External + internal attack surface, on one graph
Lens shows how an open port the internet can see reaches the exact internal application behind it — the full outside-in path on one live security graph. A complete EASM platform with its own external scanner built in, it unifies the scanners you already run, scores everything with one Lens Risk Score, and surfaces shadow AI no one registered.
External scan · live
1 critical path · fix first
From open port to the app behind it
- hop 0 NET api.bank.example:8443 open from the internet · TLS 1.2 · cert 19 days left
- hop 1 F5 vs_api_443 · BIG-IP SNAT · pool pool_api
- hop 2 APP 10.10.113.11:8080 sg_auth_backend · Java 17 · Log4j 2.14
- hop 3 CVE CVE-2021-44228 · KEV EPSS 0.97 · reachable from the internet
- + AI Shadow AI ollama · 10.10.113.40:11434 · unauthenticated
Priority: Critical path: internet → F5 → auth backend → Log4Shell. Blast radius 3 applications. Nessus and Qualys findings are bound to the same asset; fix this one first.
What it answers
From open port to the app behind it
Attackers start with an open port and work inward — Lens shows you the same path first. On one live security graph it traces an externally visible open port all the way to the exact internal application or service behind it, so external and internal attack surface finally sit in one picture. It's a complete EASM platform with its own scanner built in, it unifies the tools you already run — Tenable Nessus, Qualys, Recorded Future — surfaces self-hosted AI and MCP servers nobody registered, and scores it all with a single risk number weighted by blast radius.
- The internet sees port 8443 open. Which internal application is behind it?
- Lens draws the path from the exposed port to the exact service on one graph.
- Someone stood up an LLM server. Is it exposed?
- Lens discovers self-hosted model and MCP servers and flags the unauthenticated ones.
- We have 4,000 findings. Which one first?
- One Lens Risk Score blends CVSS, EPSS, KEV and reachability, weighted by blast radius.
- Can we keep Nessus and Qualys?
- Yes — Lens unifies the scanners you already run into one external-and-internal picture.
See it in action
The attack surface, on a live graph.
Lens resolves your external footprint onto a navigable graph, flags shadow AI and exposed services, and scores each finding by blast radius — so the next fix is the one that actually matters.
Illustrative data shown. Your deployment runs entirely on your own appliance.
What it does
01
Outside-in path mapping
See how an externally visible open port reaches the exact internal application or service behind it — the full outside-in path, drawn on one live security graph.
02
Complete EASM, built-in scanner
Everything an EASM platform should have, with its own external scanner included — bring your own vulnerability scanner if you prefer, and run the EASM standalone.
03
Unifies your scanners
Pull Tenable Nessus, Qualys, Recorded Future and the tools you already run into one external-and-internal picture, instead of a stack of disconnected consoles.
04
AI & shadow-AI exposure
Discover self-hosted model servers (Ollama, vLLM, LM Studio), MCP servers and AI agents — then flag the ones exposed, unauthenticated or running a vulnerable runtime.
05
Lens Risk Score (LRS)
One 0–100 score blends CVSS, EPSS, KEV and internet-reachability — propagated across the graph by blast radius, not raw CVE counts.
How it works
Lens unifies external and internal surface on one graph and scores risk where it matters.
- 01
Discover
Find exposed hosts, services and shadow IT with the built-in external scanner, and pull in the scanners you already run.
- 02
Map
Draw external and internal surface onto one live security graph — and trace each open port to the exact internal app behind it.
- 03
Prioritize
Score everything with one Lens Risk Score, propagated by blast radius, so the next fix is the one that matters.
Why teams run Lens
- Trace an internet-facing open port straight to the exact internal application behind it, on one graph.
- Run a complete EASM with its own scanner, or bring your own and sell it standalone.
- Unify Tenable Nessus, Qualys, Recorded Future and your other tools into one external-and-internal view.
- Surface the shadow AI nobody registered — exposed model servers, MCP endpoints and over-privileged agents.
- Prioritize by one Lens Risk Score and business blast radius, not raw CVE counts.
Attack surface
last 24hPart of the Seraxi platform
See Seraxi on your environment.
Book a technical walkthrough. We'll map Trace, Keep, and Lens to your fleet and show you a real backup, capture, and exposure picture — not a slide deck.