Platform Tour

HailBytes ASM: Complete Platform Tour

Every screen an operator uses, grouped the way the work actually runs: find the assets, scan them, tune the engines, triage what comes back, decide what matters, push it where your team works, and report on it.

Captured from a running instance against a seeded demo dataset. No mockups.

Discovery

Discovery

Attack surface management starts with knowing what you own. ASM pulls from 30+ passive and active sources, then reconciles them against your cloud accounts so the assets nobody registered still show up.

Project Dashboard

Severity KPIs, triage queue, and target risk scores in one pane.

HailBytes ASM Project Dashboard: Severity KPIs, triage queue, and target risk scores in one pane.

Target Management

Domains, subnets, and CIDRs grouped per project or per customer.

HailBytes ASM Target Management: Domains, subnets, and CIDRs grouped per project or per customer.

Organizations

Multi-tenant grouping of targets for MSSP and business-unit scoping.

HailBytes ASM Organizations: Multi-tenant grouping of targets for MSSP and business-unit scoping.

Add Target

Single, bulk, IP-range, and Netlas-discovery target intake.

HailBytes ASM Add Target: Single, bulk, IP-range, and Netlas-discovery target intake.

Cloud Connectors

AWS, Azure, GCP, and Cloudflare asset discovery beyond the asset register.

HailBytes ASM Cloud Connectors: AWS, Azure, GCP, and Cloudflare asset discovery beyond the asset register.

Subdomain Inventory

Every host with technologies, status codes, and inline screenshots.

HailBytes ASM Subdomain Inventory: Every host with technologies, status codes, and inline screenshots.

Endpoint Catalogue

Crawl-derived URL inventory with tech-stack fingerprinting.

HailBytes ASM Endpoint Catalogue: Crawl-derived URL inventory with tech-stack fingerprinting.
Scanning and Monitoring

Scanning and Monitoring

Every scan is logged, comparable against the last run, and schedulable per target and per tenant. The perimeter changes whether or not anyone is watching, so the watching is the product.

Scan History

Every scan logged with engine, status, and findings count.

HailBytes ASM Scan History: Every scan logged with engine, status, and findings count.

Scan Summary

Subdomains, endpoints, and triaged vulnerabilities in one console.

HailBytes ASM Scan Summary: Subdomains, endpoints, and triaged vulnerabilities in one console.

Screenshot Gallery

gowitness captures of every reachable host, ML-classified for triage.

HailBytes ASM Screenshot Gallery: gowitness captures of every reachable host, ML-classified for triage.

Scan Comparison

Diff two runs: assets added, removed, and changed since the last scan.

HailBytes ASM Scan Comparison: Diff two runs: assets added, removed, and changed since the last scan.

Scan Health

Live worker queue depth, scheduled-task health, and tool arsenal status.

HailBytes ASM Scan Health: Live worker queue depth, scheduled-task health, and tool arsenal status.

Continuous Monitoring

Recurring schedules per target and per tenant; set once, watch always.

HailBytes ASM Continuous Monitoring: Recurring schedules per target and per tenant; set once, watch always.
Scan Engines

Scan Engines

A scan engine is the recipe: which of the 30+ tools run, in what order, at what intensity. Start from a preset, use the guided wizard, or write the YAML directly.

Scan Engine Library

Pre-built engine presets, including the Industrial / ICS profile.

HailBytes ASM Scan Engine Library: Pre-built engine presets, including the Industrial / ICS profile.

Scan Engine Wizard

Guided goal, depth, and notification flow. No YAML required.

HailBytes ASM Scan Engine Wizard: Guided goal, depth, and notification flow. No YAML required.

Engine YAML Editor

Full control over which tools run, in what order, at what intensity.

HailBytes ASM Engine YAML Editor: Full control over which tools run, in what order, at what intensity.

Tool Arsenal

30+ reconnaissance tools with per-tool version and update state.

HailBytes ASM Tool Arsenal: 30+ reconnaissance tools with per-tool version and update state.

Wordlist Management

Upload and manage the wordlists driving fuzzing and brute-force phases.

HailBytes ASM Wordlist Management: Upload and manage the wordlists driving fuzzing and brute-force phases.
Findings and Triage

Findings and Triage

Findings are deduplicated across runs, scored by severity, and tracked against per-severity SLA clocks, so repeat noise never buries the one that matters.

Vulnerability Inventory

Severity-ranked, deduplicated findings with status subtabs.

HailBytes ASM Vulnerability Inventory: Severity-ranked, deduplicated findings with status subtabs.

ICS / OT Exposure

MODBUS, S7, DNP3, and BACnet as first-class, vendor-fingerprinted findings.

HailBytes ASM ICS / OT Exposure: MODBUS, S7, DNP3, and BACnet as first-class, vendor-fingerprinted findings.

Remediation SLAs

Per-severity SLA clocks; overdue findings flagged for QBR reporting.

HailBytes ASM Remediation SLAs: Per-severity SLA clocks; overdue findings flagged for QBR reporting.
Prioritisation

Prioritisation

A list of findings sorted by CVSS is not a plan. These views answer a different question: what is actually reachable, what does it connect to, and what would an attacker go for first.

Exposure Graph

Every asset and how it connects: one picture of the real blast radius.

HailBytes ASM Exposure Graph: Every asset and how it connects: one picture of the real blast radius.

Attack Path Analysis

Traces the chain from exposed edge to crown jewels before an adversary does.

HailBytes ASM Attack Path Analysis: Traces the chain from exposed edge to crown jewels before an adversary does.

Attacker Temptation Scoring

Ranks assets by attacker attractiveness, not just finding volume.

