See the surface. Keep the evidence.
XRAY ASM is my private attack-surface management workbench: one place to discover external surface, normalize inventory, explain relationships, detect meaningful change, and decide what deserves human review.
Five stages, one defensible decision.
The useful output is not another long asset list. XRAY keeps provenance attached while raw signals move through normalization, relationship analysis, prioritization, and operator review.
An operator desk, not a scanner wall.
Each product surface answers a concrete question instead of adding another disconnected dashboard.
Inventory with provenance
Domains, hosts, services, APIs, screenshots, technologies, and mobile surface keep their source and state instead of collapsing into anonymous rows.
Relationships with reasons
Asset connections explain why they exist. Attribution and reachability are reviewed independently, so one graph edge never silently expands scope.
Exposure with lifecycle
Signals can be triaged, accepted, prepared for retest, or rejected with history. Missing evidence does not become an automatic “fixed” state.
Powerful because its limits are explicit.
The public case study states what XRAY owns—and what it deliberately refuses to claim.
XRAY owns
- Continuous discovery and normalized external inventory
- Evidence-backed asset relationships and change history
- Exposure candidates, prioritization, and operator review queues
- Safe metadata handoff into a separately authorized validation workflow
XRAY does not claim
- A scanner observation is automatically a verified vulnerability
- Discovery silently authorizes active testing
- Missing evidence proves remediation or closure
- A public demo or repository represents the private operating system
