
Every tool for managing or discovering your attack surface runs on detection rules — but not all detection rules are equal. What actually matters is the quality of those rules and what they're built to detect. Where most EASM tools confirm a finding based on a single artefact, ShadowTrackr aims for three or more robust artefacts before confirming that a specific piece of software or an edge device is present. Where the data supports it, we go further still.
Sometimes there simply isn't enough evidence to be that certain — we might be able to identify a product but not its exact version. In those cases, we still surface what we've found. Our detection rules aren't static: we continuously review and update weaker or outdated rules as new evidence and techniques become available.
Not all exposed software carries the same risk, so our rule development effort isn't spread evenly. We prioritize detection of high-risk software and edge devices — routers, switches, VPN endpoints, and other remote login services — because that's where real-world attacks concentrate. If there's a vulnerability in JavaScript running on one of your websites, you'll hear about it. But the biggest exposure is almost always in things like exposed Juniper, Citrix, MySQL, MS RDP or similar services. We maintain a dedicated report focused specifically on these device categories, so you can see at a glance where you're carrying the most risk.
Detection isn't limited to what's running on your websites. For every host, ShadowTrackr checks open ports and identifies the software behind them — and that goes well beyond simple banner grabbing. We examine behavioral signals and binary fingerprints to identify what's actually there, including specific detail for SQL servers, RDP servers, DNS servers, and more.
We do not fire exploits. Mapping your attack surface thoroughly is one thing; disrupting your systems in the process is another, and in most jurisdictions firing exploits without prior written authorization is illegal regardless of intent. Continuous scanning and continuous exploitation are fundamentally incompatible — if you need exploit validation, that's a scoped penetration test or red team engagement, not continuous monitoring.
Everything ShadowTrackr's scanner nodes do falls within normal, legal internet traffic.
Reliable detection is only useful if it feeds into something actionable. Every confirmed software finding is automatically checked against ShadowTrackr's internal vulnerability database and scored for real-world risk — not just theoretical severity.
See how findings get matched to vulnerabilities and prioritized.
See how discovery decides what belongs in scope in the first place.