Attack Surface Management
How Companies Discover Exposed Assets: Methods & Best Practices
Companies discover exposed assets through: DNS enumeration (finding all subdomains and records), certificate transparency monitoring (certificates reveal hostnames), internet-wide scanning (Shodan, Censys searches), cloud account inventory (API-based enumeration of all cloud resources), WHOIS and ASN analysis (IP range identification), web crawling (discovering linked resources), and dark web monitoring (finding leaked infrastructure details).

Andreas Johansson · Chief Executive Officer
Senior IT management leader with 25 years of experience in Cloud, Security, and Datacenter infrastructure.
The Discovery Challenge
Discovering your full attack surface requires thinking like an attacker — using the same techniques and data sources that adversaries use to map your infrastructure before launching an attack.
The goal is asymmetric advantage: find your exposed assets before attackers do, and remediate the exposure before it's exploited.
Discovery Methods
DNS Enumeration
DNS is the foundation of asset discovery. Every internet-facing service has a DNS record (or should), and DNS records reveal the structure of your infrastructure.
- Subdomain brute forcing. Attempting resolution of common subdomain names (dev., staging., api., admin., test., vpn.) against your domain. Tools like Amass and Subfinder automate this with wordlists of tens of thousands of common names.
- Zone transfers. Misconfigured DNS servers may allow zone transfers — dumping all DNS records for a domain. While this misconfiguration is increasingly rare, it still occurs and reveals the complete DNS inventory.
- Reverse DNS. Looking up hostnames for IP addresses in your ranges reveals services that may not be linked from your primary domains.
- DNS record types. Beyond A records, examining MX (email servers), TXT (may contain SPF rules revealing email infrastructure), CNAME (reveals hosting relationships), and SRV (reveals specific services) records.
Certificate Transparency
Certificate Transparency (CT) logs are public, append-only records of every SSL/TLS certificate issued by participating certificate authorities. Since certificates include the hostnames they protect, CT logs reveal:
- All subdomains that have had certificates issued
- Internal hostnames that appeared on certificates (common misconfiguration)
- Certificate issuance patterns that reveal infrastructure structure
- Certificates issued without authorization (potential phishing or compromise)
CT monitoring is particularly valuable because it's passive (no scanning required) and reveals assets as soon as certificates are issued — often before the associated service is even publicly accessible.
Internet-Wide Scanning
Services like Shodan and Censys continuously scan the entire internet, indexing every service on every IP address. Searching these databases for your organization reveals:
- Services running on your IP ranges
- Technologies and versions exposed to the internet
- Misconfigured services (default pages, exposed admin interfaces)
- IoT devices and operational technology
- Services on non-standard ports that manual scanning might miss
Cloud Account Inventory
Cloud resources are a rapidly growing component of the attack surface. Discovery requires:
- API-based enumeration. Using cloud provider APIs (AWS describe-*, Azure Resource Graph, GCP Asset Inventory) to list all resources across all accounts, regions, and services.
- Cross-account discovery. Organizations often have multiple cloud accounts (production, staging, development, sandbox). Assets in any account are part of the attack surface.
- Multi-cloud visibility. Organizations using multiple cloud providers need discovery across all of them — assets in a forgotten GCP project are as risky as assets in a production AWS account.
- Configuration assessment. Beyond discovering assets, assess their configuration — public accessibility, security group rules, encryption status, and IAM policies.
WHOIS and ASN Analysis
WHOIS records and Autonomous System Number (ASN) registrations reveal:
- IP address ranges registered to your organization
- Domain registration details and related domains
- Organizational relationships revealed by registration data
- Historical registration data (domains and IPs previously associated with your organization)
Web Crawling and Link Analysis
Crawling your known web properties reveals linked resources:
- References to internal systems in public-facing pages
- API endpoints referenced in JavaScript code
- Third-party services integrated into your applications
- Linked subdomains and related domains
Dark Web and Breach Monitoring
Monitoring dark web forums, marketplaces, and paste sites reveals:
- Leaked credentials that expose your systems
- References to your infrastructure in attack planning discussions
- Stolen data that indicates a breach you may not have detected
- Access to your systems being sold by initial access brokers
Building a Discovery Program
Phase 1: Initial Assessment (Week 1)
Run comprehensive discovery to establish your baseline:
- Enumerate all DNS records for all known domains
- Search certificate transparency for all certificates
- Search Shodan/Censys for your IP ranges
- Inventory all cloud accounts and resources
- Compare discoveries against your known asset inventory
- Expected outcome: A baseline list of discovered assets to reconcile against your documented inventory.
Phase 2: Continuous Monitoring (Ongoing)
Establish ongoing discovery to detect changes:
- Daily certificate transparency monitoring
- Weekly DNS enumeration
- Continuous cloud inventory (API-based, real-time)
- Monthly internet scanning review
- Quarterly comprehensive reassessment
Phase 3: Integration (Month 2+)
Connect discovery to security operations:
- New assets trigger vulnerability scanning
- Exposed assets feed into risk dashboards
- Unowned assets trigger investigation workflows
- Changes in asset configuration generate alerts
How SeqOps fits
SeqOps covers the cloud and server part of your attack surface: it inventories resources in your connected cloud accounts and flags exposed services and misconfigurations. It doesn't scan the internet for assets you haven't connected.