Case Study - Attack Surface Discovery (Know What Attackers See)
The asset inventory said 180. Attackers saw 612. We closed the gap in 9 days.
Automated crawl: DNS → cert transparency → cloud APIs → port sweep → app fingerprint
Client Context
Fintech group — e-wallet, P2P lending, payment gateway. Rapid releases, 4 cloud accounts, agencies deploying promo microsites. Pre-Series-D due diligence + OJK security review.
Challenge
No one owned the full external inventory. Marketing subdomains, forgotten staging, exposed S3 and debug APIs. Risk: account takeover via forgotten asset, then pivot to payment core. Manual spreadsheet inventory updated quarterly — always stale.
Scope - Snipeyes Attack Surface Discovery (CREST methodology)
- Automated discovery: domains, subdomains (cert transparency + DNS), IPs, open ports, web apps, APIs, cloud assets (AWS/GCP), services & banners
- Deduplication + ownership attribution + exposure grading (internet-facing Tier 1 vs internal)
- Weekly delta: new / changed / removed assets with alerting to security team
- Output: living asset inventory & attack surface map feeding all downstream testing
Key Findings (redacted)
- 612 vs 180: 432 unknown assets — 41 staging/dev, 18 agency promo sites, 9 exposed buckets, 6 debug APIs with production data
- HIGH: Staging admin panel (
staging-*.co.id) with default creds → valid session on shared SSO tenant - HIGH: Exposed Jenkins + Kibana without auth on 2 IPs from old ASN
- 3 forgotten subdomains with expired CMS (RCE-class CVEs)
Outcome
- Unknown assets reduced to 0 in 9 days: taken down, authed, or onboarded to testing scope
- Due diligence passed — investor security questionnaire answered with live inventory export
- Continuous: every new subdomain/asset auto-appears in dashboard within 24h, auto-queued for vulnerability scanning
Relevance for you: If you cannot list everything exposed to the internet today — start here before any pentest.