Skip to main content
ShadowMap

ShadowMap discovers. B-52 tests what it finds

Both are products of Security Brigade, and they answer two different questions. The flow between them runs in one direction, the subscriptions are separate, and B-52 works for a customer who has never bought ShadowMap.

Two jobs

Discovery and testing are not the same work

Knowing that something is exposed and knowing what happens when it is attacked are two separate findings, and a product that does one well is not halfway to doing the other. Security Brigade sells one product on each side of that line.

The questionShadowMapB-52
What does it answer? What resolves to your organisation today, and what changed since the last time you looked. What happens when one of those things is attacked by somebody who is trying.
What comes out of it? An inventory of what is exposed, and a record of how that set has changed. A finding with the request, the response and the steps that reproduce it, a CVSS v4.0 vector and the CWE.
What starts it? It watches continuously and tells you when the estate changes. A scope you signed off, on the interval you set or on the pipeline that built the release.
Who decides what gets attacked? Not this product. It reports what exists; nothing in it becomes a B-52 target on its own. You do, in writing, before a run begins.
How is it bought? Its own subscription. Its own subscription. One scan is one application or target, from $500.

What does it answer?

ShadowMap
What resolves to your organisation today, and what changed since the last time you looked.
B-52
What happens when one of those things is attacked by somebody who is trying.

What comes out of it?

ShadowMap
An inventory of what is exposed, and a record of how that set has changed.
B-52
A finding with the request, the response and the steps that reproduce it, a CVSS v4.0 vector and the CWE.

What starts it?

ShadowMap
It watches continuously and tells you when the estate changes.
B-52
A scope you signed off, on the interval you set or on the pipeline that built the release.

Who decides what gets attacked?

ShadowMap
Not this product. It reports what exists; nothing in it becomes a B-52 target on its own.
B-52
You do, in writing, before a run begins.

How is it bought?

ShadowMap
Its own subscription.
B-52
Its own subscription. One scan is one application or target, from $500.

One direction

What actually happens between them

Where a customer runs both, the handover is not a pipe. It is a person taking something ShadowMap surfaced and putting it into a scope B-52 is authorised to test.

01 Discovery

ShadowMap reports that the estate has changed

What it does
It watches what resolves to your organisation and tells you when that set changes, including the parts nobody registered with your security team.
What it hands you
An inventory. A record of what exists, as it is today.
Where it stops
At the hand-off. Nothing ShadowMap surfaces enters a B-52 scope on its own.
02 Authorisation

A person decides whether it belongs in a scope

Who acts
You do. A target enters a B-52 scope because somebody on your side put it there and signed the scope off.
Why it is not automatic
A discovery product that also decided what to attack would be taking the scope decision that belongs to you.
What the sign-off fixes
The targets, the window and the delivery model. Nothing is tested on the grounds that it appeared.
03 Testing

B-52 tests it and returns something you can reproduce

What runs
Six phases: discovery, planning, scanning, exploitation, reporting, and a QA phase that runs on the finished report before it reaches you.
What comes back
Findings that carry open, fixed, retested and closed, closing on a retest that cannot reproduce them.
Which way the flow runs
One way. Nothing travels back from B-52 into ShadowMap.

No dependency

B-52 works without ShadowMap

Nothing in B-52 requires a ShadowMap subscription. The application classes — web application, mobile app, API, thick client and secure code review — start from a target you name, and the card flow reaches them without a sales conversation.

The class where a buyer might assume otherwise is external network testing, and that class runs its own discovery. The perimeter is worked out from what actually answers rather than from the asset list you hand over, and what comes back to you first is a scope proposal — before anything is tested. The external network page sets out how that proposal is built and what you are agreeing to when you sign it.

A customer who has never heard of ShadowMap gets the same eleven coverage classes in the same three delivery models. There is no part of B-52 that is reachable only alongside ShadowMap.

The commercial shape

Two subscriptions, and that is a product decision

B-52 is an adjacent product rather than a ShadowMap module, and it sits outside a ShadowMap licence. The separation is deliberate: the scope decision belongs to you, and a testing product that inherited its targets from an inventory would be testing whatever appeared overnight.

Where a customer does run both, it is still B-52’s own schedule that decides when testing happens — the interval you set, or the pipeline that built the release. Continuous assessment covers the cadence, and the build gate covers the case where a result has to stop a release.

What is fixed before a target is tested
  • Scope sign-off names the targets and the window. A target enters a scope because a person put it there in writing, and a discovered asset is not one until that happens.
  • Three actions stop and wait for your written approval wherever they arise: destructive or state-changing actions in production, persistence and lateral movement beyond the entry host, and anything touching live credentials or real customer data.
  • The same boundary applies in all three delivery models and on every coverage class. What the models change is whose signature the report carries, never what may be done without asking.

Approvals and audit trail records who approved what and when, and the autonomy boundary sets out where the platform stops on its own.

Buy the job you need done, in whichever order you need it

B-52 is bought on its own card flow for web application, mobile app, API, thick client and secure code review. External network, internal network, cloud, Active Directory, social engineering and LLM applications settle on a scoping call, and so does ShadowMap.