Overview
An organization's external attack surface is everything an outsider can discover and reach: domains and subdomains, IP addresses, cloud resources, certificates, web applications, APIs, SaaS tenants and code repositories.
It changes constantly. Teams launch services, acquisitions bring unknown infrastructure, and old assets are forgotten but remain online.
Key concepts
- 01
Shadow assets
Systems created outside central processes, by a team, a supplier or an acquired company, that no inventory lists.
- 02
Recurring exposures
Forgotten subdomains that can be taken over, admin interfaces open to the internet, public storage, expired or mismatched certificates and services running outdated software.
- 03
How discovery works
Starting from known domains, discovery follows DNS records, certificate transparency logs and network ranges to find what is attached to the organization, then checks what each asset exposes.
- 04
Ownership
A finding without an owner does not get fixed. Mapping each asset to a team matters as much as finding it.
What good looks like
- Start from the domains and brands you know, and let discovery expand from there.
- Assign an owner to every asset.
- Monitor continuously rather than scanning on a schedule.
- Prioritize by exposure and threat context, not by count.
- Remove what is not needed.
Common pitfalls
- Treating the last scan as the current state.
- Ignoring subsidiaries and acquired domains.
- Producing long lists with no owner.
How Neonix helps
Cybrmonk performs external attack surface management with continuous monitoring and brand monitoring, and ties findings to vulnerability and threat context.
CybrWAF can then protect the applications that discovery shows are reachable.
This note is an overview of the topic and of how Neonix approaches it. It does not report original incident data.