Threat researchers lose confidence in making smart business decisions when sources lack the quality, variety, and depth of threat intelligence needed to prevent disruption. SecurityScorecard's Attack Surface Intelligence (ASI) detects more unknown unknowns, including those of your third-party vendors and how they pose a risk to your business, arming you with deep contextual insights and attribution to prioritize your next steps - all in one single platform.
SecurityScorecard has established itself as the cybersecurity ratings leader. On our path to attaining this industry trust, we have collected security-relevant data over the past 10 years. And we continue to expand and refine processes for gathering, enriching, and normalizing nearly 10 petabytes of raw data.
Significantly, 99 percent of the data on which our ratings and services are based is sourced from in-house collection and analysis operations:
SecurityScorecard's DNS sinkhole collects information about infections from more than 150 malware families without requiring an inside sensor on infected systems or networks. Additionally, our malware attribution system provides automated malware analysis, classification, and tracking at scale. This includes rich information about malware families, threat groups, and campaigns, enabling us to generate issue types and track threat groups.
The platform also contains leaked breach records, consisting of 68 terabytes of processed data, including user names, passwords, social media URLs, Social Security numbers, credit card numbers, addresses, IPs, and more. This data set is comprised of more than 10 billion records.
Our ransomware leak site crawler provides findings specific to ransomware attacks, breaches, and credential leaks. It also provides insight into how the ransomware groups operate, what industries they target, who the victims are, and what data is stolen. Information on more than 40 active ransomware groups is actively tracked and updated daily.
SecurityScorecard operates an extensive honeypot system that provides information about the structure and intentions of advanced persistent threats (APTs) and ransomware groups that actively exploit a particular vulnerability.
We use a Chrome-based web crawler to gather information on all major sites' infrastructure, vulnerabilities, vendor dependencies, screenshots, and more. It detects supply chain dependencies in software and provides data for more than 50 types of issues in Ratings platform's Application Security factor.
For inquiries about a Private Offer (PO) or a Channel Partner Private Offer (CPPO), please contact aws-sales@securityscorecard.io.
Highlights
7B+ Normalized leaked databases records from across the dark web and forums
100B+ Vulnerabilities and attributions published weekly
36M+ Threat actor associations made and growing daily tied to exposed assets, malicious IPs, file hashes, and more.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing bills by requests to the Attack Surface Intelligence search endpoint each month. You pick between two options. The metered option charges for each single request made to the search endpoint per month, so cost rises with how many searches you run. The ASI Free Tier gives you 20 requests to the search endpoint per month at no charge. Both options measure usage the same way, by request volume against the search endpoint. Pricing scales with request count, letting you start small on the Free Tier and pay per request as your search needs grow.
Top-of-mind questions for buyers
What counts as one billable request to the Attack Surface Intelligence search endpoint?
One request equals a single call you make to the search endpoint within a month. The system counts each call separately, so running more searches raises your count. Both options measure the same way, by the number of search endpoint calls made per month.
What happens when I use up the 20 monthly requests included in the ASI Free Tier?
The Free Tier covers 20 search endpoint requests each month at no charge. To search beyond that count, you use the metered option, which charges for each single request per month. Cost then rises with each additional search you run against the endpoint.
Does SecurityScorecard train its models on the searches I run against the endpoint?
According to the vendor, they use foundational models that are not trained on customer input. Query results stay isolated to your own instance, and other users cannot see what you send. This applies to interactions with their AI-driven capabilities.
securityscorecard.com
Helpful?
Vendor refund policy
All fees are non-cancellable and non-refundable except as required by law or as provided in our MSA.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Our Customer Success team is a team of advisors, partners and experts that are here to help you maximize your experience with SecurityScorecard. They help you unleash the full potential of SecurityScorecard, provide guidance on use cases, as well as keep you apprised of new product features. From onboarding and adoption through operationalization and scaling, the Customer Success team will be your partner to ensure you meet your goals as an additional layer to our technical support resources. To reach the Customer Success team contact us at csm@securityscorecard.io. For technical support please contact us at support@securityscorecard.io.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Surface Command breaks down data silos by combining comprehensive attack surface visibility across hybrid environments to build a dynamic 360-degree view of your entire attack surface in one place
Vector Command is a managed service that helps security teams assess external attack surfaces and identify defence gaps. It combines Rapid7's Red Team expertise with top-tier attack surface management technology to provide continuous validation of exposures
Modern Penetration Testing as a Service (PTaaS), Point in Time and Continuous Testing, Attack Surface Visibility, Red Team and Other Security Assessments (Detective Controls, Social Engineering, etc). Contact partners@netspi.com for additional support.
Contact partners@netspi.com for additional support.
RidgeBot, an AI agent for continuous security validation, provides automated penetration testing, attack surface discovery, and vulnerability validation.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.