HailBytes ASM Attacker Temptation Scoring: Ranks assets by attacker attractiveness, not just finding volume.

Threat Intel Providers

Bring your own Shodan, Censys, VirusTotal, GreyNoise, MISP, and OpenCTI keys.

HailBytes ASM Threat Intel Providers: Bring your own Shodan, Censys, VirusTotal, GreyNoise, MISP, and OpenCTI keys.
Integrations

Integrations

Findings are only useful where your team already works. ASM fans out to SIEMs, ticketing, chat, and threat intel, and speaks SCIM, SAML, and TAXII for the enterprise plumbing around it.

SIEM and Ticketing Fan-out

Splunk, Sentinel, syslog CEF, Jira, ServiceNow, GitHub, GitLab, BeWise.

HailBytes ASM SIEM and Ticketing Fan-out: Splunk, Sentinel, syslog CEF, Jira, ServiceNow, GitHub, GitLab, BeWise.

Add SIEM Integration

Destination picker, severity floor, and category toggles in one form.

HailBytes ASM Add SIEM Integration: Destination picker, severity floor, and category toggles in one form.

Notification Channels

Slack, Discord, Telegram, Teams, Lark, PagerDuty, and Opsgenie.

HailBytes ASM Notification Channels: Slack, Discord, Telegram, Teams, Lark, PagerDuty, and Opsgenie.

AI / LLM Toolkit

OpenAI, Ollama, and OpenRouter for finding triage and remediation copy.

HailBytes ASM AI / LLM Toolkit: OpenAI, Ollama, and OpenRouter for finding triage and remediation copy.

API Vault

Third-party keys resolved through Vault, Azure Key Vault, or AWS Secrets Manager.

HailBytes ASM API Vault: Third-party keys resolved through Vault, Azure Key Vault, or AWS Secrets Manager.

Bug Bounty Ingestion

HackerOne and Bugcrowd reports promoted to tracked vulnerabilities.

HailBytes ASM Bug Bounty Ingestion: HackerOne and Bugcrowd reports promoted to tracked vulnerabilities.

STIX / TAXII Server

Findings published as a TAXII 2.1 collection, with OpenVEX export.

HailBytes ASM STIX / TAXII Server: Findings published as a TAXII 2.1 collection, with OpenVEX export.

SCIM 2.0 Provisioning

IdP-driven user and group provisioning mapped onto ASM roles.

HailBytes ASM SCIM 2.0 Provisioning: IdP-driven user and group provisioning mapped onto ASM roles.

SSO and SAML

Enterprise identity federation alongside LDAP / Active Directory bind.

HailBytes ASM SSO and SAML: Enterprise identity federation alongside LDAP / Active Directory bind.
Reporting

Reporting

Client-grade PDF reports, white-labelled to your brand, generated per scan or on a recurring schedule.

Scan Report

Client-grade pentest report with asset change summary and screenshot gallery.

HailBytes ASM Scan Report: Client-grade pentest report with asset change summary and screenshot gallery.

Report Branding

White-label the PDF: logo, colours, footer, and company details.

HailBytes ASM Report Branding: White-label the PDF: logo, colours, footer, and company details.

Scheduled Reports

Recurring PDF delivery plus the daily ASM change digest.

HailBytes ASM Scheduled Reports: Recurring PDF delivery plus the daily ASM change digest.
Compliance

Compliance

Findings mapped to the frameworks your auditor asks about, plus the audit trail that proves who changed what.

Compliance Templates

PCI DSS, NIST CSF, ISO 27001, HIPAA, and SOC 2 control mappings.

HailBytes ASM Compliance Templates: PCI DSS, NIST CSF, ISO 27001, HIPAA, and SOC 2 control mappings.

Compliance Control Breakdown

Per-section control evidence generated from live findings.

HailBytes ASM Compliance Control Breakdown: Per-section control evidence generated from live findings.

Audit Log

Every config change captured: SOC 2 and ISO 27001 evidence, exportable per tenant.

HailBytes ASM Audit Log: Every config change captured: SOC 2 and ISO 27001 evidence, exportable per tenant.
Operations

Operations

Everything needed to run ASM as a service: cost attribution per client, role-based access, certificate management, and white-label branding.

Billing Insights

Per-project scan spend rollup with CSV export for client chargeback.

HailBytes ASM Billing Insights: Per-project scan spend rollup with CSV export for client chargeback.

Usage Analytics

Self-hosted product analytics; nothing leaves your instance.

HailBytes ASM Usage Analytics: Self-hosted product analytics; nothing leaves your instance.

Users and Roles

Role-based access control with per-project scoping and invitations.

HailBytes ASM Users and Roles: Role-based access control with per-project scoping and invitations.

TLS Certificates

Current certificate state plus a one-click Let's Encrypt wizard.

HailBytes ASM TLS Certificates: Current certificate state plus a one-click Let's Encrypt wizard.

White-label Branding

Your logo and palette across the console and every generated report.

HailBytes ASM White-label Branding: Your logo and palette across the console and every generated report.

Queue and Concurrency

Tune worker concurrency and per-phase rate limits to your hardware.

HailBytes ASM Queue and Concurrency: Tune worker concurrency and per-phase rate limits to your hardware.

Project Switcher

One workspace per customer or business unit, fully data-isolated.

HailBytes ASM Project Switcher: One workspace per customer or business unit, fully data-isolated.

Recon Notes

Per-target analyst notes and to-do tracking alongside the scan data.

HailBytes ASM Recon Notes: Per-target analyst notes and to-do tracking alongside the scan data.

See it against your own attack surface

ASM is self-hosted: it deploys into your AWS or Azure account, and your scan data never leaves it. Bring a domain to a live session and we will run it in front of you.