Cyber due diligence
Check a target company's internet exposure before close
Capture what is public now so the deal team has a baseline.
The question
Does management's asset list match what is visible online?
FullHunt builds a dated view of the target's public infrastructure. The diligence team can compare it with management's inventory before close, then check the same assets after the transaction.
How it works
01
Set the target
Start with the legal entity, its known domains, and the agreed transaction scope.
02
Compare the inventories
Put management's list beside FullHunt's observed domains, hosts, services, and certificates.
03
Investigate the differences
Check mapped CVEs, exploit records, credential exposure, and suspected lookalike domains.
04
Save the snapshot
Give the deal team a dated report for remediation planning and the post-close review.
The records behind the answer
Observed footprint
Public domains and infrastructure attributed to the target.
Earlier relationships
Passive DNS and prior observations for infrastructure that changed before review.
Exposed vulnerabilities
Mapped CVEs and exploit records on services visible during the assessment.
Credential and domain findings
Credential exposure, suspected phishing, and typosquatting records where available.
A dated record the deal team can revisit after close.
This supports technical diligence. It does not replace legal, financial, privacy, or internal security review.
What you get
- The target's observed public asset inventory
- Current and earlier infrastructure relationships
- Vulnerability, exploit, credential, and domain findings
- A baseline for post-close comparison
Compare the target's inventory with the public record.
See which FullHunt fields are available for the assessment and post-close monitoring.