Skip to main content

New: Continuous discovery is now on by default for every plan

Opal Opal — home

External attack surface management

Every asset you own, scored by how exploitable it actually is

Opal continuously discovers your external surface, attributes every host to an owner, and ranks exposures by real-world exploitability — packaged into a shareable report in minutes, not quarters.

opal — scan
$ opal scan --org northwind --depth fullresolving seed domains .............. 41 foundenumerating subdomains ............. 1,284 hostsprobing certificate transparency ... 3,907 recordsfingerprinting services ............ 6,412 ports openattributing ownership .............. 6 clouds · 22 teamscorrelating CVEs ................... 214 matchedscoring exploitability ............. done in 3m 12s SEVERITY  ASSET                          FINDINGCRITICAL  api-staging.northwind.io:8080  unauth admin panelCRITICAL  vpn-legacy.northwind.io:443    CVE-2023-46805 · exploitedHIGH      mail-gw.northwind.io:443       CVE-2024-21762HIGH      s3-backups.northwind.io        public bucket listingMEDIUM    cdn-edge.northwind.io:80       dangling CNAMEMEDIUM    git.northwind.io:22            weak host keyLOW       docs.northwind.io:443          deprecated TLS suite unattributed hosts ................. 97 → routed to #sec-triage✓ 4,182 assets mapped · 37 exposures · report ready

Getting started

Map your surface in three commands

Install once, point Opal at a domain, and it does the rest — discovery, ownership attribution and exploitability scoring, all from a read-only vantage point outside your network.

Nothing to install on your side

Opal works entirely from outside your perimeter — the same vantage point an attacker has. Setup is a shell command and a domain.

  • No agent to deploy or maintain
  • No credentials handed over
  • No change window, no firewall rule

Install the CLI

curl -fsSL https://opal.sh | sh

Point it at your org

opal init --org acme --seed acme.com

Run your first scan

opal scan --depth full

What Opal does

Three jobs, one continuous loop

Discovery, attribution and scoring aren't three tools you run in sequence. Seed a domain once and all three keep working without anyone scheduling them.

Continuous discovery

Seed a domain or an IP range and Opal keeps enumerating — subdomains, certificates, cloud tenancy, forgotten staging boxes. The inventory is never a snapshot.

Re-scanned every 4 hours

Ownership attribution

Every host resolves to a registrant, a hosting provider and an internal team. Findings route themselves, so nobody spends a morning working out whose box it is.

22 teams mapped automatically

Exploitability scoring

CVSS tells you what could go wrong in theory. Opal ranks by what is reachable, unauthenticated and actually exercisable from the open internet.

Reachability-weighted, not CVSS-only

Trusted at scale

Built to be the surface of record

The inventory other teams cite in a review, the one an auditor accepts, and the one that still answers when the estate doubles.

Stay fast when the estate isn't small

Discovery is incremental, so a 40-host startup and a 400,000-host conglomerate get the same first result in minutes. Nothing queues behind a nightly full sweep, and adding a subsidiary doesn't reset your baseline.

Focus on response, not tooling

Opal replaces the spreadsheet, the scanner export, the DNS side-quest and the Slack thread where someone asks whose box this is. One view, continuously updated, with the evidence attached to the finding.

Evidence you can hand to an auditor

SOC 2 Type II and ISO 27001 audited annually, read-only by default with no write scopes requested, and regional data residency in the EU, US and AU. FedRAMP Moderate is in progress.

Everything the UI does, the API does

Findings export to Jira, ServiceNow and CSV, and every view has a CLI and an API behind it — so the workflow survives contact with the automation you already run.

Measured, not claimed

4.9M
Assets under continuous watch, across 610 orgs
1.2B
Ports fingerprinted each month, IPv4 + IPv6
3 min
Median time to first result, any estate size
99.98%
Platform uptime, trailing 12 months

The Opal console

Everything you need in one console

Discover the surface, rank what matters, and close it out — all against one continuously updated picture of what you actually expose.

Discovery

Know everything you own

Seed one domain. Opal walks outward through certificate transparency, passive DNS, cloud tenancy and registrar records until the picture stops changing — then keeps walking it every four hours.

How discovery works

Seed one domain. Opal walks certificate transparency, passive DNS, cloud tenancy and registrar records until the picture stops changing — then keeps walking it every four hours.

