Skip to content
FullHunt

Cyber due diligence

Check a target company's internet exposure before close

Capture what is public now so the deal team has a baseline.

Target inventory Public footprint Infrastructure history Dated report

The question

Does management's asset list match what is visible online?

FullHunt builds a dated view of the target's public infrastructure. The diligence team can compare it with management's inventory before close, then check the same assets after the transaction.

How it works

01

Set the target

Start with the legal entity, its known domains, and the agreed transaction scope.

02

Compare the inventories

Put management's list beside FullHunt's observed domains, hosts, services, and certificates.

03

Investigate the differences

Check mapped CVEs, exploit records, credential exposure, and suspected lookalike domains.

04

Save the snapshot

Give the deal team a dated report for remediation planning and the post-close review.

The records behind the answer

Observed footprint

Public domains and infrastructure attributed to the target.

Earlier relationships

Passive DNS and prior observations for infrastructure that changed before review.

Exposed vulnerabilities

Mapped CVEs and exploit records on services visible during the assessment.

Credential and domain findings

Credential exposure, suspected phishing, and typosquatting records where available.

A dated record the deal team can revisit after close.

This supports technical diligence. It does not replace legal, financial, privacy, or internal security review.

What you get

  • The target's observed public asset inventory
  • Current and earlier infrastructure relationships
  • Vulnerability, exploit, credential, and domain findings
  • A baseline for post-close comparison

Compare the target's inventory with the public record.

See which FullHunt fields are available for the assessment and post-close monitoring.