Attack Surface Report

Point us at your domain. We'll show you what an attacker sees.

Request a free Attack Surface Report and one of our security engineers will run a hands-on scan on your public assets and walk you through what we find.

Results delivered and reviewed within 3-5 working days.

Where should we look?

Tell us where to start. We'll take it from there.

We only scan what you authorize. Testing is non-intrusive and won't disrupt your services.

How it works

From request to review in a few days

1.

Request and authorize

Send us your primary domain and confirm you own it. Setup takes a few minutes, and there's nothing to install on your side.

2.

Hands-on scan

One of our security engineers investigates your public-facing assets using the same techniques a real attacker would use to size up your surface.

3.

Review the findings

Within 3-5 working days, we'll get on a short call to walk you through the findings, prioritized by risk. You'll leave with a shortlist of what to fix first and why.

What you'll uncover

A verified baseline of your external attack surface

Domains and subdomains

Every domain, subdomain, and Shadow IT asset tied to your infrastructure, including the ones you didn't know existed.

Open ports

Exposed services and entry points attackers probe first, including ports left open by misconfiguration or forgotten deployments.

Publicly exposed IPs

Which of your IP addresses are reachable from the public internet, and where an attacker could get a foothold.

What you'll get

See what lands in your inbox

Attack Surface Report

Your custom baseline of external exposure

Semi-automated discovery combined with hands-on review by a Detectify Solutions Engineer.

Prepared for
Example Corp
Root domain
example-corp.com
Reviewed by
Detectify Solutions Engineer
Overview
Executive summary

What we found on your public net

62
Assets
4
Critical
9
Medium
27
Low

Example Corp's external attack surface is broader than what appears in your DNS inventory. Manual review surfaced one high-impact takeover vector, three TLS-related risks, and a group of forgotten marketing subdomains.

Findings
Priority findings

Findings worth acting on first

Ordered by exploitability, then blast radius.

01Dangling CNAME on legacy marketing subdomainCritical
02Two TLS certificates expire within 22 daysCritical
0314 subdomains not on your DNS inventoryMedium
04Web server running version with public CVEsMedium
05Dev endpoint exposed without authenticationMedium
Discovery
Domain discovery

What we found on your surface

example-corp.com
www.example-corp.com
api.example-corp.com
staging.example-corp.comnew
dev-tools.example-corp.comnew
partner.example-corp.comnew
legacy-2019.example-corp.comtakeover
internal-events.example-corp.comnew

Showing 7 of 62 · full inventory in report

DNS
DNS hygiene

What your DNS records say about you

RecordTypeStatus
legacy-2019CNAMETakeover
temp-eventsAUnreachable
example-corp.comSPFToo broad
example-corp.comDMARCp=none
mailMXHealthy
TLS
TLS certificates

What your certificates look like from the outside

HostExpiresStatus
api2026-10-1822 days
mail2026-10-1418 days
app2027-06-04Healthy
docs2027-01-08TLS 1.1
status2027-02-12Healthy
Tech
Technology stack

What's running on your public net

TechnologyVersionNote
nginx1.18.03 CVEs
Rails7.0.4Minor drift
WordPress6.4.1Update
Hosting
AWS us-east-1
38
Cloudflare
27
GCP eu-west1
14
3rd-party
21
Actions
Recommended next steps

What we'd act on this month

Ordered by impact, assuming finite time this quarter.

✓
Reclaim the dangling CNAME on legacy-2019
Register the third-party endpoint or remove the record. Exploitable today.
✓
Renew or automate the two certs expiring under 30 days
api and mail. Push onto automated renewal path.
✓
Add 14 newly discovered subdomains to inventory
Assign an owner before deciding to monitor, redirect or retire.
✓
Tighten SPF and enforce DMARC policy
Move DMARC from p=none to p=quarantine after 30-day observation.

Frequently asked questions

Don't wait for an incident to find your blind spots

Point us at your domain. One of our security engineers will run a hands-on scan and walk you through what we find.

Request Your Attack Surface Report