Passive external exposure monitoring for known internet-facing assets with Splunk integration.
External Exposure Monitor is a lightweight security monitoring solution that continuously monitors known public assets using passive OSINT sources and forwards normalized exposure data to Splunk for visualization, alerting, and analysis.
The project is designed for SOC teams to identify newly exposed services and changes in an organization's external attack surface without performing active scanning.
- Passive external exposure monitoring
- Shodan-based asset intelligence
- Asset inventory support (IP/CIDR)
- Event normalization
- Splunk HTTP Event Collector (HEC) integration
- Exposure change detection
- Risk scoring
- Dashboards and alerts
- Python
- Splunk Enterprise
- Shodan API
- Censys [Internet wide scanner]
- Netlas.io [Internet wide scanner]
- Docker
- AWS EC2
Under active development.
![]() Venkat Vellapalem Contributor | ![]() Are Imanth Contributor |
This project is licensed under the MIT License.

