Your IT team is blind to what attackers see clearly.
BTT Armour SHIELD lets you see your organization the way an attacker would, and close the gaps before someone walks right through them.
Attackers already see this picture of your organization. You should too.
22, 443, 8080, 3389
4 ISPs
12 subdomains
BTT Armour SHIELD is Skaylink’s managed external attack surface monitoring service, powered by Entryscope. We find these exposures so you can fix them before someone else exploits them first.
30 minutes, no commitment or preparation needed
Most organizations track the infrastructure they provisioned: a website, an email server, a VPN, a cloud portal. However, the external attack surface of that same organization, visible through public DNS records, breach databases, and social network scraping, contains assets and exposures that never appeared in any internal inventory.
There’s way more info out there than you think
Reconnaissance powered by cross-referencing against 630M+ indexed domains, 230M+ catalogued hosts, 200B+ credential records from breach databases, and 10T+ historical DNS
entries.
Skaylink + Entryscope = a complete domain assesment
Skaylink’s security team runs the scan through Entryscope, reviews the raw findings, and delivers a structured assessment with prioritized remediation steps. You also get direct platform access alongside the walkthrough, so your team can revisit the data independently.
-
Dashboard
Risk posture summary with host counts, vulnerability distribution, and discovery timeline. The starting point for the assessment walkthrough.
-
Host Inventory
Every externally reachable IP tied to the domain, with ISP attribution, open port counts, and vulnerability flags per host.
-
Domain Map
Complete subdomain enumeration with IP resolution and hosting organization identification, including infrastructure that may not appear in internal inventories.
-
Credential Intelligence
Leaked credentials from combolists, infostealer malware, and data breaches, mapped to specific incidents with dates and exposed data types.
Anonymized data from an assessment of a mid-sized Lithuanian organization scanned passively.
-
IT Asset Discovery
Infrastructure mapping from a single domain input, like Subdomains, IPs, ports and software fingerprints.
-
Organization Intelligence
Employee enumeration and public exposure mapping. This is the reconnaissance attackers run before targeting people.
-
Credential Intelligence
Leaked credentials from breach databases and infostealer malware. Mapped to specific incidents and employees.
-
Threat Monitoring (Coming Soon)
Underground channel scanning for organizational mentions and planned attacks.
How infrastructure gets mapped without touching it
This module works entirely from passive data sources, so it produces no IDS alerts, requires no firewall exceptions, and needs no agents installed on anything.
The enumeration draws on 10T+ historical DNS records, which means it catches infrastructure that was active years ago and may still be reachable but absent from internal inventories. Essentially: forgotten staging environments, decommissioned-but-still-live subdomains, and test servers that never got taken down all surface here.
This produces the infrastructure map: which IPs belong to which hosting providers, where they're physically located, and how many domains each IP serves. When the assessment reveals hosts at providers the IT team doesn't recognize, those are typically the highest-priority findings.
Without sending a single probe packet, Entryscope identifies exposed services and their software versions by cross-referencing against existing scan databases. Skaylink's team uses this to flag hosts running outdated or vulnerable software in the assessment report, along with specific remediation steps.
The raw host and domain data gets contextualized: which hosts are genuinely vulnerable versus which are informational findings, what the actual risk to the organization is, and what specific actions the IT team should take first. The assessment report separates urgent items from monitoring recommendations, so teams can prioritize without guessing.
The same reconnaissance an attacker runs before a targeted campaign
Social engineering and spear phishing start with research. This module maps the publicly available information that makes those attacks possible.
LinkedIn profiles, public directories, social networks, company websites, and conference speaker lists all contribute. The module reconstructs organizational hierarchies, identifies key personnel (IT administrators, finance directors, executives), and maps reporting structures that attackers use to craft convincing pretexts.
Once the naming convention is identified (firstname.lastname, f.lastname, initials), the module can enumerate likely email addresses for every discovered employee. This is exactly how spear-phishing target lists get built, and knowing the extent of the exposure is the first step toward limiting it.
Public posts, check-ins, project mentions, and professional affiliations create the context that makes social engineering convincing. An attacker who knows an employee just returned from a specific conference can reference it in a phishing email to bypass suspicion. The module surfaces this exposure so organizations can make informed decisions about their public information footprint.
Not every public employee listing is a problem, but an IT administrator's email address combined with their LinkedIn profile showing the exact technologies they manage is a gift to an attacker. The assessment distinguishes between normal public presence and exposures that materially increase the risk of targeted attacks. All with concrete steps to reduce the attack surface where it matters.
