# Shadowyard

*/Startups/Shadowyard*

## Startup Overview

Enterprise security teams struggle to track internet-facing infrastructure as engineering units spin up and abandon temporary environments. The platform eliminates this blind spot by continuously enumerating orphaned subdomains and unmanaged cloud instances. It maps the complete external perimeter and identifies exposed assets before threat actors can find and exploit them.

Traditional discovery methods rely on manual OSINT audits or legacy network scanners that fail to match the velocity of modern cloud provisioning. Even heavy enterprise alternatives like Palo Alto Cortex Xpanse demand complex internal integrations. By deploying completely agentless, this solution bypasses internal friction entirely. It synchronizes external asset state in real time, delivering an exact, live inventory of the attack surface without requiring a single endpoint installation.

## Startup Founding Hypothesis

**Approach**: that continuously enumerates orphaned subdomains and unmanaged cloud instances
**Competitors**:
- [Palo Alto Cortex Xpanse](/Competitors/Palo_Alto_Cortex_Xpanse)
- [Legacy Network Scanners](/Competitors/Legacy_Network_Scanners)
- [Manual OSINT Audits](/Competitors/Manual_OSINT_Audits)
**Differentiator2x2**: fully agentless to deploy and synchronizes external asset state in real time

## Startup Solution Coordinate

**Solution**: [Shadowyard Asset Mapper](/Software/Shadowyard_Asset_Mapper)

## Startup Position2x2

```mermaid
quadrantChart
    title Position vs Competitors
    x-axis Requires Agents/Heavy Setup --> Fully Agentless
    y-axis Periodic Static Scans --> Real-Time State Synchronization
    quadrant-1 Continuous & Agentless
    quadrant-2 Continuous & Heavy
    quadrant-3 Periodic & Heavy
    quadrant-4 Periodic & Agentless
    Legacy Network Scanners: [0.25, 0.25]
    Manual OSINT Audits: [0.90, 0.15]
    Palo Alto Cortex Xpanse: [0.75, 0.70]
    Shadowyard: [0.85, 0.85]
```

## Startup Customer Journey

```mermaid
flowchart LR
    A[AWS Marketplace] --> B[DNS Exposure Audit]
    B --> C[Orphaned DNS Record]
    C --> D[Continuous Asset Feed]
    D --> E[Cloud Identity Provider]
    E --> F[Threat-Hunting Agent]
```

## Startup Proof Points

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**Pilot Goals**:
- 14-day passive discovery pilot: Aiming to identify at least 3 previously unknown, unmanaged cloud assets or orphaned subdomains that the client's legacy network scanner missed.
- 30-day API integration pilot: Targeting the successful real-time routing of newly discovered external assets into the client's SIEM within 5 minutes of a developer standing up the shadow infrastructure.
**Target Metrics**:
- Target: <5 minutes mean-time-to-discovery (MTTD) for newly exposed orphaned subdomains.
- Target: 0 agent deployments required to achieve a complete external perimeter map.
- Target: <15 minutes initial time-to-value to generate the first complete external attack surface baseline.
- Aim: 100% detection rate of unmanaged cloud infrastructure tied to corporate domains via TLS and DNS validation.
**Target Case Studies**:
- Mid-market fintech Security Operations Center (SOC) team: Validating the ability to discover and shut down forgotten legacy staging environments and orphaned subdomains before they face exploitation.
- Enterprise retail Chief Information Security Officer (CISO) managing acquisitions: Demonstrating the mapping of a newly acquired subsidiary's entire external attack surface within 24 hours without requiring network credentials or agent deployments.
- Lean B2B SaaS security engineer: Proving the detection of shadow IT cloud instances spun up by developers on non-corporate AWS accounts by monitoring global certificate transparency logs.
**Testimonial Targets**:
- Chief Information Security Officer (CISO): Shock at the volume of shadow IT existing outside known AWS billing accounts, combined with relief that it is now continuously mapped without manual intervention.
- SOC Analyst: Appreciation that the active DNS and TLS certificate matching filters out unowned assets, saving hours previously spent chasing false positives from legacy scanners.
- DevSecOps Engineer: Validation that the API webhook seamlessly feeds newly discovered unmanaged assets directly into their existing vulnerability management pipeline in real time.

