Skip to content

Lesson 1 of 4

Free preview

Continuous discovery

DNS, certificate transparency, cloud APIs, registrars and acquisitions — run on a schedule, not a project.

14 min 3-question quiz 3 guides to read next

On this page
  1. The sources, and what each is good for
  2. Make it a pipeline
  3. Scope carefully

Discovery is not an annual exercise. The estate changes with every deployment, and the asset that appears on a Friday afternoon is the one somebody else will find first.

The sources, and what each is good for

DNS. Your zones tell you what you publish; passive DNS data reveals names that were never documented. Watch for records pointing at released cloud resources — a dangling record is a takeover waiting to happen.

Certificate transparency. Every publicly trusted certificate is logged. Searching the logs for your domains routinely surfaces hosts, environments and even whole projects that no inventory contains.

Cloud provider APIs. The only authoritative source for what is actually exposed: public addresses, load balancers, storage with public policies, functions with public URLs, managed databases with public endpoints. Enumerate every account — and find the accounts from billing.

Registrars, address allocations and acquisitions. Companies you bought bring domains, addresses and systems, usually with no owner and worse hygiene.

Your own build and deployment systems, which know about environments before DNS does.

Make it a pipeline

Scheduled collection, normalised into one store, differenced against the last run, with changes as the output. The daily question is not "what do we have?" but "what is new, and who created it?"

Scope carefully

Define what belongs to you before you scan it: domains, address ranges, cloud accounts. Enumerating infrastructure that turns out to be a supplier's — or a different company with a similar name — is an easy and embarrassing mistake, and in some jurisdictions a legal one.

Check your understanding

3 questions · pass with 2 correct

1. What does certificate transparency reveal?
2. What is a dangling DNS record?
3. Why define ownership of scope before scanning?

You'll see your score; enrol to have it count towards your certificate.

Enrol for free to save your progress, unlock every lesson and earn a certificate.

Sign in to enrol

Further reading

Guides that go deeper on this lesson.