
Threat IntelligenceGovernance, Risk & Compliance
CTM360
External attack surface, digital risk protection, and threat intelligence in one platform
CTM360 Overview
What it does
CTM360 is a consolidated external cybersecurity and Digital Risk Protection (DRP) platform that maps and defends an organization's presence in cyberspace from the attacker's perspective. Six bundled modules span External Attack Surface Management (HackerView), digital risk protection and takedowns (CyberBlindspot), cyber threat intelligence (ThreatCover), DMARC and email authentication (DMARC360), third-party risk management (RiskHub), and curated cyber news and advisories (CyNA). The platform arrives pre-populated with externally observable data, so onboarding requires no installation, agents, or configuration.
How it works
HackerView builds the external asset inventory by pivoting across WHOIS records, reverse WHOIS, DNS entries, and SSL certificates, scoring exposure through Indicators of Exposure. CyberBlindspot runs a capture, curate, manage workflow over surface, deep, and dark web sources, covering 50+ digital risk use cases, and routes incidents to a Cyber Incident Response Team that executes takedowns through registrar and hosting relationships in the Global Takedown Network. ThreatCover maps threat feeds to the MITRE ATT&CK framework and publishes intelligence in STIX 2.1, TAXII, YARA, and JSON formats, while RiskHub combines questionnaire-based assessments with outside-in monitoring of third, fourth, and nth parties.
Credentials and traction
Recognized in the 2026 Gartner Magic Quadrant for Cyberthreat Intelligence Technologies, the platform also carries G2 Leader and High Performer badges for Spring 2026. CTM360 was recognized as a 2026 Bronze Winner in the Cybersecurity Excellence Awards and ranked in the 2022 Deloitte Technology Fast 50 for the Middle East. It serves banking, financial services, government, healthcare, and telecom organizations, with a free Community Edition open to any legitimate organization.
Key Capabilities
mapped to solution categoriesProfiles each third party at intake, capturing criticality, data sensitivity, service type, geography and regulatory requirements, to determine which risk domains apply to it and to scope the depth and cadence of assessment accordingly.
Gives third parties their own portal to complete assessments, upload evidence, report issues and keep their documentation current, with customer branding and multilingual support, so much of the assessment workload shifts to the third party rather than the risk team.
Distributes, collects and scores third-party assessments and security questionnaires from a maintained template library that spans risk domains and standards, with evidence requests, reminders, reviewer collaboration and scoring rules; stronger implementations scope questionnaire depth and cadence dynamically from the third party's risk profile rather than sending one template to every vendor.
Watches third parties between assessments for new risk events, such as security incidents, financial distress, sanctions or adverse-media hits and regulatory actions, and surfaces them through dashboards, reports, alerts, reminders and notifications; stronger implementations re-score the third party and trigger escalation or corrective action when an event crosses a defined threshold instead of only updating a dashboard.
Maps the relationships between the organization, its third parties and their fourth and Nth parties as a navigable graph, including geographic views by headquarters or facility, so hidden dependencies and shared providers are visible, and reports risk metrics over that map with export of third-party risk data for presentations and regulators.
Brings risk-domain data subscriptions into each third party's record, such as outside-in cybersecurity ratings, external attack surface findings, financial health, sanctions and adverse media, and ESG data, whether produced natively or ingested from a ratings or data-aggregator provider, and uses that data in scoring and ongoing monitoring so an indicator crossing a threshold updates the risk score and starts a workflow rather than only refreshing a dashboard.
Scores each third party's inherent and residual risk and measures its potential impact on the business or supply chain to produce an impact estimate, aggregating domain-level results into a composite score that can be rolled up across the portfolio and correlated with enterprise objectives and control performance.
Monitors and alerts on deep and dark web, domain abuse, brand impersonation, social media and geopolitical risk.
Profiles threat actors with associated TTPs and attribution context.
Provides an interactive portal with contextualized dashboards, configurable alerting, search and built-in analysis.
Produces finished intelligence reports at technical, operational and strategic levels.
Supports machine-to-machine integration via JSON, APIs and STIX or TAXII, with sharing across private and public communities such as ISACs.
Delivers tailored vulnerability and exposure intelligence highlighting actively exploited vulnerabilities with associated IoCs, TTPs and threat actors.
Offers analyst support such as requests for information, recurring analyst augmentation and takedown services.
Discovers or ingests external attack surface and digital asset data to curate organization-specific risk.
Ingests and shares intelligence via STIX/TAXII and other machine-to-machine formats and APIs.
Provides comprehensive indicators of compromise such as IPs, URLs, domains and file hashes with maliciousness ratings and enrichments like geolocation and TTPs.
Monitors newly registered domains using typosquatting, homograph, and combosquatting techniques against the organization's brand, surfacing phishing infrastructure before campaigns launch.
Submits abuse reports to registrars, hosting providers, and platform operators to remove confirmed phishing pages, fake profiles, and impersonating applications.
Identifies the organization's internal documents, source code, credentials, and PII on paste sites, code repositories, and dark web data markets.
Monitors external sources for leaked personal data, credential exposure, targeted phishing infrastructure, and social media impersonation targeting named executives.
Monitors social media and collaboration platforms for brand abuse, impersonation and organizational exposure.
Monitors dark web forums, marketplaces, and access broker listings for mentions of the organization, active threats, and sale of stolen access or data.
Discovers fake websites, social media profiles, and mobile applications impersonating the organization, using domain similarity, visual fingerprinting, and content analysis.
Discovers all services sending email on behalf of a domain by analyzing DMARC aggregate reports, surfacing unauthorized senders and unaligned legitimate sources.
Manages the DMARC policy lifecycle from p=none monitoring through p=quarantine to p=reject enforcement, with visibility into failing sources and aggregate authentication reports.
Manages SPF record structure (flattening, include chain management), and DKIM key rotation across all mail sending sources to maintain authentication alignment.
Manages the full BIMI deployment chain (DMARC enforcement prerequisite, VMC provisioning, DNS record publication), enabling brand logo display in supporting email clients.
Ranks discovered exposures by combining exploitability signals, asset business context, and active threat intelligence to produce an actionable remediation queue.
Identifies software stacks, versions, and components running on discovered assets through passive banner analysis and active probing, mapping CVE exposure without authenticated scanning.
Continuously enumerates internet-exposed assets (domains, IPs, subdomains, certificates, cloud storage, APIs) using passive DNS, certificate transparency logs, and active probing, including assets outside the official inventory.
Identifies cloud resources, SaaS applications, and exposed services deployed by business units without IT or security team visibility or approval.
Tracks SSL/TLS certificate expirations, newly registered lookalike domains, and subdomain takeover opportunities (dangling DNS records pointing to deprovisioned cloud services).
Compliance
certificationsImplementation & support
Info last updated on September 7, 2026
Buyers
Start a shortlist with CTM360
Compare options, add your notes, and run informed evaluations.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.