Which employee credentials are already circulating in breach databases
Cross-referencing domain-associated email addresses against 200B+ leaked credential records from data breaches and infostealer malware infections.
The check identifies which employees have credentials appearing in known data breaches, which specific breach incidents are involved (with dates and breach names), and what data types were exposed in each incident: passwords, phone numbers, physical addresses, usernames, or authentication secrets.
A password in a combolist from a 2019 breach is concerning. A fresh credential harvested by infostealer malware is an active emergency, because infostealers also capture session cookies, browser-saved passwords, and VPN tokens. The module distinguishes between these categories so response can be appropriately urgent.
Active session cookies can bypass multi-factor authentication entirely, giving an attacker direct access to authenticated sessions without needing the password at all. When the assessment finds these, Skaylink flags them for immediate session invalidation and investigates whether the affected systems show signs of unauthorized access.
The assessment report groups credential findings by severity and urgency. Active infostealer infections go at the top with specific remediation steps. Historical breach exposures follow with password-reset recommendations scoped to affected accounts. Each finding traces back to a specific incident, so the remediation is targeted rather than a blanket "reset all passwords" directive that creates disruption without proportionate benefit.
Threat Monitoring
An early warning layer that will scan underground channels, Telegram groups, and dark web forums for mentions of the organization, planned attacks, and compromised data listings. When active, it feeds directly into the BTT Armour SHIELD assessment cycle alongside the three existing modules.
Passive scanning means zero disruption. The entire asset discovery process runs against existing data sources: DNS databases, certificate transparency logs, and historical scan archives. Nothing touches production infrastructure.
Entryscope runs the reconnaissance, and we turn it into a managed security service.
Triage, remediation guidance, compliance mapping, incident escalation, integration with SOC/backup/continuity services, and regulatory expertise require additional resources on the client side.
Skaylink's security team runs the scan through Entryscope, reviews the raw findings, and delivers a structured assessment with prioritized remediation steps. You get direct platform access alongside the walkthrough, so your team can revisit the data independently.
When SHIELD surfaces findings, Skaylink's security stack acts on them.
Each of these is a Skaylink managed service with its own team and scope. When an organization also uses SHIELD, findings feed into SOC monitoring, compliance reports support NIS2 audits, and data SHIELD flags as at-risk gets covered by BTT Vault.
Findings feed into 24/7 security operations monitoring
SOC service for businessAssessment reports map directly to audit requirements
NIS2 complianceRecovery planning tied to exposed infrastructure findings
Data Security & Business ContinuityThe same scan, different outputs for different roles.
Security Teams
Prioritized exposure data before threat actors find itIdentify exposures and vulnerabilities across the external perimeter before threat actors do, with findings prioritized by severity so the team focuses on what matters instead of processing noise from generic scanners.
IT Administrators
Shadow IT and forgotten assets surfaced automaticallyMaintain visibility across distributed infrastructure, including cloud services, legacy systems, and shadow IT that appeared without formal provisioning. The asset inventory surfaces hosts and subdomains that internal monitoring tools miss entirely.
Risk & Compliance
Audit-ready documentation for NIS2 and ISO 27001Demonstrate due diligence with a documented external risk assessment that maps to regulatory frameworks. The report structure is built for audit consumption, covering asset identification, vulnerability assessment, and remediation tracking.
Executive Leadership
Board-ready risk posture summariesUnderstand the organization's external risk posture through clear, non-technical summaries. The dashboard and executive reporting layer translate technical findings into business impact language suitable for board-level communication and investment decisions.
MSSPs & Consultants
Multi-tenant assessments that scale without headcountDeliver external attack surface assessments to clients using Entryscope's multi-tenant infrastructure, with automated discovery and monitoring that scales across engagements without linear headcount increases.
M&A Due Diligence
Target security posture assessed before closingAssess the external security posture of acquisition targets before closing. The scan reveals hidden technical debt, exposed infrastructure, and leaked credentials that affect valuation and integration risk.
See what's exposed.
Schedule a 30-minute assessment call. Skaylink's security team will run a live scan of your domain and walk through what it finds.
Live scan of your primary domain during the call
Findings walkthrough with a Skaylink security specialist
Assessment of your external risk posture with next steps
30 minutes, no commitment or preparation needed