FAQ
Frequently Asked Questions
Find answers to common questions about PentaTrail CTEM/ASM
PentaTrail is a CTEM (Continuous Threat Exposure Management) platform that automatically discovers and monitors your external attack surface.
Starting from the domains your organization owns, it continuously scans externally exposed assets and vulnerabilities from an attacker's perspective.
Key Features:
- Automated discovery of hosts, IPs, ports, technology stacks, URLs, and cloud buckets
- Web application and SSL/TLS vulnerability scanning
- Real-time detection of asset changes
- Risk quantification via proprietary scoring (TDL/TER)
CTEM (Continuous Threat Exposure Management) is a framework for continuously identifying, assessing, and remediating external threats.
PentaTrail covers the full CTEM lifecycle through 5 integrated stages:
- Scoping — Register domains and define your monitoring scope
- Discovery — Automatically discover subdomains, IPs, ports, technologies, and URLs
- Prioritization — Score each finding using TDL/TER metrics combining CVSS, EPSS, KEV, and business impact
- Validation — Validate exploitability with AI-powered deep scans
- Mobilization — Assign remediation tasks, track status, and generate reports
Of these five stages, Scoping and Discovery — plus viewing the AI remediation guidance in Mobilization — are included in the ASM plan. Prioritization (asset weighting and grouping), Validation, and Mobilization's remediation-task workflow and executive reporting are added in the CTEM plan. See "What is the difference between ASM and CTEM?" for details.
- Agree to Terms of Service & Create an Account — Sign up with Google OAuth, or with your email address (we send a passwordless sign-in link — no password required)
- Register a Passkey — During initial setup, register a passkey (your device biometrics or screen lock, or a security key) as your sign-in credential. No authenticator app or QR code is needed
- Register Your Domain — Add the domain you want to monitor from the dashboard
- Verify Domain Ownership — Add a DNS TXT record to confirm ownership. Propagation typically takes a few minutes to a few hours
- Automatic Scanning Begins — Once verification is complete, asset discovery starts automatically
Note: Free email addresses (gmail.com, yahoo.com, etc.) cannot be used for registration.
Yes. PentaTrail offers a 14-day free trial after account creation — credit card registration only, no upfront charges.
What's included in the trial:
- Up to 3 origin domains
- Full asset discovery (hosts, IPs, ports, technologies, URLs)
- Complete dashboard access including risk scoring
Deep scanning is available as an add-on after subscribing to a paid plan.
You can start monitoring in as little as 5 minutes. No software installation or network configuration required.
- Agree to Terms of Service & create an account
- Register the domain you want to monitor
- Asset discovery begins automatically
Discovery results appear in your dashboard within a few hours. If you want deep scanning, DNS TXT domain ownership verification is required as a separate step.
No. PentaTrail uses non-intrusive, external observation — the same perspective an attacker would have.
- No agents or internal network access required
- Scans use only public information gathering (HTTP/HTTPS requests, DNS lookups)
- Server load is comparable to normal web browsing
- No write operations or data modifications are performed
Even during the Validation phase, exploitability is confirmed using non-destructive techniques.
Register origin domains from the dashboard:
- Add a domain from "Domain Management" in the dashboard
- Verify domain ownership via DNS TXT record
- Asset discovery begins automatically after verification
DNS verification typically takes a few minutes to a few hours, depending on DNS propagation.
ASM (Attack Surface Management) covers discovery, continuous monitoring, and risk rating of your external attack surface. CTEM (Continuous Threat Exposure Management) is the broader continuous risk management framework that includes ASM.
- ASM — Discovery of externally exposed assets, continuous monitoring of changes, and access to AI remediation guidance
- CTEM — Everything in ASM, plus active AI-driven validation (non-destructive confirmation of real-world exploitability), remediation task management with owners and due dates, business-impact grouping and responsibility assignment, and executive summary reporting
CTEM is the framework that runs the full 5 stages proposed by Gartner (Scoping, Discovery, Prioritization, Validation, and Mobilization), and ASM covers Scoping, Discovery, and part of Mobilization (viewing the AI remediation guidance) within it.
Free single-domain scanning tools typically run a one-time check against the single URL you enter. PentaTrail automatically discovers subdomains, IPs, ports, and technology stacks under your registered origin domain, then continuously monitors and re-scans them.
- Discovery scope — A single-domain scan only covers the URL you enter. PentaTrail automatically discovers related assets under your origin domain, surfacing assets you were not previously aware of
- Continuity — A single-domain scan is a one-time check you run manually. PentaTrail runs continuously, detecting new assets and newly disclosed vulnerabilities on an ongoing basis
- Prioritization — A single-domain scan typically just lists what it finds. PentaTrail adds proprietary risk scoring (TDL/BI score) and AI remediation guidance to show what to fix first
For product questions, technical inquiries, or billing matters, please don't hesitate to reach out.
Still have questions?
If the FAQ didn't resolve your issue, feel free to contact us.