## Startup Top Risks

**Risks**:
- Severity: existential · Description: Major cloud providers enforce strict rate limits or block the platform's unauthenticated scanning heuristics, breaking the core asset discovery engine. · Mitigation Status: in-progress
- Severity: high · Description: Enterprise security teams consolidate their toolchain and opt for the bundled Palo Alto Cortex Xpanse module over a standalone point solution. · Mitigation Status: unmitigated
- Severity: moderate · Description: The real-time synchronization engine triggers overwhelming false positives when monitoring intentionally ephemeral infrastructure like auto-scaling container workloads. · Mitigation Status: in-progress
- Severity: low · Description: Inconsistent API structures across legacy domain registrars prevent the agentless scanner from mapping historical or deeply nested DNS records. · Mitigation Status: mitigated

## Startup Competitors

- [Palo Alto Cortex Xpanse](/Competitors/Palo_Alto_Cortex_Xpanse) — Incumbent EASM
- [Legacy Network Scanners](/Competitors/Legacy_Network_Scanners) — Status Quo
- [Manual OSINT Audits](/Competitors/Manual_OSINT_Audits) — DIY
- [Tenable ASM](/Competitors/Tenable_ASM) — Incumbent
- [Qualys CSAM](/Competitors/Qualys_CSAM) — Legacy Platform

## Startup Token Hero

**Genre**: founding-hypothesis
**Rendered**: What if you could see every unmanaged cloud instance the moment it's spun up? Shadowyard continuously enumerates orphaned subdomains and abandoned assets, giving you total perimeter visibility before attackers find a way in.
**Mechanism**: spine-derived-v1
**Template Id**: spine-founding-hypothesis
**Vocab Fingerprint**: c01ff7b7c232ede4

## Startup Token Positioning

**Genre**: moore-positioning
**Rendered**: External Attack Surface Management for CISO at high-growth enterprise companies. Unlike Palo Alto Cortex Xpanse — detect orphaned subdomains and unmanaged cloud instances in real time.
**Mechanism**: spine-derived-v1
**Template Id**: spine-moore-positioning
**Vocab Fingerprint**: 93f217dbb62d06f6

## Startup Token Pitch Deck

**Genre**: pitch-deck
**Rendered**: Problem: Engineering teams spin up and abandon temporary AWS environments or subdomains that never appear in Palo Alto Cortex Xpanse or legacy network scanners.
Solution: What if you could see every unmanaged cloud instance the moment it's spun up? Shadowyard continuously enumerates orphaned subdomains and abandoned assets, giving you total perimeter visibility before attackers find a way in.
Customer: CISO at high-growth enterprise companies
Unlike: Palo Alto Cortex Xpanse
**Mechanism**: spine-derived-v1
**Template Id**: spine-pitch-deck
**Vocab Fingerprint**: 1c2c9534e2534bf3

## Startup Token M E D D P I C C

**Pain**: Engineering teams spin up and abandon temporary AWS environments or subdomains that never appear in Palo Alto Cortex Xpanse or legacy network scanners.
**Metrics**: Target: You maintain a live, 100% accurate inventory of your external attack surface with every new asset discovered in under five minutes.
**Rendered**: Pain: Engineering teams spin up and abandon temporary AWS environments or subdomains that never appear in Palo Alto Cortex Xpanse or legacy network scanners.
Economic buyer: Security Engineering Team
Metrics: Target: You maintain a live, 100% accurate inventory of your external attack surface with every new asset discovered in under five minutes.
Competition: Palo Alto Cortex Xpanse
**Mechanism**: spine-derived-v1
**Competition**: Palo Alto Cortex Xpanse
**Economic Buyer**: Security Engineering Team
**Vocab Fingerprint**: 696f7d18bfad839e

## Startup Token Cold Email

**Genre**: cold-email
**Rendered**: Subject: External Attack Surface Management for CISO at high-growth enterprise companies

CISO at high-growth enterprise companies — Engineering teams spin up and abandon temporary AWS environments or subdomains that never appear in Palo Alto Cortex Xpanse or legacy network scanners. What if you could see every unmanaged cloud instance the moment it's spun up? Shadowyard continuously enumerates orphaned subdomains and abandoned assets, giving you total perimeter visibility before attackers find a way in.
**Mechanism**: spine-derived-v1
**Template Id**: spine-cold-email
**Vocab Fingerprint**: d9c660a0aa4da68a

