Your IT team is blind to what attackers see clearly.

BTT Armour SHIELD lets you see your organization the way an attacker would, and close the gaps before someone walks right through them.

Attackers already see this picture of your organization. You should too.

yourcompany.com Scan
Leaked credentials
169
across 6 breach databases
Infostealer leaks
13
+ 4 session cookies
Subdomains discovered
yourcompany.com
├─mail.yourcompany.com
├─vpn.yourcompany.com
└─dev-staging.yourcompany.com
+ 33 more subdomains
Employees enumerated
1,284
847 email addresses harvested
!
2 vulnerable hosts
medium risk
Breach sources
naz.api2024-01-24 book24.ru2024-04-26 filmai.in2021-09-14 gonitro.com2023-08-02
+ 2 more sources
Hosting providers
Telia Lietuva, AB Microsoft Corporation PBAS hosting system
16 hosts across 4 ISPs
36 domains · 12 subdomains
Ports 22, 443, 8080, 3389
yourcompany.com Scan
Leaked credentials
169
across 6 breach databases
Infostealer leaks
13
+ 4 session cookies
Subdomains discovered
yourcompany.com
├─mail.yourcompany.com
├─vpn.yourcompany.com
└─dev-staging.yourcompany.com
+ 33 more subdomains
!
2 vulnerable hosts
medium risk
Ports
22, 443, 8080, 3389
Employees enumerated
1,284
847 email addresses harvested
Breach sources
naz.api2024-01-24 book24.ru2024-04-26 filmai.in2021-09-14 gonitro.com2023-08-02
+ 2 more sources
16 hosts across
4 ISPs
36 domains
12 subdomains
Hosting providers
Telia Lietuva, AB Microsoft Corporation PBAS hosting system

BTT Armour SHIELD is Skaylink’s managed external attack surface monitoring service, powered by Entryscope. We find these exposures so you can fix them before someone else exploits them first.

30 minutes, no commitment or preparation needed

Most organizations track the infrastructure they provisioned: a website, an email server, a VPN, a cloud portal. However, the external attack surface of that same organization, visible through public DNS records, breach databases, and social network scraping, contains assets and exposures that never appeared in any internal inventory.

There’s way more info out there than you think

Main website www.yourco.com
Email server mail.yourco.com
VPN gateway vpn.yourco.com
Cloud portal portal.yourco.com
4 known assets
recon — yourcompany.com — passive enumeration
$ entryscope enumerate --domain yourcompany.com --passive
# Starting passive reconnaissance...
Subdomains discovered
mail.domenas1.lt 185.12.xx.xx PBAS hosting system LAN
vps.domenas1.lt 185.12.xx.xx N/A
savitarna.domenas1.lt 22.222.xx.xx Telia Lietuva, AB
erp.domenas2.lt 11.11.xx.xx PBAS hosting system LAN
www.dvs.domenas2.lt 11.11.xx.xx PBAS hosting system LAN
archv.darbuotojams.domenas2.lt 11.11.xx.xx PBAS hosting system LAN
www.domenas3.lt 11.11.xx.xx PBAS hosting system LAN
... 29 more subdomains enumerated
Host inventory
IP ISP Ports Vuln
11.11.11.111 Telia Lietuva, AB 1 NO
22.444.444.4 Microsoft Corporation 2 NO
33.333.33.33 Microsoft Corporation 2 YES
33.444.55.5 Microsoft Corporation 2 NO
33.444.55.0 Microsoft Corporation 2 NO
33.444.55.666 Microsoft Corporation 2 NO
33.333.33.33 Telia Lietuva, AB 1 NO
... showing 7 of 16 hosts
Open ports
22 (SSH) 443 (HTTPS) 8080 (HTTP-ALT) 3389 (RDP)
Credential breaches
Source Date Exposed fields
naz.api 2024-01 email, password
book24.ru 2024-04 email, password, fullname
filmai.in 2021-09 email, password, userid
gonitro.com 2023-08 email, password, username
intelx.io-whois 2023-03 email, phone, country
intelx.io-pastescrape 2022-11 email, password, secret
Malware leak overview
156 passwords found in combolists
13 passwords found in infostealer logs
4 active session cookies in infostealer logs
Employee enumeration
Harvested from LinkedIn, public directories, and social networks:
j.smith@yourco.com Head of IT
a.jones@yourco.com Finance Director
m.davis@yourco.com System Administrator
r.wilson@yourco.com Project Manager
k.lee@yourco.com Sales Manager
d.brown@yourco.com HR Director
... 841 more email addresses with roles and locations
Vulnerable hosts
⚠ 33.333.33.33 Microsoft Corporation VULNERABLE 0 open ports, 1 associated domain
⚠ 33.333.33.33 N/A VULNERABLE 2 open ports, 1 associated domain
# Scan complete. 36 domains, 16 hosts, 847 emails,
# 169 leaked credentials across 6 breach databases.
# All from one domain. No agents. No internal access.

