RECURSOS
Whitepapers, datasheets & materiais.
Estudos de cibersegurança, especificações técnicas e materiais aprofundados — conteúdo técnico para equipes de segurança, não material de marketing.
report
State of Digital Exposure · 2026 Edition
CSURFACE annual report with the aggregated, anonymized panorama of observed digital exposure — attack-surface, supplier-chain and credential…
datasheet
Compliance Matrix · CSURFACE × Regulations
Direct mapping of seven CSURFACE controls to the specific clauses of nine regulatory frameworks — NIST CSF, ISO 27001:2022, CIS Controls v8,…
datasheet
CSURFACE × Embedded EASM · Capability Comparison
Objective, capability-by-capability comparison between CSURFACE (dedicated ASM) and the EASM embedded in Microsoft Defender, Tenable, Qualys…
datasheet
CSURFACE Platform · Architecture and Capabilities
Two-page datasheet covering architecture, deployment, security posture and the platform's four capabilities — Machine Learning with an agent…
whitepaper
CTEM — from the Gartner framework to an operational program
Independent technical guide to Continuous Threat Exposure Management: the Gartner framework, the five phases (Scoping, Discovery, Prioritiza…
whitepaper
Implementation Guide: Cyber Risk Quantification
The complete version — a step-by-step guide to establishing and operating a CRQ program: obstacles, the limits of 5×5 matrices, the FAIR met…
whitepaper
The exposure window between the scheduled scan and remediation
Exposure Window: the acceleration of exploitation (Mandiant M-Trends), seven recent public cases (Log4Shell, Spring4Shell, Citrix Bleed, F5,…
whitepaper
Converting technical risk into financial decisions
Cyber Risk Quantification: a guide to the FAIR methodology for translating cyber exposure into ALE and VaR — in financial terms, for the aud…
whitepaper
Leaked credentials: the interval between exposure and discovery
Credential Leakage Monitor: why continuous monitoring of leaked credentials outperforms point-in-time audits, and how to shorten the interva…
whitepaper
Vulnerability prioritization beyond CVSS
Threat Intelligence and dynamic prioritization: how to get the remediation queue right by combining technical severity, observed active expl…
whitepaper
Digital supplier-chain risk: exposure inherited from third parties
Digital Supply Chain Risk: from the Polyfill.io case to subdomain takeover. Public cases (MageCart at British Airways, Ticketmaster/Inbenta,…
whitepaper
The real attack surface and what the official inventory does not record
Context-aware discovery with Machine Learning: why subdomain enumeration reveals only a fraction of the real attack surface — and how to ide…