## Startup Token Agent Spec

**Genre**: ai-agent-spec
**Rendered**: External Attack Surface Management. What if you could see every unmanaged cloud instance the moment it's spun up? Shadowyard continuously enumerates orphaned subdomains and abandoned assets, giving you total perimeter visibility before attackers find a way in. Serves CISO at high-growth enterprise companies.
**Mechanism**: spine-derived-v1
**Template Id**: spine-ai-agent-spec
**Vocab Fingerprint**: 1e9b848edc5c5d6f

## Neighborhood

### Candidate solutions

- [Delayed Unbilled Time Realization](/Problems/Delayed_Unbilled_Time_Realization) — candidate solution for · Problems

### Competitors

- [Tenable ASM](/Competitors/Tenable_ASM) — competes with · Competitors
- [Qualys CSAM](/Competitors/Qualys_CSAM) — competes with · Competitors
- [Manual OSINT Audits](/Competitors/Manual_OSINT_Audits) — competes with · Competitors
- [Palo Alto Cortex Xpanse](/Competitors/Palo_Alto_Cortex_Xpanse) — competes with · Competitors
- [Legacy Network Scanners](/Competitors/Legacy_Network_Scanners) — competes with · Competitors
- [Thomson Reuters Practice CS](/Competitors/Thomson_Reuters_Practice_CS) — competes with · Competitors
- [BigTime](/Competitors/BigTime) — competes with · Competitors
- [CCH Axcess Practice](/Competitors/CCH_Axcess_Practice) — competes with · Competitors
- [Outlook Calendar Reconstruction](/Competitors/Outlook_Calendar_Reconstruction) — competes with · Competitors
- [Xero Practice Manager](/Competitors/Xero_Practice_Manager) — competes with · Competitors

### Embodies

- [Software](/Theses/Software) — embodies · Theses
- [Agent](/Theses/Agent) — embodies · Theses

### What it offers

- [Shadowyard Asset Mapper](/Software/Shadowyard_Asset_Mapper) — offers · Software

### Composed of

- [Engagement Attribution Agent](/Agents/Engagement_Attribution_Agent) — composes · Agents
- [Activity Reconciliation Agent](/Agents/Activity_Reconciliation_Agent) — composes · Agents
- [Desktop Exhaust API](/Agents/Desktop_Exhaust_API) — composes · Agents
- [Practice Management SDK](/Agents/Practice_Management_SDK) — composes · Agents
- [WIP Billing Service](/Services/WIP_Billing_Service) — composes · Services

### Who it serves

- [Accounting Firm](/CompanyTypes/Accounting_Firm) — serves · CompanyTypes

### Similar Startups

- [Weborb](/Startups/Weborb) — similar · Startups
- [Cloudint](/Startups/Cloudint) — similar · Startups
- [Scovers](/Startups/Scovers) — similar · Startups
- [Mapleshape](/Startups/Mapleshape) — similar · Startups
- [Keystonepulse](/Startups/Keystonepulse) — similar · Startups
- [Porosityscaffold](/Startups/Porosityscaffold) — similar · Startups
- [Denoot](/Startups/Denoot) — similar · Startups
- [Domyn](/Startups/Domyn) — similar · Startups
- [Guardiandeck](/Startups/Guardiandeck) — similar · Startups
- [Awarestack](/Startups/Awarestack) — similar · Startups
- [Casdomain](/Startups/Casdomain) — similar · Startups
- [Acceam](/Startups/Acceam) — similar · Startups
- [Maplecontour](/Startups/Maplecontour) — similar · Startups
- [Apyard](/Startups/Apyard) — similar · Startups
- [Concortex](/Startups/Concortex) — similar · Startups
- [Triquint](/Startups/Triquint) — similar · Startups
- [Multishadow](/Startups/Multishadow) — similar · Startups
- [Domainpoint](/Startups/Domainpoint) — similar · Startups
- [Corelamp](/Startups/Corelamp) — similar · Startups
- [Hororus](/Startups/Hororus) — similar · Startups
