This is a passive due-diligence workflow. It discovers candidate company-domain relationships, preserves their sources, and enriches only domains that the assessment team independently verifies as in scope.

Requirements

  • API access for organization profiles and domain details
  • Nexus access for company-domain collection and WHOIS
  • A documented due-diligence purpose and access policy
  • Python 3.10 or later with requests
Do not trigger active scans through this workflow. Use only passive and indexed observations unless the target organization has provided explicit scan authorization.

Evidence stages

The Nexus company lookup uses query. Each validated Nexus lookup deducts one credit.

Collect candidates and verified evidence

Leave FULLHUNT_VERIFIED_DOMAINS empty during initial discovery. Add domains only after the deal team verifies the relationship through corporate, legal, or target-provided evidence.
assess_ma_exposure.py

Assessment output

For each verified domain, record:
  • Current indexed hosts, ports, services, products, TLS names, and observation times
  • Registration evidence and its source date
  • Ownership evidence supplied by the target or deal team
  • Shared hosting, subsidiary, divestiture, and historical-domain caveats
  • Material exposure, remediation owner, and decision deadline
Do not calculate a company security grade from record counts. Coverage, company size, shared services, stale observations, and unverified ownership make those comparisons misleading. Keep candidate domains out of scan scope and executive findings until their relationship is verified. Use aggregate findings in reports unless a named asset is necessary for the due-diligence decision and access is restricted appropriately.