Reconnaissance powered by cross-referencing against 630M+ indexed domains, 230M+ catalogued hosts, 200B+ credential records from breach databases, and 10T+ historical DNS
entries.

How infrastructure gets mapped without touching it

This module works entirely from passive data sources, so it produces no IDS alerts, requires no firewall exceptions, and needs no agents installed on anything.

01
Entryscope takes the primary domain and resolves every associated subdomain, apex domain, and DNS record

The enumeration draws on 10T+ historical DNS records, which means it catches infrastructure that was active years ago and may still be reachable but absent from internal inventories. Essentially: forgotten staging environments, decommissioned-but-still-live subdomains, and test servers that never got taken down all surface here.

02
Each discovered host gets IP-resolved, geolocated, and attributed to an ISP or hosting provider

This produces the infrastructure map: which IPs belong to which hosting providers, where they're physically located, and how many domains each IP serves. When the assessment reveals hosts at providers the IT team doesn't recognize, those are typically the highest-priority findings.

03
Open ports and running software get fingerprinted passively

Without sending a single probe packet, Entryscope identifies exposed services and their software versions by cross-referencing against existing scan databases. Skaylink's team uses this to flag hosts running outdated or vulnerable software in the assessment report, along with specific remediation steps.

04
Skaylink delivers the infrastructure section of the assessment with prioritized remediation

The raw host and domain data gets contextualized: which hosts are genuinely vulnerable versus which are informational findings, what the actual risk to the organization is, and what specific actions the IT team should take first. The assessment report separates urgent items from monitoring recommendations, so teams can prioritize without guessing.

The same reconnaissance an attacker runs before a targeted campaign

Social engineering and spear phishing start with research. This module maps the publicly available information that makes those attacks possible.

01
Employee names, roles, and email addresses get harvested from public sources

LinkedIn profiles, public directories, social networks, company websites, and conference speaker lists all contribute. The module reconstructs organizational hierarchies, identifies key personnel (IT administrators, finance directors, executives), and maps reporting structures that attackers use to craft convincing pretexts.

02
Email address patterns get validated against the organization's domain

Once the naming convention is identified (firstname.lastname, f.lastname, initials), the module can enumerate likely email addresses for every discovered employee. This is exactly how spear-phishing target lists get built, and knowing the extent of the exposure is the first step toward limiting it.

03
Social media presence gets mapped across platforms

Public posts, check-ins, project mentions, and professional affiliations create the context that makes social engineering convincing. An attacker who knows an employee just returned from a specific conference can reference it in a phishing email to bypass suspicion. The module surfaces this exposure so organizations can make informed decisions about their public information footprint.

04
Skaylink identifies which exposures create actionable risk and recommends specific mitigations

Not every public employee listing is a problem, but an IT administrator's email address combined with their LinkedIn profile showing the exact technologies they manage is a gift to an attacker. The assessment distinguishes between normal public presence and exposures that materially increase the risk of targeted attacks. All with concrete steps to reduce the attack surface where it matters.

Which employee credentials are already circulating in breach databases

Cross-referencing domain-associated email addresses against 200B+ leaked credential records from data breaches and infostealer malware infections.

01
Every email address tied to the domain gets checked against combolist and breach databases

The check identifies which employees have credentials appearing in known data breaches, which specific breach incidents are involved (with dates and breach names), and what data types were exposed in each incident: passwords, phone numbers, physical addresses, usernames, or authentication secrets.

02
Infostealer malware infections get flagged separately because they carry different risk

A password in a combolist from a 2019 breach is concerning. A fresh credential harvested by infostealer malware is an active emergency, because infostealers also capture session cookies, browser-saved passwords, and VPN tokens. The module distinguishes between these categories so response can be appropriately urgent.

03
Session cookies from infostealer logs get identified as highest-priority findings

Active session cookies can bypass multi-factor authentication entirely, giving an attacker direct access to authenticated sessions without needing the password at all. When the assessment finds these, Skaylink flags them for immediate session invalidation and investigates whether the affected systems show signs of unauthorized access.

04
Skaylink delivers incident-specific remediation: which accounts to reset, which sessions to kill, and what to investigate

The assessment report groups credential findings by severity and urgency. Active infostealer infections go at the top with specific remediation steps. Historical breach exposures follow with password-reset recommendations scoped to affected accounts. Each finding traces back to a specific incident, so the remediation is targeted rather than a blanket "reset all passwords" directive that creates disruption without proportionate benefit.

Threat Monitoring

An early warning layer that will scan underground channels, Telegram groups, and dark web forums for mentions of the organization, planned attacks, and compromised data listings. When active, it feeds directly into the BTT Armour SHIELD assessment cycle alongside the three existing modules.

