
Threat IntelligenceGovernance, Risk & Compliance
CTM360
External attack surface, digital risk protection, and threat intelligence in one platform
CTM360 Overview
What it does
CTM360 is a consolidated external cybersecurity and Digital Risk Protection (DRP) platform that maps and defends an organization's presence in cyberspace from the attacker's perspective. Six bundled modules span External Attack Surface Management (HackerView), digital risk protection and takedowns (CyberBlindspot), cyber threat intelligence (ThreatCover), DMARC and email authentication (DMARC360), third-party risk management (RiskHub), and curated cyber news and advisories (CyNA). The platform arrives pre-populated with externally observable data, so onboarding requires no installation, agents, or configuration.
How it works
HackerView builds the external asset inventory by pivoting across WHOIS records, reverse WHOIS, DNS entries, and SSL certificates, scoring exposure through Indicators of Exposure. CyberBlindspot runs a capture, curate, manage workflow over surface, deep, and dark web sources, covering 50+ digital risk use cases, and routes incidents to a Cyber Incident Response Team that executes takedowns through registrar and hosting relationships in the Global Takedown Network. ThreatCover maps threat feeds to the MITRE ATT&CK framework and publishes intelligence in STIX 2.1, TAXII, YARA, and JSON formats, while RiskHub combines questionnaire-based assessments with outside-in monitoring of third, fourth, and nth parties.
Credentials and traction
Recognized in the 2026 Gartner Magic Quadrant for Cyberthreat Intelligence Technologies, the platform also carries G2 Leader and High Performer badges for Spring 2026. CTM360 was recognized as a 2026 Bronze Winner in the Cybersecurity Excellence Awards and ranked in the 2022 Deloitte Technology Fast 50 for the Middle East. It serves banking, financial services, government, healthcare, and telecom organizations, with a free Community Edition open to any legitimate organization.
Key Capabilities
mapped to solution categoriesMonitors and alerts on deep and dark web, domain abuse, brand impersonation, social media and geopolitical risk.
Discovers or ingests external attack surface and digital asset data to curate organization-specific risk.
Supports machine-to-machine integration via JSON, APIs and STIX or TAXII, with sharing across private and public communities such as ISACs.
Ingests and shares intelligence via STIX/TAXII and other machine-to-machine formats and APIs.
Profiles threat actors with associated TTPs and attribution context.
Produces finished intelligence reports at technical, operational and strategic levels.
Offers analyst support such as requests for information, recurring analyst augmentation and takedown services.
Delivers tailored vulnerability and exposure intelligence highlighting actively exploited vulnerabilities with associated IoCs, TTPs and threat actors.
Provides comprehensive indicators of compromise such as IPs, URLs, domains and file hashes with maliciousness ratings and enrichments like geolocation and TTPs.
Provides an interactive portal with contextualized dashboards, configurable alerting, search and built-in analysis.
Discovers fake websites, social media profiles, and mobile applications impersonating the organization, using domain similarity, visual fingerprinting, and content analysis.
Monitors newly registered domains using typosquatting, homograph, and combosquatting techniques against the organization's brand, surfacing phishing infrastructure before campaigns launch.
Monitors dark web forums, marketplaces, and access broker listings for mentions of the organization, active threats, and sale of stolen access or data.
Identifies the organization's internal documents, source code, credentials, and PII on paste sites, code repositories, and dark web data markets.
Monitors external sources for leaked personal data, credential exposure, targeted phishing infrastructure, and social media impersonation targeting named executives.
Monitors social media and collaboration platforms for brand abuse, impersonation and organizational exposure.
Submits abuse reports to registrars, hosting providers, and platform operators to remove confirmed phishing pages, fake profiles, and impersonating applications.
Continuously enumerates internet-exposed assets (domains, IPs, subdomains, certificates, cloud storage, APIs) using passive DNS, certificate transparency logs, and active probing, including assets outside the official inventory.
Identifies cloud resources, SaaS applications, and exposed services deployed by business units without IT or security team visibility or approval.
Identifies software stacks, versions, and components running on discovered assets through passive banner analysis and active probing, mapping CVE exposure without authenticated scanning.
Tracks SSL/TLS certificate expirations, newly registered lookalike domains, and subdomain takeover opportunities (dangling DNS records pointing to deprovisioned cloud services).
Ranks discovered exposures by combining exploitability signals, asset business context, and active threat intelligence to produce an actionable remediation queue.
Determines which risk domains apply to each third party and scopes the assessment accordingly.
Provides ongoing visibility into third-party risk events through dashboards, alerts, reminders and notifications.
Sends, collects and evaluates third-party security questionnaires and assessments with collaboration and evidence workflows.
Identifies fourth- and Nth-party dependencies and concentration risk across the supply chain.
Maps and visualizes third- and fourth-party relationships with metrics and exportable risk data.
Generates continuous outside-in cybersecurity ratings of third parties from externally observable data.
Measures the potential impact of a third party on the business or supply chain and produces a risk impact estimate.
Discovers and monitors a third party external and internet-facing assets to surface exposure.
Manages the DMARC policy lifecycle from p=none monitoring through p=quarantine to p=reject enforcement, with visibility into failing sources and aggregate authentication reports.
Manages SPF record structure (flattening, include chain management), and DKIM key rotation across all mail sending sources to maintain authentication alignment.
Discovers all services sending email on behalf of a domain by analyzing DMARC aggregate reports, surfacing unauthorized senders and unaligned legitimate sources.
Manages the full BIMI deployment chain (DMARC enforcement prerequisite, VMC provisioning, DNS record publication), enabling brand logo display in supporting email clients.
Implementation & support
Info last updated on August 4, 2026
Buyers
See how CTM360 fits your stack
Add CTM360 to your shortlist and unlock all evaluation tools.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.