AppSecNews
DAST Commercial Established

Detectify

by Detectify

Hosted platform that maps an organization's internet facing assets and tests them with checks built from findings submitted by a private hacker community.

Visit detectify.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Detectify in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
  • Integration list: partially confirmed, verify against vendor docs
  • Current product module names and how surface monitoring and application scanning are packaged: verify

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Detectify starts from the domain rather than the application. Given a root domain it enumerates subdomains continuously, fingerprints what is running on each host, and keeps a live inventory of the internet facing estate including assets nobody remembered were there. It watches that inventory for change: a new subdomain, a service that appeared, a DNS record pointing at a decommissioned provider and therefore takeover prone.

Against discovered assets it runs security tests. The distinguishing mechanism is where those tests come from. Detectify operates a private community of invited security researchers who submit vulnerability findings and reproductions, and the platform's engineers convert accepted submissions into automated checks that then run across every customer's estate. That gives the check library a bias toward real world, currently exploited issues in specific products and frameworks, rather than only generic vulnerability classes. A separate application scanning capability performs deeper crawling and testing of a nominated web application, including authenticated coverage.

Where it fits

This is a security team tool that runs continuously against production, not a pipeline step. It is most often bought to answer the question of what is actually exposed, which is a problem of inventory before it is a problem of vulnerabilities. Alerts route to chat or ticketing. It requires domain ownership verification, and it works best when someone owns the response process, because the whole point is that new findings arrive on their own schedule rather than when you run a scan.

Strengths

  • Subdomain discovery and continuous monitoring surface forgotten and shadow assets, which is where a large share of real breaches begin.
  • Crowdsourced check pipeline produces detection for specific, current issues faster than a purely internal research function typically manages.
  • Subdomain takeover detection is handled well and is a class most application scanners ignore entirely.
  • Alerting is continuous rather than scan cycle bound, so exposure windows are short.

Limitations

  • Deep application testing is not its strength. If your need is thorough assessment of one complex authenticated application, a dedicated scanner or a manual test will go further.
  • Coverage is external by definition. Internal applications and anything not reachable from the internet are outside its model.
  • Findings volume on a large estate can be significant, and without an owner the alert stream becomes background noise.
  • Business logic and authorization flaws are not addressed.

Who it suits

Good for organizations with sprawling internet facing infrastructure, frequent domain and subdomain churn, acquisitions, or marketing sites standing up outside engineering control. Less appropriate for a team with a single well understood application and no discovery problem, where the money is better spent on depth of testing than on breadth of surface mapping.

Used Detectify? Recommend it under your own name and title.

Recommend this tool