Defensio XT
on-premise external attack surface management with continuous scanning

The component dedicated to continuously scanning the assets you expose to the internet. XT works only from the outside, looking at your public perimeter exactly the way a real attacker would.

It stands on its own. Defensio XT is bought and used completely independently. You do not need the SOC, a Sensor or the cloud platform. Like the Sensor, it is an autonomous product: install it on your own infrastructure — a VPS, a dedicated server, a cloud node — and it starts working as an external attack surface management engine.

Continuous attack surface management

Traditional vulnerability assessments happen once, or on a calendar. XT runs continuously: automated scan cycles that keep finding what changed.

External vulnerability assessment

Systematic identification of known vulnerabilities on the assets you expose to the internet.

Subdomain discovery

Automatic mapping of forgotten, undocumented or shadow IT assets — cloud instances, exposed APIs, orphaned databases.

TLS and certificate audit

Full review of cipher suites, supported protocols, configuration and certificate weaknesses.

DNS and email security

Checks on SPF, DKIM and DMARC configuration, to stop your domain being used for spoofing and abuse.

Security headers

Analysis of HTTP and HTTPS headers against the accepted application security practice.

Web application testing

Active and passive scanning of the web applications you have published.

Perimeter discovery

Continuous mapping of the ports, services and assets reachable from the internet.

Digital identity protection

Monitoring of company credentials in breach databases, performed locally on your own instance.

How an instance is set up

Every XT instance operates with a dedicated public address, separate from the one you browse from, with redundant instances for load distribution and continuity. XT runs on ordinary server resources: the deterministic scanning engines need no specialised hardware, and nothing about the product assumes you have any.

XT can also be connected to the SOC. In that case its results join centralised correlation alongside those of the Sensors, for a complete picture of risk from inside and outside at once. The connection is a choice, not a requirement in either direction: an organisation that runs the SOC can keep external scanning wherever it prefers.

Prioritisation that reflects reality

XT contextualises each finding against global threat intelligence. A vulnerability rated high that has an exploit circulating today is raised to critical, because it is. Every finding gets a priority based on the real risk of exploitation against your specific infrastructure, rather than the score alone.

Who runs XT

It suits any organisation with assets exposed to the internet that wants their security verified continuously rather than annually.

Web agencies and software houses

Test the security of the sites and applications you build for clients, from a small site on shared hosting to an enterprise application on a dedicated server, before and after go-live.

Developers and DevOps

Put security scanning inside the development cycle. Each deploy to staging or production gets checked for misconfiguration, expiring certificates, missing headers and application flaws.

Managed service providers

Offer continuous external security monitoring to your own customers. XT runs autonomously on your infrastructure, with full operational control and customisable reporting.

Internet service providers and datacentres

Keep continuous watch on your own exposed assets and your customers’ — address space, published services, certificates — and offer external scanning as a service on top.

Distributed infrastructure

Watch dozens of domains, web applications, APIs and exposed services from a single point of control, with automated scans and proactive alerting.

E-commerce and online platforms

Keep the storefront, the payment gateway and the API integrations continuously checked against web vulnerabilities and configuration mistakes.

XT or SECaaS?

Both cover the same ground — continuous external scanning — with very different models.

Defensio XT

Installed on your own infrastructure, with full operational control and full control of the data. It suits organisations that manage security internally, and providers that want to operate independently and bill it on.

Defensio SECaaS

Nothing to install: the whole infrastructure is supplied and run by Fidem, and you buy it online. It suits anyone who wants monitoring immediately, without an infrastructure decision first.

Compare the SECaaS plans →

Reporting is included

Like every Defensio component, XT includes the next-generation reporting engine, which turns raw scan and monitoring data into professional documents: tactical visualisations, severity charts, exposure maps and prioritised recommendations. Available as executive, technical, compliance and custom formats, generated and delivered on schedule.

Common questions

Do we have to install anything on our systems?

Nothing on the systems being scanned. XT itself runs on infrastructure you choose — yours or ours — and all it needs is authorisation to scan assets you own.

How is this different from a penetration test?

XT is continuous automated surveillance with verification of findings; a penetration test is a manual exercise at a point in time. They complete each other: XT tells you every day what is exposed, the pentest goes deep when it needs to.

Do we need special hardware for it?

No. The scanning engines are deterministic and run on ordinary server resources. Specialised hardware is not part of the product.

How often does it scan?

On the schedule you agree — typically continuous cycles with recurring full checks. Newly discovered assets enter the monitored perimeter automatically.

Set up your external scanning engine

Talk to us about XT and we will size the instance to the perimeter you actually have.

Talk to us about XT

Explore the ecosystem: All products · Defensio SOC · Defensio Sensor · Defensio SECaaS · Identity Shield