Gain complete visibility and control over your organization's internet-facing assets, identify vulnerabilities, and map attack paths to proactively strengthen your security posture.
RiskProfiler's External Attack Surface Management module empowers organizations to uncover their entire internet-exposed asset inventory, including cloud connections, mobile applications, and on-premise systems. Leveraging advanced vulnerability intelligence and threat detection, it identifies risks and attack paths that hackers could exploit. With integrations for AWS, GCP, Azure, and other platforms, this module provides actionable insights, attack path analysis with security graphs, and real-time threat intelligence to help you mitigate risks effectively. Additionally, the Trust Center and seamless integrations ensure robust protection tailored to your digital ecosystem.
Highlights
Discover internet-exposed systems with seamless integrations across AWS, GCP, and Azure for full visibility of your digital footprint.
Leverage real-time vulnerability insights, threat detection, and attack path analysis with visual security graphs to identify and mitigate risks efficiently.
Monitor mobile applications, streamline workflows with advanced integrations, and centralize threat insights in the Trust Center for actionable security management.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
Gain foundational visibility into your attack surface with continuous monitoring for up to 1,000 assets. Strengthen security by identifying and addressing vulnerabilities.
$36,960.00
Professional Plan
Expand monitoring to 6,000 assets with advanced vulnerability scanning, detailed reporting, and seamless tool integrations for comprehensive protection.
$55,440.00
Enterprise Plan
Unlimited asset monitoring with tailored solutions, enterprise-grade threat detection, and dedicated support for large-scale environments.
You choose one of three plans based on how many external assets you need to monitor. The Essential Plan covers up to 1,000 assets for foundational visibility. The Professional Plan raises coverage to 6,000 assets and adds advanced vulnerability scanning, detailed reporting, and tool integrations. The Enterprise Plan removes the asset limit and adds tailored solutions and dedicated support for large environments. Pricing scales by asset count and capability, so the tier you pick reflects the size of your attack surface. All plans are sold as a contract billed in units.
Top-of-mind questions for buyers
What counts as one asset for billing across the plans?
An asset is any internet-facing item RiskProfiler discovers and monitors. This includes domains, IP addresses, cloud resources, services, and forgotten systems across your external attack surface. Each discovered item counts toward your plan's asset limit, so the count reflects the size of your monitored external footprint.
What happens to my cost if my monitored assets grow past my plan's limit?
Each plan sets an asset ceiling: 1,000 for Essential and 6,000 for Professional. If your footprint grows past that ceiling, you move to a plan with more capacity. The Enterprise Plan removes the asset limit entirely, so growth does not require another upgrade for asset count.
What capabilities distinguish the plans beyond asset count?
Essential gives foundational monitoring and vulnerability identification. Professional adds advanced vulnerability scanning, detailed reporting, and tool integrations such as ticketing workflows. Enterprise adds tailored solutions, enterprise-grade threat detection, and dedicated support for large environments. So the plan you pick reflects both your asset volume and the depth of features you need.
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Protect your brand reputation with advanced detection and remediation of brand abuse, impersonation, and online threats across social media, surface, deep, and dark web.
CloudSEK's BeVigil Enterprise offers a comprehensive Attack Surface Fingerprinting and Monitoring solution, empowering organizations to identify, monitor, and secure their dynamic attack surfaces, including asset changes, network threats, and vulnerabilities. BeVigil Enterprise puts organizations in control of their external attack surfaces, enabling them to effectively mitigate associated risks.
Continuous discovery and monitoring of your entire external attack surface. Hadrian's event-driven architecture finds every asset hackers could target and prioritizes exposures from the attacker's perspective.
Adaptive TPRM That Automates Questionnaires and Keeps Risk Assessments Up to Date
Reviewed on Sep 04, 2026
Review provided by G2
What do you like best about the product?
The adaptive TPRM process is the strongest area for our use case. Questionnaires can be distributed automatically, follow-up questions can adjust to previous answers, compliance controls are mapped, and risk assessments update when vendor posture or supporting evidence changes.
What do you dislike about the product?
Understanding the logistics behind vendor scoring and benchmarking takes some time.
What problems is the product solving and how is that benefiting you?
RiskProfiler has streamlined vendor onboarding and periodic reassessment with its AI agents, improving the workflows from a simple static checklist. The combination of questionnaire evidence, external exposure, and attack-path context gives us a more current view of third-party risk.
Information Technology and Services
Identity Exposure + EASM: Clear Visibility Into Attack Paths
Reviewed on Sep 04, 2026
Review provided by G2
What do you like best about the product?
The connection between identity exposure and EASM is what I value most. Exposed credentials can be evaluated alongside internet-facing services and potential attack paths into sensitive applications.
What do you dislike about the product?
The platform offers services for different threat modules, making initial onboarding and understanding a bit complex.
What problems is the product solving and how is that benefiting you?
The platform's agentic AI engine helps us understand how an external leak or exposed service might be used as the first step in a broader compromise. That context improves decisions around authentication controls and unnecessary access.
Information Technology and Services
RiskProfiler Unifies Threat Intelligence Across Dimensions with AI-Powered Insights
Reviewed on Sep 04, 2026
Review provided by G2
What do you like best about the product?
A major strength is the ability to examine a threat across several dimensions from one platform. RiskProfiler can link suspicious domains and impersonation activity with hosting infrastructure, internet-facing assets, vulnerabilities, compromised identities, third parties, and potential attack routes. AI-assisted data collection and analysis expose these connections while reducing manual investigation.
What do you dislike about the product?
The breadth of available information can feel extensive for a new user, so saved views and role-specific dashboards are helpful.
What problems is the product solving and how is that benefiting you?
RiskProfiler gives us a consolidated perspective across external attack-surface management, third-party risk, brand and domain protection, phishing, vulnerability intelligence, identity exposure, and cyber threat intelligence. Analyst review remains important, but the connected evidence helps our team investigate threats and set priorities more quickly.
Recommendations to others considering the product:
To enhance user experience, consider offering guided tutorials and interactive demos to help new users navigate the platform effectively.
Sanjay K.
Actionable threat intelligence tailored to our exposure
Reviewed on Sep 02, 2026
Review provided by G2
What do you like best about the product?
The threat-intelligence capability brings together signals related to our assets, suppliers, domains, identities, and known vulnerabilities. AI-supported analysis highlights meaningful connections and provides useful context, reducing the need to investigate each indicator individually.
What do you dislike about the product?
Wide-ranging intelligence feeds may initially generate lower-priority findings. Refining relevance criteria, alert thresholds, and notification preferences helps ensure the most important activity receives attention.
What problems is the product solving and how is that benefiting you?
RiskProfiler has made threat intelligence more actionable by identifying activity with a direct relationship to our organisation. Built-in enrichment and relationship mapping give analysts a stronger starting point, allowing investigations to progress more efficiently.
Information Technology and Services
Valuable Phishing Detection with Rich Attack-Surface Context and Insights
Reviewed on Sep 02, 2026
Review provided by G2
What do you like best about the product?
Combining phishing detection with external attack-surface monitoring and attack-path insights gives us valuable context. When the platform identifies an impersonation site or suspicious domain, we can examine associated infrastructure, certificates, identities, and any potential links to our organization.
What do you dislike about the product?
Notification settings can take some refinement during high-activity campaigns so that relevant alerts are routed to the correct response teams.
What problems is the product solving and how is that benefiting you?
The solution has simplified phishing investigations by bringing previously fragmented capabilities into one place. We can assess a campaign, determine which identities may be exposed, and organize remediation efforts with greater speed.