+
+
Visit Website

About

Criminal IP ASM delivers a threat intelligence-powered approach to attack surface management by combining continuous asset discovery with deep threat analysis across IPs, domains, OSINT, and associated infrastructure. Built on Criminal IP’s advanced scanning and enrichment capabilities, it brings Threat Intelligence context such as vulnerability intelligence, C2 detections, malicious IP/domain correlations, and dark web exposure into every layer of asset discovery in an integrated approach that empowers security teams to proactively identify, prioritize, and mitigate threats before they are exploited.

About

ScanFactory is an Attack Surface Management & Continuous Automated Vulnerability Assessment Platform that provides realtime security monitoring across all external assets of a company by enumerating & scanning its entire network infrastructure utilizing 15+ most trusted community-backed security tools & extensive database of exploits. Its vulnerability scanner stealthily performs a deep & continuous reconnaissance to map your entire external attack surface & are extended with handpicked top-rated premium plugins, custom wordlists & plethora of vulnerability signatures. Its dashboard can be used to discover & review all vulnerabilities sorted by CVSS & has enough information to understand, replicate & remediate the issue. It also has capability to export alerts to Jira, TeamCity, Slack & WhatsApp.

Platforms Supported

Windows Not Supported
Mac Not Supported
Linux Not Supported
Cloud Supported
On-Premises Not Supported
iPhone Not Supported
iPad Not Supported
Android Not Supported
Chromebook Not Supported

Platforms Supported

Windows Not Supported
Mac Not Supported
Linux Not Supported
Cloud Supported
On-Premises Supported
iPhone Not Supported
iPad Not Supported
Android Not Supported
Chromebook Not Supported

Audience

Security operations, threat-intelligence and risk teams wanting a tool to get access to auto-monitored assets exposed to attack surfaces

Audience

Anyone working towards ensuring the security of externally-facing assets in a network infrastructure

Support

Phone Support Supported
24/7 Live Support Not Supported
Online Supported

Support

Phone Support Supported
24/7 Live Support Supported
Online Supported

API

Offers API Supported

API

Offers API Supported

Screenshots and Videos

Screenshots and Videos

Pricing

Send us an inquiry about purchasing the Criminal IP Enterprise license.
Our sales team will get in touch with you as soon as possible.
Free Version Not Supported
Free Trial Supported

Pricing

$50
We usually calculate this individually per request as it depends on size of infrastructure and frequency of re-scans.
Free Version Not Supported
Free Trial Supported

