RECURSOS

Whitepapers, datasheets & materiais.

Estudos de cibersegurança, especificações técnicas e materiais aprofundados — conteúdo técnico para equipes de segurança, não material de marketing.

report

State of Digital Exposure · 2026 Edition

CSURFACE annual report with the aggregated, anonymized panorama of observed digital exposure — attack-surface, supplier-chain and credential…

datasheet

Compliance Matrix · CSURFACE × Regulations

Direct mapping of seven CSURFACE controls to the specific clauses of nine regulatory frameworks — NIST CSF, ISO 27001:2022, CIS Controls v8,…

datasheet

CSURFACE × Embedded EASM · Capability Comparison

Objective, capability-by-capability comparison between CSURFACE (dedicated ASM) and the EASM embedded in Microsoft Defender, Tenable, Qualys…

datasheet

CSURFACE Platform · Architecture and Capabilities

Two-page datasheet covering architecture, deployment, security posture and the platform's four capabilities — Machine Learning with an agent…

whitepaper

CTEM — from the Gartner framework to an operational program

Independent technical guide to Continuous Threat Exposure Management: the Gartner framework, the five phases (Scoping, Discovery, Prioritiza…

whitepaper

Implementation Guide: Cyber Risk Quantification

The complete version — a step-by-step guide to establishing and operating a CRQ program: obstacles, the limits of 5×5 matrices, the FAIR met…

whitepaper

The exposure window between the scheduled scan and remediation

Exposure Window: the acceleration of exploitation (Mandiant M-Trends), seven recent public cases (Log4Shell, Spring4Shell, Citrix Bleed, F5,…

whitepaper

Converting technical risk into financial decisions

Cyber Risk Quantification: a guide to the FAIR methodology for translating cyber exposure into ALE and VaR — in financial terms, for the aud…

whitepaper

Leaked credentials: the interval between exposure and discovery

Credential Leakage Monitor: why continuous monitoring of leaked credentials outperforms point-in-time audits, and how to shorten the interva…

whitepaper

Vulnerability prioritization beyond CVSS

Threat Intelligence and dynamic prioritization: how to get the remediation queue right by combining technical severity, observed active expl…

whitepaper

Digital supplier-chain risk: exposure inherited from third parties

Digital Supply Chain Risk: from the Polyfill.io case to subdomain takeover. Public cases (MageCart at British Airways, Ticketmaster/Inbenta,…

whitepaper

The real attack surface and what the official inventory does not record

Context-aware discovery with Machine Learning: why subdomain enumeration reveals only a fraction of the real attack surface — and how to ide…