Overview
Dubai-based spiderSilk, founded in 2019, is using AI to scan billions of internet-facing IP addresses on behalf of customers, hunting for exposed assets, leaked credentials, and zero-day vulnerabilities before attackers find them first. The company recently closed a $9 million Series A round led by Saudi Aramco Entrepreneurship Ventures, with participation from Global Ventures and STV, funding a platform that aims to give defenders the same outside-in view an attacker would have.
How It Works
Where most external attack surface tools need a customer to hand over a list of known domains and IP ranges, spiderSilk's platform reportedly needs only a company's name to get started. From there, its scanning technology sweeps billions of IP addresses looking for infrastructure, leaked data, exposed systems, and compromised credentials the organization never intended to expose — mimicking how an outside attacker would go about mapping a target rather than relying on an internal asset inventory that's often already stale.
Co-founder and Chief Security Officer Mossab Hussein says the system also assesses what it finds — analyzing a page's content, code, and even visual branding elements like logos — to determine whether a given exposure is an internal system misconfiguration or simply commercially hosted software, before deciding what's worth flagging to a customer.
Built for Zero-Day Response
The platform, which spiderSilk calls SilkNet, continuously aggregates open source and darknet data at scale and can kick off fresh, targeted internet scans the moment a new zero-day vulnerability is disclosed, pushing a threat report straight into a customer's internal systems. A newer SOC Autonomous AI Agent layer goes a step further, configured to act on confirmed exposures directly — isolating a compromised host, blocking a suspicious IP, or locking an account — without waiting on a human analyst to act first.
Track Record
spiderSilk has a history of surfacing major exposures well before this AI-driven platform existed, including the Blind anonymous-network leak, an exposed Samsung source code repository, a Clearview AI code and app leak, and an unencrypted MoviePass card-number spill. The company says its research has collectively uncovered exposures affecting more than 120 million people, and its customer base now spans telecommunications, energy, financial services, healthcare, and retail across North America, Europe, and Asia-Pacific.
Why It Matters
External attack surface management has largely been a story of inventory: knowing what you own well enough to defend it. spiderSilk's pitch is that AI now makes it practical to skip straight to an attacker's-eye view of an organization instead — discovering exposures that never made it into an asset list in the first place, and doing it fast enough to matter on the same day a new zero-day drops rather than weeks later during a scheduled scan.