Case Study - Attack Surface Discovery (Know What Attackers See)

The asset inventory said 180. Attackers saw 612. We closed the gap in 9 days.

ILLUSTRATION — DISCOVERY COVERAGE
🌐 Domains 🔗 Subdomains 🖥️ IPs & Ports 🔌 APIs ☁️ Cloud Assets → Asset Inventory

Automated crawl: DNS → cert transparency → cloud APIs → port sweep → app fingerprint

Client Context

Fintech group — e-wallet, P2P lending, payment gateway. Rapid releases, 4 cloud accounts, agencies deploying promo microsites. Pre-Series-D due diligence + OJK security review.

Challenge

No one owned the full external inventory. Marketing subdomains, forgotten staging, exposed S3 and debug APIs. Risk: account takeover via forgotten asset, then pivot to payment core. Manual spreadsheet inventory updated quarterly — always stale.

Scope - Snipeyes Attack Surface Discovery (CREST methodology)

  • Automated discovery: domains, subdomains (cert transparency + DNS), IPs, open ports, web apps, APIs, cloud assets (AWS/GCP), services & banners
  • Deduplication + ownership attribution + exposure grading (internet-facing Tier 1 vs internal)
  • Weekly delta: new / changed / removed assets with alerting to security team
  • Output: living asset inventory & attack surface map feeding all downstream testing

Key Findings (redacted)

  • 612 vs 180: 432 unknown assets — 41 staging/dev, 18 agency promo sites, 9 exposed buckets, 6 debug APIs with production data
  • HIGH: Staging admin panel (staging-*.co.id) with default creds → valid session on shared SSO tenant
  • HIGH: Exposed Jenkins + Kibana without auth on 2 IPs from old ASN
  • 3 forgotten subdomains with expired CMS (RCE-class CVEs)

Outcome

  • Unknown assets reduced to 0 in 9 days: taken down, authed, or onboarded to testing scope
  • Due diligence passed — investor security questionnaire answered with live inventory export
  • Continuous: every new subdomain/asset auto-appears in dashboard within 24h, auto-queued for vulnerability scanning

Relevance for you: If you cannot list everything exposed to the internet today — start here before any pentest.