{"uid":"cap_PalANvfXSBJuAI4VB4XTT","slug":"cyberpulse-attack-surface-assessment-50dedf12","name":"CyberPulse Attack Surface Assessment","description":"External attack-surface assessment (EASM) for any company and domain — internet-exposed assets, tech-stack fingerprinting, email-security posture, supply-chain and identity exposure, and a prioritized remediation roadmap, for security and red-team-context agents. Authorized defensive use only.","url":"https://cyberpulse-six.vercel.app/api/cyber/attack-surface","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"type":"object","properties":{"lang":{"type":"string","description":"en | es | fr | de | ja | zh | ko | pt | ar | hi (default: en)"},"domain":{"type":"string","description":"Primary domain — e.g. \"acme.com\" | \"techstartup.io\" | \"globalbank.co.uk\""},"company":{"type":"string","description":"Company name — e.g. \"Acme Corporation\" | \"TechStartup Inc\" | \"GlobalBank\""}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"errors":{"type":"object","description":"Documented error responses, keyed by HTTP status code","additionalProperties":{"type":"object","required":["description"],"properties":{"example":{"type":"object"},"description":{"type":"string"}}}},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"domain":"acme.com","company":"Acme Corporation","risk_grade":"C","email_security":{"spf":"pass","dkim":"missing","dmarc":"none","bec_risk":"HIGH","email_spoofing_possible":true},"executive_summary":"Acme Corporation has critical RDP exposure and no DMARC — enabling email spoofing attacks. Immediate actions: block RDP port, implement DMARC reject policy.","high_risk_findings":[{"risk":"CRITICAL","effort":"Quick win","finding":"RDP port 3389 exposed to internet on subsidiary IP","remediation":"Block RDP at perimeter firewall; use VPN + MFA for remote access","attack_scenario":"Brute force or credential stuffing could yield initial access"}],"overall_risk_score":68,"attack_scenarios_most_likely":["Phishing targeting finance team","Credential stuffing on customer portal","Exploitation of exposed RDP"]}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.25","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.25/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.25","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.25","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_JdPLepPMX-DCPmB3AQQGT","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.25","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Performs external attack-surface reconnaissance on a company or domain, returning exposed assets, tech-stack fingerprints, email security posture, supply-chain risks, and a prioritized remediation roadmap.","exampleAgentPrompt":"Run an external attack-surface assessment on acmecorp.com — I want to see all internet-exposed assets, what tech stack they're running, their email security configuration, any supply-chain or identity exposure risks, and a prioritized remediation roadmap.","exampleUseCases":[{"title":"Pre-acquisition security due diligence","prompt":"We're considering acquiring TechStartup Inc. — can you run a full external attack-surface assessment on their domain? I need to understand what assets they're exposing, their tech stack, email security posture, and any supply-chain risks before our security team meets with their leadership."},{"title":"Red-team planning for authorized testing","prompt":"I'm planning a red-team engagement for a client next month. Scan their primary domain and all known subdomains for internet-exposed assets, tech fingerprints, email security gaps, and third-party integrations — give me the prioritized attack surface so we can design a realistic simulation."},{"title":"Internal security posture assessment","prompt":"Our CEO wants visibility into our own company's external security posture. Run a full attack-surface recon on our domain, show me everything we're exposing to the internet, our current email security config, and any remediation steps we should prioritize to reduce our risk footprint."}],"resultDescription":"Returns a structured report covering: internet-exposed assets and open services, technology stack fingerprints (frameworks, CDNs, servers), email security posture (SPF/DKIM/DMARC status), supply-chain and third-party identity exposure indicators, and a ranked remediation roadmap with actionable recommendations.","failureModes":["Invalid or unresolvable domain — returns error indicating domain not found","Rate limiting or quota exceeded — returns 429 or payment-related error","Payment not processed — returns 402 requiring x402 payment","Domain with no significant internet presence — returns sparse or empty asset list","Timeout on reconnaissance tasks for very large organizations — may return partial results"],"whenToPreferThis":"Use this endpoint when you need a comprehensive external recon profile of a company or domain in a single call, covering assets, tech stack, email security, and supply-chain risk together with remediation guidance. Prefer this over individual OSINT or Shodan lookups when you want a synthesized, prioritized security posture summary rather than raw data from a single source.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T12:49:25.038Z","isFirstParty":false}