The Purplemet Web Attack Surface Management Platform is a continuous monitoring and security assessment tool that maps an organization's entire web ecosystem. Starting from a domain name or IP address range, it automatically discovers public web applications, URLs, hidden assets, shadow IT, and rogue applications. The platform conducts non-intrusive scans using a technology cascade detection method and an extensive component database to identify underlying web technologies without impacting system performance or availability.
The system evaluates web properties to detect CVEs, SSL/TLS vulnerabilities, misconfigured admin panels, debug modes, sensitive services, authentication methods, and API endpoints. Additionally, it assesses domain health by checking security standards such as DNSSEC, DKIM, DMARC, CAA, SPF, SMTP TLS, and DANE. Detected vulnerabilities are automatically prioritized based on NIST EPSS and CISA KEV scoring for severity, exploitability, and impact, providing real-time alerts and actionable remediation insights.