Detectify
Editorial coverage of Detectify.
Detectify is an external attack surface management and application security platform whose automated tests are derived in part from a curated ethical hacker community.
Who makes Detectify
Detectify publishes the platform directly at detectify.com and operates Crowdsource, a curated ethical hacker programme that feeds researcher findings into its automated test library.
Official website: detectify.com ↗
What it actually does
Two documented products sit on one platform: Surface Monitoring, which continuously discovers and watches internet-facing domains, subdomains, hosts and exposed services including subdomain takeover conditions; and Application Scanning, which performs deeper crawl-based and authenticated testing of nominated web applications.
Product family
- · Surface Monitoring
- · Application Scanning
- · Crowdsource researcher programme
What people hire it for
- Inventorying and monitoring a large external attack surface
- Detecting subdomain takeover risk and forgotten hosts
- Authenticated scanning of nominated web applications
- Keeping automated tests aligned with real-world attacker technique
- Pulling findings into an existing security programme via API
Where it runs
Security & privacy
Detectify is hosted SaaS and testing runs from its own infrastructure against assets the customer verifies they control. No on-premise deployment model appears in its published material, and internal network testing is out of scope.
Where Detectify appears
Featured in these buying guides
Not yet included in a Best-Of round-up. Editorial planned for the next update cycle.
Head-to-head
Planned
- Detectify vs Bitdefender — coming soon
- Detectify vs Norton — coming soon
Planned reviews
Full review published — read it here.
Read next
- CyberSuitePenetration testing, dark web monitoring and security awareness training sold as one SMB subscription instead of a consulting engagement.
- IntruderContinuous vulnerability management and external attack-surface scanning for SMB and mid-market engineering teams.
- PenteraAutomated security validation that emulates attacks across internal, external and cloud environments for enterprise security teams.
- HackerOneResearcher-powered platform for vulnerability disclosure, bug bounty programmes and scoped penetration testing.