Telegram channel monitoring Underground chatter detection Attack plot early warnings Phishing campaign simulation Employee awareness testing

Passive scanning means zero disruption. The entire asset discovery process runs against existing data sources: DNS databases, certificate transparency logs, and historical scan archives. Nothing touches production infrastructure.

Entryscope runs the reconnaissance, and we turn it into a managed security service.

Entryscope standalone
Entryscope EASM Platform External attack surface management tool
Automated scanning
Raw finding exports
Dashboard access
Credential monitoring

Triage, remediation guidance, compliance mapping, incident escalation, integration with SOC/backup/continuity services, and regulatory expertise require additional resources on the client side.

BTT Armour SHIELD through Skaylink
BTT Armour SHIELD Managed assessment & monitoring

Skaylink's security team runs the scan through Entryscope, reviews the raw findings, and delivers a structured assessment with prioritized remediation steps. You get direct platform access alongside the walkthrough, so your team can revisit the data independently.

Managed service with continuous monitoring, triage, and actionable remediation guidance from engineers who understand your environment
Security managed by experts across endpoint security, incident response, and infrastructure for over 600 organizations in the Baltics
Compliance-ready reporting structured for NIS2, DORA, and ISO 27001 audit requirements, covering the external attack surface component auditors expect
Remediation path to execution where findings connect directly to SOC, backup, and continuity services already in the Skaylink stack
Passive scanning that produces no IDS alerts, requires no firewall exceptions, and needs no agents installed on anything
Local delivery by a Lithuanian-speaking security team with regional regulatory understanding and a single point of contact

When SHIELD surfaces findings, Skaylink's security stack acts on them.

Each of these is a Skaylink managed service with its own team and scope. When an organization also uses SHIELD, findings feed into SOC monitoring, compliance reports support NIS2 audits, and data SHIELD flags as at-risk gets covered by BTT Vault.

Separate service SOC Service

Findings feed into 24/7 security operations monitoring

SOC service for business
Separate service NIS2 Compliance

Assessment reports map directly to audit requirements

NIS2 compliance
Separate service BTT Vault

Backup and recovery for data SHIELD identifies as at-risk

BTT Vault
Separate service Data Security & Business Continuity

Recovery planning tied to exposed infrastructure findings

Data Security & Business Continuity
Separate service BTT Armour

Endpoint and workstation security for the broader fleet

BTT Armour

The same scan, different outputs for different roles.

01

Security Teams

Prioritized exposure data before threat actors find it

Identify exposures and vulnerabilities across the external perimeter before threat actors do, with findings prioritized by severity so the team focuses on what matters instead of processing noise from generic scanners.

Attack surface monitoring Credential breach alerts Threat-informed prioritization
02

IT Administrators

Shadow IT and forgotten assets surfaced automatically

Maintain visibility across distributed infrastructure, including cloud services, legacy systems, and shadow IT that appeared without formal provisioning. The asset inventory surfaces hosts and subdomains that internal monitoring tools miss entirely.

Complete asset inventory Shadow IT discovery Configuration insights
03

Risk & Compliance

Audit-ready documentation for NIS2 and ISO 27001

Demonstrate due diligence with a documented external risk assessment that maps to regulatory frameworks. The report structure is built for audit consumption, covering asset identification, vulnerability assessment, and remediation tracking.

Risk scoring & reporting Audit-ready documentation Third-party risk insights
04

Executive Leadership

Board-ready risk posture summaries

Understand the organization's external risk posture through clear, non-technical summaries. The dashboard and executive reporting layer translate technical findings into business impact language suitable for board-level communication and investment decisions.

Executive dashboards Trend analysis Board-ready reports
05

MSSPs & Consultants

Multi-tenant assessments that scale without headcount

Deliver external attack surface assessments to clients using Entryscope's multi-tenant infrastructure, with automated discovery and monitoring that scales across engagements without linear headcount increases.

Multi-tenant dashboard White-label reporting API integrations
06

M&A Due Diligence

Target security posture assessed before closing

Assess the external security posture of acquisition targets before closing. The scan reveals hidden technical debt, exposed infrastructure, and leaked credentials that affect valuation and integration risk.

Rapid target assessment Risk quantification Post-merger monitoring
thiswontbeyou.com
Attack
subdomains hosts credentials employees open ports breaches ISPs DNS records
Attack vectors found 0

See what's exposed.

Schedule a 30-minute assessment call. Skaylink's security team will run a live scan of your domain and walk through what it finds.

1

Live scan of your primary domain during the call

2

Findings walkthrough with a Skaylink security specialist

3

Assessment of your external risk posture with next steps

Schedule a Domain Assessment

30 minutes, no commitment or preparation needed