Skip to content

External attack surface management

Continuous discovery of what you expose, triage of what is actually reachable, and remediation that holds.

Free on glitchdata intermediate 4 lessons 54 min

What you'll learn

  • Build a continuous discovery pipeline from DNS, certificates and cloud APIs
  • Triage exposure by reachability and consequence rather than by scanner severity
  • Handle shadow IT and acquisitions without driving them further underground
  • Set remediation windows and exception handling that teams keep to

About this course

External attack surface management is an operational discipline, not a product: discover continuously, work out what is genuinely exposed, route it to an owner, and prove it was closed.

This course covers building the discovery pipeline, triaging findings honestly, handling shadow IT and acquisitions, and setting remediation expectations that engineering teams can meet.

Before you start

  • Understanding your attack surface, or equivalent
  • Familiarity with DNS and cloud platforms

Course content

4 lessons · 54 min

  1. 1
    Continuous discovery

    DNS, certificate transparency, cloud APIs, registrars and acquisitions — run on a schedule, not a project.

    Free preview 14 min
  2. 2
    Triage: what is actually exposed

    Reachability, authentication and consequence — in that order, before scanner severity.

    14 min
  3. 3
    Shadow IT, acquisitions and the long tail

    Why unmanaged systems appear, how to find them, and how to bring them in without driving them underground.

    13 min
  4. 4
    Remediation that actually closes

    Windows by severity and exposure, routing to owners, exceptions that expire, and proof of closure.

    13 min

What learners say

Sign in and enrol to leave a review.

No reviews yet — be the first once you have worked through it.

More in Cyber security