Background Gradient

Complete visibility

Assetnote is now part of Searchlight Cyber

Assetnote’s Attack Surface Management platform is now called Searchlight Exposure.

The same team and leading security research power Searchlight’s complete Preemptive Threat Exposure Management platform.

Still leading the way

What this means for you

Assetnote was acquired by Searchlight Cyber in 2025. Since then, our teams have worked closely to combine the value of Searchlight’s visibility into attacker behavior with Assetnote’s exposure management capabilities.

If you’re an existing Assetnote customer, our commitment to the technology, the team behind it, and our preemptive mission remains unchanged. Our customers continue to get the same pre-disclosure research and continuous ASM protection, delivered by the Searchlight platform.

Software dashboard showing confirmed exploitable vulnerability with local file disclosure on Jenkins server at port 8080.

Meet the team

Searchlight Cyber is built by a mission driven team

Our leadership team are experts in cybersecurity, attack surface management, the dark web, law enforcement, and defense.

Michael Gianarakis

CEO at Searchlight Cyber

Michael Gianarakis is CEO of Searchlight Cyber, a leader in premptive cybersecurity. With over a decade in the security industry, Michael has built and led offensive security teams across Asia Pacific and Japan. In 2018 he co-founded Assetnote, a pioneering attack surface management platform acquired by Searchlight Cyber in 2025 – bringing best-in-class ASM capability into the PTEM platform. Michael is a respected security researcher and has presented at DEF CON, Black Hat Asia, BSides Las Vegas, Hack in the Box, AusCERT, Thotcon, 44Con, and OWASP.

Michael Gianarakis
Shubham Shah

Chief Security Research Officer at Searchlight Cyber

Shubham Shah is Chief Security Research Officer, having joined Searchlight Cyber following the acquisition of Assetnote, where he was Co-Founder and CTO. Shubham leads the global security research team whose findings feed directly into Searchlight Exposure – surfacing zero-day vulnerabilities in the tools organisations rely on, often months ahead of public disclosure. He remains a prolific bug bounty hunter ranked in the top 50 hackers on HackerOne, and has presented at various industry events including QCon London, Kiwicon, AusCert, BSides Canberra, and CrikeyCon.

Shubham Shah
Timothy Hunt

VP of Customer Success at Searchlight Cyber

Timothy Hunt is the Vice President of Customer Success at Searchlight Cyber, where he leads the customer success function across the business. With over a decade in the information security industry, Tim has built and led global teams, which help organizations of all sizes understand their risk, strengthen their security programs, and get measurable value from their security investments.

Timothy Hunt

Key Capabilities

ASM that just works

Discover everything on your attack surface

Web applications, APIs, cloud infrastructure, DNS, certificates, and subdomains, discovered and validated across the whole external surface, so exposure is proven wherever it lives, not just on the assets that were easy to find.

Only what's real reaches you

Searchlight automatically cross-references your assets, including the versions you're running, to verify an exposure is legitimate before alerting your team. You only hear about the exposures that are genuinely exploitable and exposed, not the ones that aren't.

Know it's closed, the moment you fix it

Re-run the original exploit the instant you've remediated, and watch it fail, no waiting for the next scheduled scan while attackers move in hours. Every action is logged, so each exposure is tested, resolved, and recorded with a clear audit trail.

Send findings straight for remediation

Every finding is proven before it lands, so confirmed exposures route straight into Splunk, Jira, and your SIEM or SOAR. The signal is strong enough that some customers send critical ones to engineering with no human review in between.

Background Gradient

96%
faster discovery and validation than other vendors

I asked our SOC Team Leader earlier, how long could we be without Searchlight? Would it be for minutes, hours, days? The response: We couldn’t. The Searchlight ASM solution is a key part of our security program, and we could not do without it.

Chief Information Security Officer

Multi-national Technology Company

Research-led Security

Searchlight’s researchers continue to discover vulnerabilities across the enterprise software you actually run, and they find them first, so you're protected before the patching scramble begins.

All publications

Technical Blog

View Article

Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25

July 20, 2026

Technical Blog

View Article

wp2shell: Pre Authentication RCE in WordPress Core

July 17, 2026

Technical Blog

View Article

Smashing the ServiceNow Sandbox – Pre Authentication RCE

July 14, 2026

Technical Blog

View Article

CargoWise WebTracker – The Keys Were in the Cargo

June 25, 2026

FAQ

Frequently asked questions

Searchlight Cyber is a leader in preemptive cybersecurity. Founded in 2017 to support criminal investigation teams in conducting secure investigations on the dark web, the company later made the same law-enforcement-grade intelligence available to enterprises, so they could see who is targeting them. In 2025, Searchlight acquired the leading exposure validation platform, Assetnote, to enhance its customers’ ability to identify and respond to the highest-priority threats. Since then, the company has acquired the cyber risk company, Intangic, and continues to be at the forefront of preemptive cybersecurity, conducting research into hidden criminal activity and uncovering zero-day vulnerabilities in some of the most widely used enterprise software.

Searchlight Exposure, formerly Assetnote, is an external attack surface platform that continuously discovers and validates where organizations are exposed. Searchlight Threat automatically monitors hard to reach sources across the clear, deep, and dark web to identify when attackers are targeting your organization. Both are powered by our expert research into vulnerabilities and attacker behavior. Together, they enable security teams to know what’s exposed and what’s critical – meaning security teams are able to identify and remediate their most critical threats before they become incidents.

Preemptive Threat Exposure Management helps security teams find, validate, and prioritize exposures before they become incidents. It combines visibility into your external attack surface with real-world threat context, so teams can focus on what attackers are actually targeting.