Skip to main content

Ore Hammer Surface — adversarial attack surface monitoring

See yourself the wayan adversary does.

Ore Hammer Surface continuously examines your external attack surface, discovers exploitable paths, connects them to real-world threat context, and tells you what an attacker is most likely to do next—and what you should fix first.

Contact us to get a trial started. Self-service coming soon.

Watch

See your attack surface as adversaries see it.

The problem

You cannot defend a surface you have not finished counting.

External attack surface is the one part of your estate you do not control the growth of. Marketing stands up a subdomain, a team ships a staging host, an acquisition arrives with its own infrastructure. The list is never current, and the list was never the point anyway.

The inventory is always stale

A quarterly scan describes an estate that no longer exists. Discovery has to run at the speed the estate changes.

Findings are not paths

A list of exposed services tells you nothing about whether any of them reach something that matters. Attackers chain; scanners enumerate.

Severity is not priority

A critical CVE on an unreachable host outranks nothing. Priority comes from what the weakness enables, not from its score.

Nobody re-tests the fix

The change lands, the ticket closes, and no one proves the path is actually gone — or notices when it returns.

What it does

What Ore Hammer Surface does

  1. Continuous external discovery

    Domains, subdomains, exposed services, forgotten staging hosts, third-party surface. The map is rebuilt as your estate changes, not once a quarter.

  2. Exploitable path discovery

    Agents chain weaknesses the way an adversary would — an exposed edge, a weak identity, a reachable workload — and surface the path, not the parts.

  3. Real-world threat context

    Rich, comprehensive threat intelligence that tracks actors, campaigns, KEV, EPSS and IOCs from multiple sources and curates them into an actor dossier aligned with your industry sector. Every path is read against what attackers are actually doing to organizations like yours — the graph and the threats are built on your unique context, not a generic feed.

  4. What to fix first

    One ranked answer: the change that removes the most paths to compromise, with the evidence behind it and the way to verify it later.

How it reasons

From a surface, to a path, to the one fix that breaks it.

Three diagrams, not screenshots. The product demo shows the real interface.

Kill-chain coverage — observed attacker stages across the surface
  • REReconone
  • RDResource devno signal
  • IAInitial accesstwo
  • EXExecutionno signal
  • PEPersistenceone
  • PRPriv escno signal
  • CACred accesssix
  • DIDiscoverytwo
  • LMLateralno signal
  • COCollectionthree
  • EFExfiltrationno signal
  • IMImpactno signal

Coverage is reported honestly: where a stage was never observed, it says so rather than reading as clean.

One path, four hops
  1. ENTRY POINTPublic compute instanceReachable from the internet, in a public subnet.
  2. CHOKE POINTCluster node roleThe identity the instance can assume.
  3. CHOKE POINTOver-permissive policyGrants more than the workload needs.
  4. TARGETConcrete dataObject storage, secrets, registry access.

A path is only interesting if it ends somewhere that matters. Ore Hammer scores the route, not the individual weaknesses.

Fix next — ordered by paths removed
  1. NOWClose public access on the exposed compute instancesbreaks twenty paths
  2. NOWScope the cluster node role to what the workload usesbreaks seven paths
  3. NEXTPatch the kernel on the reachable nodesbreaks four paths

Not five hundred findings. Three changes, in the order that removes the most exposure.

The loop

Exposure, to adversary context, to breach probability, to action.

SEE

Every internet-reachable thing you own, including what you forgot.

UNDERSTAND

Which exposures actually chain into a path to something that matters.

ACT

The ranked fix, handed to the team or the agent that can land it.

ASSURE

The path is re-tested after the change, and watched for its return.

Who it’s for

Three people read this page for different reasons.

Ore Hammer Surface produces one ranked answer, but the evidence behind it has to satisfy the person who has to act on it.

  • Security leadership

    You need to say what our exposure is, and defend the answer. Ore Hammer Surface gives you the paths that exist today, what they reach, and the ranked changes that remove them — with the coverage gaps stated rather than hidden.

  • AppSec and cloud security

    You need to stop triaging. The output is validated paths with entry points, choke points and evidence, so the work you take on is work that changes the risk.

  • Platform and DevOps

    You need the change request to be specific and safe. Fixes name the resource, the configuration and the blast radius, so you are not guessing what will break.

Getting started

From conversation to first attack paths.

There is nothing to install. We scope the domains in scope with you, confirm authorization, and run.

Start · the first day

Scope the surface

We agree which domains and cloud accounts are in scope, and you confirm you are authorized to have them tested.

Then · within hours

First discovery run

Ore Hammer Surface maps what is reachable, chains what it finds and returns the ranked paths — no access to your environment required.

After that · ongoing

Continuous coverage

Discovery reruns as the estate changes. Closed paths are re-tested, and the return of a path is treated as a new finding.

Datasheet

The technical answer.

Deployment
Agentless. External discovery requires no access to your environment; connected-cloud enrichment is read-only.
Cloud coverage
AWS, Azure and GCP.
Threat frameworks
MITRE ATT&CK tactic and technique mapping, with observed coverage reported per tactic.
Threat intelligence
Actors, campaigns, KEV, EPSS and IOCs from multiple sources, curated into an actor dossier aligned with your industry sector.
Outputs
Asset graph, ranked attack paths with entry points and choke points, ranked fix list, evidence log, coverage gaps.
Integrations
Slack, email, and a cloud integration for the ransomware assessment.
Scan cadence
Continuous, or on an interval you set.

PDF · two pages

Ore Hammer Surface product brief

The one-pager to forward internally: what it does, what it needs, what it returns.

Request the brief

PDF · technical

Ore Hammer Surface datasheet

Full specification: coverage, integrations, data handling and limits.

Request the datasheet

Scoped evaluation

Run it on your own estate

The fastest way to evaluate this is to point it at something you own. We scope it with you.

Contact us

Questions

What people ask before they say yes.

Do you need access to our environment?
No. External discovery works entirely from the outside. If you connect a cloud account read-only, Ore Hammer Surface can enrich what it finds with internal context — but that is optional and never required to get value.
Is this a scanner with an AI wrapper?
A scanner enumerates weaknesses. Ore Hammer Surface reasons about how they chain into a route to something that matters, then ranks the change that breaks the most routes. The agent shows the evidence for each conclusion so you can disagree with it.
Does Surface test what it finds?
It finds, ranks and contextualizes. Proving that a path is exploitable — reproducing it and keeping the evidence — is Ore Hammer Penetration Test, scoped against the surface this product found. They are separate products; many teams run both.
How do you handle false positives?
Paths are validated before they are shown, and where a detector could not run, the product says so rather than reporting the surface as clean. Honest gaps beat confident coverage.
What does it cost?
We are onboarding by invitation and scope pricing to the size of your surface. Tell us what you run and we will be specific.

Alongside the suite

The outside view, in one place.

Ore Hammer Surface runs independently — it needs nothing else connected to be useful, and nothing installed. It models the same entities as SentinelFlow and ActiveFlux, so an exposed path can be read back to the repository that built it and forward to the cloud that runs it; joining those views into one graph is on the roadmap, not a prerequisite.

Trusted by security and platform teams at

  • Instacart
  • Plume
  • HealthTap
  • MergeBase
  • Arrivo
  • LMKR

See your attack paths.

Ore Hammer Surface is available by invitation while we onboard carefully. Tell us what you run and we will scope an evaluation on your own estate.

  • Agentless
  • Read-only
  • Scoped with you