Home / Services / Web Security
Service categoriesWeb Security
Find, know, stop, notice. Protect your public web from four angles
Use ASM to see the entry points visible from the outside, threat intelligence to gather information on attackers, WAAP to stop attacks, and defacement detection to notice changes right away. Choose the services you need to protect public websites and APIs, starting with what matters most.
Services
Web Security services
ASM
Seeing what an attacker sees, ASM automatically discovers your subdomains and servers visible from the outside, every day. It inspects open ports, certificates and technology stacks, and alerts you first to vulnerabilities that are being exploited.
KnowThreat intelligence
Combines trusted public feeds, your own IOCs and the feeds you subscribe to in one place. It removes noise, assigns confidence scores, delivers over the REST API and TAXII 2.1, and feeds your WAAP WAF rules.
StopWAAP
Reduces false blocks in AWS WAF and automates operations, from switching Count to Block to quarantining attacking IPs and bot defense.
NoticeDefacement detection
Crawls your public websites from the outside and inspects them for defacement in three layers: page content, rendered screen and AI analysis. It also detects skimming scripts that leave the page unchanged, by watching where scripts are loaded from.
Better together
What changes when you combine them
Protect the entry points you find
Of the public assets ASM finds, you can add the ones that need protection to WAAP's protected targets and to defacement detection's monitoring targets.
Notice changes that slip past your defenses
Attacks the WAF could not stop, and unauthorized updates made through an admin panel, are detected from changes to pages and scripts.
Respond faster to new vulnerabilities
When a critical vulnerability is disclosed, use ASM to identify the affected assets, and strengthen protection with the WAF until they are fixed.
Stop known attack sources ahead of time
Apply the malicious IP lists gathered by threat intelligence to your WAAP policy at a confidence level you choose. Check the impact in Count mode, then switch to Block.
Capabilities
Key features by service
ASM
- Daily automated discovery
- Imports public AWS resources
- Open port checks
- TLS certificates and technology stacks
- Active checks for known vulnerabilities, exposures and misconfigurations
- Prioritization with KEV and EPSS
- Prompt alerts on changes
- Active checks only on approved targets
Threat intelligence
- Automatic collection of public feeds
- Many IOC types
- Noise removal and confidence scores
- Register your own IOCs
- Ingest subscribed feeds
- Delivery over TAXII 2.1 / STIX 2.1
- Lookup API and console
- False-positive exclusions and audit logs
WAAP
- Exclusion suggestions for false blocks
- Impact estimates before changes
- Automatic promotion from Count to Block
- Automatic quarantine of attacking IPs
- Bot defense without paid rule groups
- ML-based malicious request detection
- Drift detection and rollback
- Log search and AI daily briefing
Defacement detection
- Three-layer inspection
- Screen diffs and diff images
- AI second-stage review
- Fail-safe design
- Script source monitoring
- URL lists and crawling
- Flexible monitoring schedules
- Notifications with reasons
Service inquiries and demo requests
We will propose the services you need for your environment and challenges.