Skip to content

Repository files navigation

External Exposure Monitor

Passive external exposure monitoring for known internet-facing assets with Splunk integration.


Overview

External Exposure Monitor is a lightweight security monitoring solution that continuously monitors known public assets using passive OSINT sources and forwards normalized exposure data to Splunk for visualization, alerting, and analysis.

The project is designed for SOC teams to identify newly exposed services and changes in an organization's external attack surface without performing active scanning.


Features

  • Passive external exposure monitoring
  • Shodan-based asset intelligence
  • Asset inventory support (IP/CIDR)
  • Event normalization
  • Splunk HTTP Event Collector (HEC) integration
  • Exposure change detection
  • Risk scoring
  • Dashboards and alerts

Technology Stack

  • Python
  • Splunk Enterprise
  • Shodan API
  • Censys [Internet wide scanner]
  • Netlas.io [Internet wide scanner]
  • Docker
  • AWS EC2

Project Status

Under active development.


Collaborators

Venkat
Venkat Vellapalem

Contributor
Collaborator
Are Imanth

Contributor

License

This project is licensed under the MIT License.

About

The repository contains detailed explanation and working flow of an lightweight EASM tool which integrates the attack surface information into the splunk

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages