Attack Surface
Attack Surface answers one question: what can an attacker see?
Everything here is discovered from the outside in, from your verified domains, without anything deployed on your network. That is also its limitation - it tells you what is exposed, not what is behind it. Internal estate needs scanners.
Getting started
Discovery begins automatically once a domain is verified. There is nothing else to configure, and the first results typically appear within the hour.
If nothing is appearing, the domain is almost certainly not verified. See Getting started - that step is what authorizes discovery, and it is easy to leave half-finished because the TXT record has a trap in it.
What it finds
Discovered is the inventory: hosts and web applications found for your domains, what services they run, and what those services report about themselves.
SCREENSHOT: the Discovered view listing hosts and services.
External attack surface is the roll-up - the shape of your exposure rather than the item-by-item list. Start here to get oriented, then drill down.
External intelligence is what can be learned about you from outside your estate without touching it - information already published, indexed, or leaked. It is the context around the inventory rather than the inventory itself, and it is where exposure that no scan can find shows up.
DNS covers the records for your domains. Worth attention beyond inventory: stale records pointing at deprovisioned infrastructure are how subdomain takeovers happen, and they are invisible unless something is watching for them.
Host services is what is listening where. The usual first pass is looking for things that should never be internet-facing - database ports, management interfaces, admin panels.
Domain security covers the domain's own posture: the mail-related records that decide whether someone can send mail as you.
SSL certificates tracks certificates for your exposed services - issuer, validity, what is about to expire. An expiring certificate is an outage with advance notice, which makes it one of the few security findings with a hard deadline attached.
Security headers checks what your web applications send back. Low individual severity, useful in aggregate, and usually cheap to fix.
Network vulnerabilities are the findings on everything above. These flow into the main findings queue rather than living only here - see Findings and triage.
Working through it
The inventory is not the point; the exceptions are. A useful first pass:
- Hosts you do not recognise. Shadow IT and forgotten infrastructure surface here before they surface anywhere else, and unknown-but-yours is the highest-value thing on this page.
- Services that should not be public. Management and database ports reachable from the internet.
- Certificates expiring soon. Fixed deadline, known consequence.
- DNS records pointing nowhere. Takeover risk.
- Everything else, by severity.
The first pass through attack surface is also the best opportunity to tag assets - owner, environment, whether it is meant to be public. It is tedious once and saves every subsequent triage. See Organizations, business units, and zones.
Discovery is continuous
This is not a point-in-time scan. New hosts appear as they are exposed, and that is the part with ongoing value - a service accidentally published on a Friday shows up without anyone thinking to look.
An asset that stops being discovered is not deleted. Its history stays, because "this was exposed for six weeks" is a question that gets asked later. See Assets.
API
The endpoints behind this section are in the API reference.
Next
- Findings and triage - working what is found here
- Cloud Exposure - the inside view of cloud assets
- Assets - why one machine can appear more than once