belongs to your organization is the hard part — and it's where most EASM tools get sloppy. ShadowTrackr applies risk-based logic modeled on how an attacker would actually move through your infrastructure, rather than simple pattern matching.
A concrete example: if a server is confirmed as yours, any website with a vulnerability that could grant access to that server is treated as part of your attack surface — because an attacker would treat it that way too. On the other hand, finding one website on a specific subdomain doesn't automatically mean every subdomain of that domain belongs to you. Ownership isn't inferred more broadly than the evidence supports.
Some assets sit in a gray zone. When ShadowTrackr can't confidently attribute a new find, it goes into a dedicated suggestions index rather than your main inventory or reports. From there you can quickly disregard an entire domain, or all suggestions tied to a specific asset. If an asset you are not responsible for keeps reappearing you can set it to ignored, keeping it permanently out of scans and reports.
We recommend reviewing your suggestions periodically — it's the fastest way to keep your attack surface accurate without manual asset-by-asset upkeep.
More of your infrastructure lives in the cloud every year, and ShadowTrackr accounts for that. Our scanner nodes detect all common cloud platforms and monitor cloud-hosted assets precisely — without pulling your entire cloud environment into your attack surface just because one asset lives there. You also get reports on which clouds your assets have been found in, providing you insight into your overall cloud usage.
Some organizations track thousands, or tens of thousands, of assets. At that scale, oversight is the real challenge — so ShadowTrackr lets you tag assets and use those tags across queries, reports, and alerts to focus on exactly the slice of your attack surface you care about.
Tags can be inherited from domains and subnets, so newly discovered assets automatically land in the right custom reports without manual intervention. Some tags — mail servers, DNS servers, and similar infrastructure roles — are applied automatically by our scanner nodes.
A note for MSSPs: if you're managing multiple clients, tags aren't the right tool for separating them. ShadowTrackr supports true multi-tenant accounts, keeping each client's attack surface properly isolated.
Discovery is the starting point, not the end state. Once an asset is confirmed, ShadowTrackr continuously tracks the software running on it, checks it against known vulnerabilities, and scores the real-world risk using continuously updated threat data — not just a static severity rating.
Read how our continuously updated scoring works.
See how findings are prioritized and actioned.