Lesson 1 of 4
Continuous discovery
DNS, certificate transparency, cloud APIs, registrars and acquisitions — run on a schedule, not a project.
14 min 3-question quiz 3 guides to read next
Discovery is not an annual exercise. The estate changes with every deployment, and the asset that appears on a Friday afternoon is the one somebody else will find first.
The sources, and what each is good for
DNS. Your zones tell you what you publish; passive DNS data reveals names that were never documented. Watch for records pointing at released cloud resources — a dangling record is a takeover waiting to happen.
Certificate transparency. Every publicly trusted certificate is logged. Searching the logs for your domains routinely surfaces hosts, environments and even whole projects that no inventory contains.
Cloud provider APIs. The only authoritative source for what is actually exposed: public addresses, load balancers, storage with public policies, functions with public URLs, managed databases with public endpoints. Enumerate every account — and find the accounts from billing.
Registrars, address allocations and acquisitions. Companies you bought bring domains, addresses and systems, usually with no owner and worse hygiene.
Your own build and deployment systems, which know about environments before DNS does.
Make it a pipeline
Scheduled collection, normalised into one store, differenced against the last run, with changes as the output. The daily question is not "what do we have?" but "what is new, and who created it?"
Scope carefully
Define what belongs to you before you scan it: domains, address ranges, cloud accounts. Enumerating infrastructure that turns out to be a supplier's — or a different company with a similar name — is an easy and embarrassing mistake, and in some jurisdictions a legal one.
Check your understanding
3 questions · pass with 2 correct
Enrol for free to save your progress, unlock every lesson and earn a certificate.
Sign in to enrolFurther reading
Guides that go deeper on this lesson.
-
Attack Surface Discovery: DNS, Certificates and Cloud
Finding the internet-facing things you own, including the ones nobody remembers creating.
2 min read
-
Shadow IT and Unmanaged Assets
The systems nobody told you about, why they appear, and how to find them without becoming the enemy.
2 min read
-
Cloud Misconfiguration and Public Exposure
The handful of settings behind most cloud incidents, and how to catch them before someone else does.
2 min read