Skip to content

Attack Surface Discovery: DNS, Certificates and Cloud

Finding the internet-facing things you own, including the ones nobody remembers creating.

Editorial team 2 min read

External attack surface management begins with an unglamorous fact: nobody has a complete list of what their organisation exposes.

The sources

DNS. Zone data for domains you know, plus passive DNS to find subdomains that were never documented. Watch for records pointing at decommissioned cloud resources — a dangling record is a takeover waiting for somebody to claim the name.

Certificate transparency. Every publicly trusted certificate is logged. Searching the logs for your domains reveals hosts that were never in any inventory, often in environments you did not know existed.

Cloud provider APIs. Enumerate from the accounts themselves: public IPs, load balancers, storage buckets, functions with public URLs, managed databases with public endpoints. This is the only authoritative source, and only for the accounts you know about — so start with billing, which knows about all of them.

Registrars, ASNs and acquisitions. Companies you bought bring domains, addresses and systems with them, usually with worse hygiene and no owner.

Turning discovery into a programme

Discovery without ownership produces a list nobody acts on. Each asset needs an owner, a business purpose and a decision: keep and secure, or remove. The second option is the one most under-used — the cheapest reduction in attack surface is turning things off.

Run discovery continuously. Attack surface changes with every deployment, and the asset that appears on a Friday afternoon is the one that will be found by somebody else.

More in Cyber security

All Cyber security guides →
Cyber security Guide · 2 min

What a Penetration Test Is, and Is Not

A penetration test is a time-boxed, authorised attempt to reach a defined objective — not a full inventory of every weakness you have.

Cyber security 2 min read 25 May 2025

Cyber security Guide · 2 min

Rules of Engagement and Authorisation

What to agree before any testing starts: scope, timing, data handling, escalation and the single document that makes the work lawful.

Cyber security 2 min read 24 May 2025

Cyber security Guide · 2 min

Writing a Finding People Will Fix

Severity, evidence, reproduction, impact in business terms, and a fix the team can actually make.

Cyber security 2 min read 23 May 2025

Cyber security Guide · 2 min

Vulnerability Scanning Done Properly

Credentialed scans, asset coverage, tuning out noise, and why scan counts are a bad metric.

Cyber security 2 min read 22 May 2025