  • Subdomain and dangling-CNAME enumeration
  • Shadow IT and forgotten staging boxes
  • IPv4 and IPv6 sweeps

The staging box from a pilot that ended three years ago, the campaign subdomain nobody logged, the bucket a contractor left listable. The assets that were never in the CMDB are the ones this finds.

  • Hosts absent from your own inventory
  • Subdomain-takeover candidates
  • Expired ownership, still answering

Six providers and twenty-two teams resolve into one normalised asset list, with the account, the subscription and the owning team attached to every host in it.

  • AWS, Azure, GCP, Cloudflare and bare metal
  • Account and subscription attribution
  • One inventory, one scoring model

Exposure

Rank what actually matters

A critical CVSS behind three firewalls matters less than an unauthenticated admin panel on the open internet. Opal scores reachability first and severity second, so the top of the list is the top of the list.

How scoring works

A critical CVSS behind three firewalls matters less than an unauthenticated admin panel on the open internet. Opal scores reachability first and severity second.

  • Reachability-weighted scoring
  • Live CVE correlation
  • Exploit-availability signal

Registrant, hosting provider, cloud account and owning team — resolved automatically, so a finding arrives with a name attached instead of starting a hunt.

  • Auto-attribution to internal teams
  • Unattributed queue surfaced, never buried
  • Routes straight to Jira or ServiceNow

A port that opened last night matters more than one that has been open for a year. Every scan is diffed against the last, so the queue leads with what changed rather than with what is merely bad.

  • Diffed against the previous sweep
  • Reopened findings flagged, not re-filed
  • Alerting on new reachable surface

Response

Close it, and prove you closed it

Triage in one place with the evidence attached, and hand out a report that a stakeholder can read without anyone rebuilding it in slides first.

How response works

Comment, assign and close without leaving the exposure. Every change syncs live, so the response is designed once rather than reconstructed from a Slack thread later.

  • Real-time collaboration
  • Full audit trail per finding
  • Evidence attached inline

Closing a ticket is not the same as closing a hole. Opal re-probes the host on the next sweep and reopens the finding itself if the exposure is still answering.

  • Re-probed, not self-reported
  • Reopens automatically on regression
  • Time-to-close measured from the host

One link gives a stakeholder the whole picture — inventory, exposures, remediation plan and SLA status — without anyone exporting a slide.

  • Shareable live link
  • Point-in-time PDF snapshot
  • Scoped to an audience

Coverage

Cloud, on-prem, edge? No problem.

Opal doesn't care where a host lives. If it answers from the public internet, it's in scope — and if it stops answering, Opal notices that too.

Deploy nothing

There is no agent, no collector VM and no credential to rotate. Opal sees what an attacker sees, from where an attacker stands.

Map your surface

FAQ

Questions, answered

Still stuck? Talk to an engineer — not a sales rep.

Anything that answers from the public internet and traces back to you. Opal starts from a seed — a domain, an IP range or a cloud account — then expands outward through certificate transparency logs, passive DNS, registrar records and cloud tenancy metadata until the picture stops growing. It never touches your internal network, because an attacker can't either.
No. Opal is read-only and entirely external — there is no agent to deploy, no collector VM to maintain and no credential to rotate. Optional cloud connectors improve ownership attribution if you want them, and those request read-only scopes you can revoke at any time.
CVSS describes how bad a vulnerability would be in the abstract. Opal scores what is actually reachable from the open internet: whether the service responds, whether it requires authentication, whether a working exploit exists in the wild, and whether the host sits in a production path. A 9.8 behind three firewalls ranks below an unauthenticated admin panel on a forgotten staging box — because that is the order an attacker would work in.
Scans are rate-shaped to stay well inside the acceptable-use policy of every provider we touch, and Opal identifies itself honestly in its user agent and reverse DNS. We publish our source ranges so you can allow-list them. In eight years we have not had a customer receive a complaint about our traffic.
Minutes. Discovery is incremental, so assets and exposures stream into the console as they are confirmed rather than landing in one batch at the end. A mid-sized estate typically reaches a stable inventory inside an hour; the first criticals usually surface well before that.
In the region you pick — EU, US or AU — and nowhere else. Findings are encrypted at rest and in transit, access is scoped per workspace with SSO and SCIM, and every read of your data is logged where you can audit it. We do not sell, share or aggregate customer surface data into any external dataset.

Start mapping

The exposure nobody else found.
The fix nobody else shipped.

Map your external attack surface in minutes. Free for the first 500 assets, no card, no call.