Reviews/Ratings

Overall 4.7 / 5
ease 4.3 / 5
features 4.4 / 5
design 4.6 / 5
support 4.7 / 5

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Pros from Real Users

Pros

  • I like how much information Criminal IP ASM puts in one place. It’s useful for finding internet-facing assets that you may not know about anymore, especially old subdomains, open ports, certificates, and exposed services. The threat intelligence is also helpful because it gives more context around why something might be worth looking into instead of just showing a long list of findings. I’ve found the search and investigation side of the platform pretty straightforward once you get used to it.
  • Criminal IP ASM provides excellent visibility into external assets through continuous asset discovery across domains, IPs, certificates, and exposed services. What stands out is the integration of threat intelligence directly into the attack surface management workflow, allowing security teams to prioritize risks based on real-world threat context instead of relying solely on CVE severity. The platform's OSINT capabilities, dark web monitoring, certificate monitoring, and AI-driven risk correlation help identify exposures that traditional ASM solutions may overlook. The dashboard is intuitive and provides actionable insights that reduce investigation time and improve remediation prioritization.
  • 🔹 1. Automated Asset Discovery and Centralized Dashboard Criminal IP ASM automatically detects your organization’s internet-exposed assets and manages them through a centralized dashboard, providing quick visibility for security teams to assess attack surfaces and vulnerabilities. 🔹 2. AI and Threat Intelligence Integration for Enhanced Accuracy By integrating AI and Threat Intelligence, the platform helps prioritize risks and offer strategic recommendations for mitigating potential threats. It categorizes risks by various attack vectors, improving decision-making efficiency. 🔹 3. Real-Time Risk Monitoring & Alerts Criminal IP ASM continuously monitors risks in real-time and updates security teams on new vulnerabilities or changes, enabling prompt response and threat mitigation. 🔹 4. Wide Asset Support It supports a broad range of internet-connected assets, including servers, domains, IoT devices, and cloud services, offering comprehensive management across your entire attack surface. 🔹 5. Flexible Integration with Existing Security Tools The platform supports API integration and can seamlessly connect with existing SIEM or SOAR systems, making it highly scalable and suitable for organizations that want to enhance automation and threat detection.
  • What I appreciated the most was the comprehensive nature of the platform. Criminal IP ASM offers an extensive perspective on the external attack surface, revealing assets that you might not even be aware of. The inclusion of threat intelligence, OSINT enrichment, screenshots, and metadata transforms the findings into tangible and actionable insights rather than mere theories. It’s evident that the platform has been designed with the mindset of a security professional in mind.
  • Criminal IP ASM is refreshingly straightforward. You log in, you see what’s exposed, and you immediately understand where the risks are. As someone responsible for security decisions but not too knowledgable about it, I appreciate how fast it gets to the point. Asset discovery works well, the data feels reliable, and it helps validate assumptions we already had while also catching things we missed.
  • As a CTO, what I value most is clarity and signal over noise, and Criminal IP ASM does a good job there. It gives a clear picture of our external attack surface without overwhelming the team. Asset discovery is solid, risks are easy to understand, and the platform feels practical rather than academic. It’s something you can check regularly and act on, not just generate reports that no one reads.
  • - Can automatically discover and inventory all internet-facing assets associated with an organization — including IPs, domains, cloud services, open ports, certificates, and other externally exposed infrastructure. This includes shadow IT and unknown assets that are often missed in asset inventories. - Unlike periodic scanning approaches, Criminal IP ASM provides continuous monitoring of external assets against evolving threat data. Detected exposures and vulnerabilities are automatically scored (e.g., High/Medium/Low), helping security teams quickly identify and focus on critical risks. - The findings add context to vulnerabilities, that possibly help teams understand not just what’s exposed but how vulnerable it is to specific attacks, enabling better decision-making. - As a SaaS solution, it's quick to deploy, requiring minimal setup. This is especially valuable for large enterprises where fast onboarding and scalability are crucial.

Training

Documentation Supported
Webinars Supported
Live Online Supported
In Person Supported

Training

Documentation Supported
Webinars Supported
Live Online Supported
In Person Supported

Company Information

AI Spera
Founded: 2017
United States
www.criminalip.io/products/asm/attack-surface-management

Company Information

ScanFactory
Founded: 2021
India
in.scanfactory.io

Alternatives

Criminal IP

Criminal IP

AI SPERA

Alternatives

Silent Armor

Silent Armor

Silent Breach

Categories

Categories

Cybersecurity Features

AI / Machine Learning Supported
Behavioral Analytics Not Supported
Endpoint Management Not Supported
Incident Management Not Supported
IOC Verification Not Supported
Tokenization Not Supported
Vulnerability Scanning Supported
Whitelisting / Blacklisting Supported

Vulnerability Scanners Features

Asset Discovery Supported
Black Box Scanning Supported
Compliance Monitoring Supported
Continuous Monitoring Supported
Defect Tracking Not Supported
Interactive Scanning Supported
Logging and Reporting Supported
Network Mapping Supported
Perimeter Scanning Supported
Risk Analysis Not Supported
Threat Intelligence Not Supported
Web Inspection Supported

Integrations

Cisco CX Cloud Supported
Criminal IP Supported
Google Chrome Supported
Jira Not Supported
Nmap Supported
Polarity Supported
PolySwarm Supported
Slack Not Supported
Splunk Cloud Platform Supported
Splunk Enterprise Not Supported
Sumo Logic Supported
Tenable One Cloud Exposure (CNAPP) Supported
VirusTotal Supported
WhatsApp Not Supported
WordPress Supported

Integrations

Cisco CX Cloud Not Supported
Criminal IP Not Supported
Google Chrome Not Supported
Jira Supported
Nmap Not Supported
Polarity Not Supported
PolySwarm Not Supported
Slack Supported
Splunk Cloud Platform Not Supported
Splunk Enterprise Supported
Sumo Logic Not Supported
Tenable One Cloud Exposure (CNAPP) Not Supported
VirusTotal Not Supported
WhatsApp Supported
WordPress Not Supported
Claim ScanFactory and update features and information
Claim ScanFactory and update features and information