watchTowr
Singapore-based platform combining external attack surface management with continuous automated red teaming to validate whether exposures are actually exploitable.
Visit Website ↗Overview
watchTowr is headquartered in Singapore and has raised $19 million in a Series A round led by Peak XV (formerly Sequoia India & Southeast Asia), with participation from Prosus Ventures and Cercano Management, bringing total funding to roughly $29 million. The company’s research arm, watchTowr Labs, has built a strong public reputation in the security research community for disclosing serious vulnerabilities in widely deployed enterprise edge and networking software.
Its structural differentiator is validating exploitability rather than merely flagging presence: watchTowr’s Continuous Automated Red Teaming approach runs real-world attacker tactics across MITRE ATT&CK initial-access vectors against discovered assets, aiming to confirm whether an attacker could actually get in rather than just reporting a theoretical exposure. This combination of proactive threat intelligence, attacker telemetry, and live automated red-teaming positions it closer to offensive validation than passive asset inventory.
Innovation Matrix Assessment
watchTowr Labs maintains an unusually active public vulnerability research output on enterprise edge and VPN software, a strong indicator of continuous technical investment ahead of product releases.
Automated red teaming that validates real exploitability, rather than just flagging exposed assets, directly reduces the operational burden of triaging false-positive findings.
$19M Series A led by Peak XV with Fortune 500 and critical infrastructure customers claimed by the company, though independently reported customer counts were not found.
Continuous automated red teaming as the validation mechanism — proving exploitability through real attacker tactics rather than passive scanning — is a structurally different philosophy than conventional EASM asset listing.
watchTowr Labs' public vulnerability research and disclosures in widely deployed enterprise software are independently visible in the security community and give the company unusually strong credibility for its size.
As attack surfaces grow, the ability to distinguish theoretical exposure from actually exploitable weaknesses becomes more operationally valuable, not less.
Why CISOs Should Care
A CISO gets confirmation of which exposures an attacker could actually exploit right now, using real attack tactics, rather than a long list of theoretical findings that still need manual triage.
What Makes It Different
Instead of stopping at asset discovery, watchTowr runs continuous automated red-team attacks against discovered assets to prove exploitability, and its research team's public vulnerability disclosures feed directly back into the detection logic.
The Matrix Verdict
78/100 — MEANINGFUL INNOVATOR
A young but unusually research-credible company whose automated-red-team validation model is a genuine structural departure from passive EASM scanning — one of the more disruptive smaller entrants in this list, backed by visible, independently verifiable security research output.
Editorial Note: Claims vs. Verified Findings
Funding amount and lead investor are corroborated by SecurityWeek and watchTowr's own press release; specific customer counts and named Fortune 500 relationships are vendor-stated and not independently itemized, though watchTowr Labs' public vulnerability research output is independently observable in the security community.
Sources
Alternatives to watchTowr
Axonius
New York-based CAASM pioneer that aggregates data from hundreds of existing tools to build a unified, agentless asset…
CyCognito
Agentless attack surface management platform that maps organizations' entire external footprint, including subsidiaries and shadow assets, using graph-based…
Assetnote (Searchlight Cyber)
Offensive-security-researcher-built EASM platform from Brisbane, profitable and self-funded until its 2025 acquisition by dark-web intelligence firm Searchlight Cyber.
IONIX
EASM vendor, formerly Cyberpion, that maps not just an organization's own internet-facing assets but the chain of third-party…
Palo Alto Networks Cortex Xpanse
DARPA-derived internet scanning platform, now Palo Alto Networks' EASM module, that continuously maps and attributes internet-facing assets.
Detectify
Stockholm-based EASM and DAST platform that feeds its scanner with vulnerability research crowdsourced from a network of ethical…