Attack surface management tools, in one platform
Most security teams stitch together a scanner, a breach-data feed, a certificate monitor and a vendor questionnaire. PuReAI runs all of it from a single domain: 12 OSINT modules discover the external attack surface, and an AI threat graph explains what actually matters — with one Risk Score per company.
The 12 modules behind the score
Every module feeds one of four segments. The segments are weighted into a single Company Risk Score, so a discovery finding and a breach record are comparable instead of living in separate tools.
Exposure surface
10% of Risk Score- Domain — Enumerates domains, subdomains and DNS records tied to the organisation.
- IP — Maps hosts, open ports and services reachable from the internet.
- Certificate — Tracks TLS certificates, issuers and expiry across the estate.
- Technology — Fingerprints the stack running on each exposed asset.
Issues
30% of Risk Score- Vulnerability — Matches detected products and versions against NVD and CISA KEV.
- Misconfiguration — Flags weak DNS, mail and TLS configuration on discovered assets.
Compromises
40% of Risk Score- Leaked Data — Surfaces credentials and records exposed in third-party breaches.
- Git Leaks — Scans public repositories for secrets and tokens.
- Sensitive Files — Finds indexed documents and backups that should not be public.
Threats & supply chain
20% of Risk Score- Lookalike — Detects typosquatted and impersonating domains.
- News / Threats — Correlates ransomware actor activity and MITRE ATT&CK TTPs.
- Supply Chain — Scores vendors and partners for DORA and NIS2 obligations.
Ask the attack surface a question
Classic ASM tools hand you a list. PuReAI builds a graph of assets, CVEs, ransomware actors and MITRE ATT&CK techniques, then lets analysts query it in plain language: which vendors are exposed to a given CVE, which actors target this sector, what changed since last week.
Built for DORA and NIS2 reporting
Third-party risk is scored continuously rather than annually. Supply chain findings, vendor CVEs and breach evidence are tracked per domain, so evidence for regulatory reporting comes out of the same toolset that runs discovery.
