- Root domain
- Subdomains and exposed services
- Login portals, admin consoles, APIs
- Public cloud assets and storage
See your external attack surfacebefore attackers do.
Adversary maps your external attack surface and validates real exposures. Exposed API keys, subdomain takeover, leaked secrets. You get a client-ready report in minutes, not weeks.
- map
- validate
- evidence
- report
Minutes
not weeks
First-pass attack surface scan delivered in minutes.
Validated
not scanner noise
Every finding is probed and confirmed, not just enumerated.
Portfolio
or one target
Run one attack surface scan or a hundred.
What goes in. What comes out.
Hand Adversary a target. It runs the first pass end to end: map, validate, capture evidence, prioritize. Built by people who broke detection vendors for a living.

- Attack paths across exposed assets
- Validated findings with evidence and severity
- Remediation guidance and an executive summary
Built to clear the work, not replace the judgment.
Less manual recon
Automate the repetitive mapping, probing, and evidence-gathering work that slows down assessments.
Validated findings only
Ship confirmed exposures, not another noisy scanner report. Every finding is probed before it lands.
More assessment capacity
Run more targets, serve more clients, and scale external attack surface management without adding headcount linearly.
Cleaner client deliverables
Hand clients a structured, client-ready report your team edits and sends, instead of reformatting raw scanner output.
Human review stays intact
Experts still review, interpret, and sign off. Nothing reaches a client without a human in the loop.
Built for startups and MSSPs
Run an attack surface scan for startups, recurring portfolio reviews, or pre-engagement recon.
What Legba returns.
Validated findings in a client-ready report your team can review, edit, and send.
- target loaded
- external surface mapped
- exposed services identified
- subdomain takeover validated
- exposed API key confirmed
- attack path assembled
- evidence captured
- severity assigned
- remediation drafted
- report ready for review
elapsed
08m 14s
findings
46
validated
11
Attack paths
How exposed assets and weaknesses connect into real risk.
Validated findings
Confirmed exposures with evidence: exposed API keys, subdomain takeover, leaked secrets. No scanner noise.
Evidence capture
Screenshots, request and response detail, affected assets, and reproduction notes where applicable.
Severity and priority
Clear ranking so teams know what to fix first.
Remediation guidance
Plain-English next steps for closing the exposure.
Executive summary
A readable overview for clients, operators, and non-technical stakeholders.
- Automates first-pass external attack surface management.
- Validates real exposures where scoped, instead of just listing them.
- Maps attack paths across exposed assets.
- Returns validated findings with evidence.
- Lets teams move faster across many targets.
- It does not replace senior security judgment.
- It does not remove the need for authorization and scope.
- It does not replace formal compliance sign-off by itself.
- It does not fix issues without human remediation.
- It does not turn scanner output into truth without review.
Legba does not replace the expert. It removes the repetitive work before the expert steps in.
Go deeper on what Adversary finds
- Exposure libraryDetection, validation, and remediation guides for every finding type Adversary surfaces.
- EASM glossaryPlain-language explainers for reconnaissance, asset discovery, and validation.
- Exposed API keys scannerWhere API keys and secrets leak across your surface, and how Adversary validates the real ones.
- Free attack surface scanRequest a first-pass external scan for your startup. Validated findings, not scanner noise.
- Browser threat playbooksHow modern attacks start in the browser, with practical checklists.
- Research hubBrowser isolation, AI security, and threat research that supports the engine.
Related surfaces
Adversary is one Legba surface, not the whole engine.
Adversary is the assessment-automation surface inside the broader Legba family. Use the related pages below to evaluate browser isolation, isolated agent execution, and the research that supports the engine.
Browser isolation for everyday workflows
Same disposable browser engine, shipped as a Chrome extension for individual users and teams who want isolation without changing how they browse.
ExploreRun autonomous AI agents in an isolated sandbox
Evaluate coding agents in a one-click cloud environment that has zero access to your real machine and is destroyed on close.
ExploreRead the engine and isolation explainers
Browser isolation, AI security, and threat explainers that support the commercial product story with practical detail.
ExploreAccess anything.
Expose nothing.
Legba is a disposable real browser: it spawns a clean session, does the work, and destroys itself on close.
chromium / real fingerprint · residential ip · burn on close
Real browser. Real IP. Real page. Spawn a session. Do the work. Destroy it. Off your device. Off your stack. Gone on close.