All posts

Map What Attackers Can Already See

guideattack surfaceorganizations

Bayloz campaign poster for Exposure and Attack Surface: a shark fin cutting through neon-lit water.

Nobody starts with the exploit. An attacker's first hour is spent looking, and every bit of it happens from the outside, without touching anything you would consider a system.

The uncomfortable part is that they are working from the same public sources you could check yourself, and they usually end up with a more current picture of your organization than your own asset inventory holds.

What counts as attack surface

More than the servers you know about:

  • Domains and subdomains, including the staging site somebody stood up for a launch two years ago and never took down.
  • Cloud storage left open, and the backups nobody remembered were in it.
  • Login panels facing the internet: VPNs, admin interfaces, remote desktop, forgotten dashboards.
  • Credentials in breach data, where a work email and a reused password appear together in an old dump.
  • Code and configuration, in public repositories, including keys committed by accident and never rotated.
  • Your people. Roles, reporting lines, email format, who just joined, who is on leave. This is what turns a generic phishing email into one that works.
  • Documents. Published PDFs carrying software versions, internal usernames, and file paths in their metadata.

Why the inventory is always wrong

Not through negligence. Through normal work.

A campaign needs a microsite. A vendor gets a subdomain. An engineer spins up a test environment on a Friday. A department buys a SaaS tool on a card and connects it to your identity provider. Each is reasonable. None of them makes it onto a list, and each one persists long after the person who created it moved on.

Attack surface is not built. It accumulates, and it only ever grows unless something deliberately prunes it.

What an assessment actually does

We look at your organization the way someone targeting it would, using open sources and lawful reconnaissance only. Nothing is exploited, and nothing is accessed that is not already public.

The output is not a scanner dump. It is a ranked picture:

  • Everything internet-facing we could attribute to you, including what you did not know about.
  • Exposed credentials and where they came from.
  • The realistic paths in, described as a chain rather than a list of isolated findings.
  • The specific people most likely to be targeted first, and why.
  • What to fix in what order, separated into what closes an actual path and what is merely tidy.

Do this before you call anyone

Three things you can check today:

  1. Enumerate your own subdomains from public certificate transparency logs. Certificates are published, so every hostname you have ever issued a certificate for is already a matter of record.
  2. Check your domain against a breach index and see which staff addresses appear.
  3. Search for your domain name alongside terms like admin, login, and test, and see what answers.

If any of that surprises you, that is the finding.

Then close the loop

Mapping once is useful. Mapping once and never again gives you a document that is wrong within a quarter, which is why our Exposure and Attack Surface work pairs the initial map with ongoing monitoring rather than leaving you with a PDF.

Request an assessment and we will scope it against what you actually run.