Continuous discovery
Seed a domain or an IP range and Opal keeps enumerating — subdomains, certificates, cloud tenancy, forgotten staging boxes. The inventory is never a snapshot.
External attack surface management
Opal continuously discovers your external surface, attributes every host to an owner, and ranks exposures by real-world exploitability — packaged into a shareable report in minutes, not quarters.
$ opal scan --org northwind --depth fullresolving seed domains .............. 41 foundenumerating subdomains ............. 1,284 hostsprobing certificate transparency ... 3,907 recordsfingerprinting services ............ 6,412 ports openattributing ownership .............. 6 clouds · 22 teamscorrelating CVEs ................... 214 matchedscoring exploitability ............. done in 3m 12s SEVERITY ASSET FINDINGCRITICAL api-staging.northwind.io:8080 unauth admin panelCRITICAL vpn-legacy.northwind.io:443 CVE-2023-46805 · exploitedHIGH mail-gw.northwind.io:443 CVE-2024-21762HIGH s3-backups.northwind.io public bucket listingMEDIUM cdn-edge.northwind.io:80 dangling CNAMEMEDIUM git.northwind.io:22 weak host keyLOW docs.northwind.io:443 deprecated TLS suite unattributed hosts ................. 97 → routed to #sec-triage✓ 4,182 assets mapped · 37 exposures · report ready Getting started
Install once, point Opal at a domain, and it does the rest — discovery, ownership attribution and exploitability scoring, all from a read-only vantage point outside your network.
Opal works entirely from outside your perimeter — the same vantage point an attacker has. Setup is a shell command and a domain.
Install the CLI
curl -fsSL https://opal.sh | sh Point it at your org
opal init --org acme --seed acme.com Run your first scan
opal scan --depth full What Opal does
Discovery, attribution and scoring aren't three tools you run in sequence. Seed a domain once and all three keep working without anyone scheduling them.
Seed a domain or an IP range and Opal keeps enumerating — subdomains, certificates, cloud tenancy, forgotten staging boxes. The inventory is never a snapshot.
Every host resolves to a registrant, a hosting provider and an internal team. Findings route themselves, so nobody spends a morning working out whose box it is.
CVSS tells you what could go wrong in theory. Opal ranks by what is reachable, unauthenticated and actually exercisable from the open internet.
Trusted at scale
The inventory other teams cite in a review, the one an auditor accepts, and the one that still answers when the estate doubles.
Discovery is incremental, so a 40-host startup and a 400,000-host conglomerate get the same first result in minutes. Nothing queues behind a nightly full sweep, and adding a subsidiary doesn't reset your baseline.
Opal replaces the spreadsheet, the scanner export, the DNS side-quest and the Slack thread where someone asks whose box this is. One view, continuously updated, with the evidence attached to the finding.
SOC 2 Type II and ISO 27001 audited annually, read-only by default with no write scopes requested, and regional data residency in the EU, US and AU. FedRAMP Moderate is in progress.
Findings export to Jira, ServiceNow and CSV, and every view has a CLI and an API behind it — so the workflow survives contact with the automation you already run.
The Opal console
Discover the surface, rank what matters, and close it out — all against one continuously updated picture of what you actually expose.
Discovery
Seed one domain. Opal walks outward through certificate transparency, passive DNS, cloud tenancy and registrar records until the picture stops changing — then keeps walking it every four hours.
Seed one domain. Opal walks certificate transparency, passive DNS, cloud tenancy and registrar records until the picture stops changing — then keeps walking it every four hours.
The staging box from a pilot that ended three years ago, the campaign subdomain nobody logged, the bucket a contractor left listable. The assets that were never in the CMDB are the ones this finds.
Six providers and twenty-two teams resolve into one normalised asset list, with the account, the subscription and the owning team attached to every host in it.
Exposure
A critical CVSS behind three firewalls matters less than an unauthenticated admin panel on the open internet. Opal scores reachability first and severity second, so the top of the list is the top of the list.
A critical CVSS behind three firewalls matters less than an unauthenticated admin panel on the open internet. Opal scores reachability first and severity second.
Registrant, hosting provider, cloud account and owning team — resolved automatically, so a finding arrives with a name attached instead of starting a hunt.
A port that opened last night matters more than one that has been open for a year. Every scan is diffed against the last, so the queue leads with what changed rather than with what is merely bad.
Response
Triage in one place with the evidence attached, and hand out a report that a stakeholder can read without anyone rebuilding it in slides first.
Comment, assign and close without leaving the exposure. Every change syncs live, so the response is designed once rather than reconstructed from a Slack thread later.
Closing a ticket is not the same as closing a hole. Opal re-probes the host on the next sweep and reopens the finding itself if the exposure is still answering.
One link gives a stakeholder the whole picture — inventory, exposures, remediation plan and SLA status — without anyone exporting a slide.
Coverage
Opal doesn't care where a host lives. If it answers from the public internet, it's in scope — and if it stops answering, Opal notices that too.
There is no agent, no collector VM and no credential to rotate. Opal sees what an attacker sees, from where an attacker stands.
Map your surfaceStart mapping
Map your external attack surface in minutes. Free for the first 500 assets, no card, no call.