Skip to content
Osintpro

Attack Surface Management From Public Records, Dated and Diffable

Most attack surface work produces a list nobody can date. A quarter later you cannot tell what changed, which is the one thing leadership actually asks. The fix is not more collection, it is putting a timestamp and a source on every item so two runs can be compared.

Passive collection throughout. Nothing here touches a system, so it works on an acquisition target as well as on your own estate.

See pricing
  • Scope recorded before collection.
  • Passive collection only.
  • Evidence a reviewer can re-run.
  • Built to clear procurement.

Attack surface discovery is not the problem, the diff is.

Every organization that has run an external surface review has the artifact: a spreadsheet of hostnames, some IP addresses, a few notes. It was accurate the week it was made. It is now of unknown age, nobody can say which entries were verified, and the next review starts from scratch.

What leadership asks is not "what do we expose". It is "what changed, and is it worse". Answering that requires two dated collections you can subtract, which means every finding needs a retrieval timestamp and a source endpoint from the first run onwards. Retrofitting that is impossible.

That is the whole design here. Collection is the easy half. The half that makes a program rather than an exercise is a record you can re-run and compare.

Run it on a domain you are authorized to assess.

This is the same collection the estate review runs, scoped to a single domain. Pick "Own estate review", tick the authorization box and run it against something you own.

  • It runs in your browser. Queries go to public DNS and RDAP endpoints, not through us.

  • Nothing reaches the subject. The domain you enter is never contacted, probed or scanned.

  • A domain, never a person. There is no input on this panel that accepts an individual.

  • Findings carry their evidence. Raw record, source endpoint and the UTC moment of retrieval.

Domain footprint sweep

passive collection only

stamped on the report
Samples:

Every finding will carry four things

  • 1 Severity. What the record means for the decision in front of you.
  • 2 The raw record. Exactly as the source returned it, unedited.
  • 3 The source endpoint. The request that produced it, so it can be re-run.
  • 4 The UTC retrieval time. Records change. Without this it is an assertion.

Reads dns.google and rdap.org from your browser. Nothing is sent to the domain you enter.

Tick the authorization box, then run the sweep. Enter the domain you are authorized to assess, then run the sweep. Run the sweep. The report lands here.

What public records expose about an estate.

All of it published by the organization itself, deliberately or otherwise, and all of it readable without sending a packet to any of your systems.

Hostnames from certificate transparency

Every publicly trusted certificate is logged, and subject alternative names make those logs a reliable inventory of hostnames, including the ones never linked from anywhere.

Mail spoofability

SPF, DKIM alignment and DMARC policy together decide whether your domain can be impersonated. Published rules with enforcement off is the most common posture on the internet and it is worth a board line.

Certificate issuance control

A CAA record restricts which certificate authorities may issue for your domain. No CAA record means any publicly trusted CA may, which is a one-line control most estates have not set.

DNS provider concentration

The nameserver set names the vendor that can change every record you own, including where mail goes. It is the highest-leverage account in the estate and it is public.

Registration exposure

Missing transfer locks on a business-critical domain, an expiry date inside ninety days, or a name sitting in a redemption period. See the status code reference.

Lookalike registrations

Typosquats and homoglyph domains targeting your brand, with registration dates and mail configuration attached, which is what turns a complaint into an actionable filing.

Passive collection, and why that boundary is commercially useful.

The distinction is not pedantic. It decides which assets you may legitimately assess without a signed testing agreement.

What it does

Passive public-source collection
Reads records published by registries, resolvers and transparency logs
Active scanning
Sends traffic to the target and observes the response

Target sees

Passive public-source collection
Nothing. No packet from you reaches them.
Active scanning
Connections in their logs, and possibly an alert

Authorization needed

Passive public-source collection
A documented business purpose
Active scanning
A signed testing agreement, every time

Works on a vendor

Passive public-source collection
Yes
Active scanning
No, not without their written permission

Works on an acquisition target

Passive public-source collection
Yes, before the deal is announced
Active scanning
No

What Osintpro does

Passive public-source collection
This, exclusively. There is no active mode.
Active scanning
Never. Use a licensed testing provider.

Reading an index such as Shodan is also passive, because the scanning already happened. The Shodan post covers where that boundary sits.

The quarterly loop that turns this into a program.

  1. Step 1

    Declare the scope once, per estate

    Own estate review, the domains and brands in scope, and what is explicitly out. Written before collection so it constrains the work rather than justifying it afterwards.

  2. Step 2

    Run the collection modules

    DNS and mail posture, registration, certificate and hostname surface, hosting fingerprint. Every finding lands with its record, endpoint and UTC retrieval time.

  3. Step 3

    Triage by severity, not by volume

    Findings arrive graded. A missing DMARC policy on a trading domain outranks forty informational hostname observations, and the report says so rather than leaving it to the reader.

  4. Step 4

    Re-run next quarter and read the difference

    Same scope, same modules, new timestamps. The diff is the finding: three new hostnames, one lock removed, an expiry now inside ninety days. That is the slide leadership actually wants.

Questions buyers ask about attack surface management.

Vulnerability management works from an asset list you already have and asks which known flaws affect it. Attack surface management works in the other direction: it asks what is exposed under your name that nobody put on the list. The first assumes the inventory is right. The second exists because it usually is not.

External attack surface management covers only what is reachable or discoverable from outside the organization: internet-facing hosts, subdomains, certificates, mail configuration and registration records. It excludes internal networks and endpoints. The scope is what an outsider could establish without credentials, which is also the scope an attacker starts from.

A tool starts from a seed you own, usually a domain or an organization name, then expands outward through public evidence: certificate transparency logs, DNS records, registration data and, in scanning products, live connections to the hosts it finds. Findings are attributed back to you, deduplicated against the last run, and the difference is what gets reviewed.

They answer different questions and most regulated programs carry both. A penetration test is a deep, point-in-time attempt to break a defined set of targets. Attack surface management is a shallow, repeating inventory of what those targets even are. A test scoped from a stale asset list will miss the host nobody remembered.

Quarterly is the common floor for an owned estate, monthly where change is fast or acquisitions are frequent, and immediately after any merger, divestment or brand launch. What matters more than the interval is that consecutive runs are comparable, so the output is a diff against the last review rather than a fresh list each time.

Public records establish what exists, who registered it, where mail routes and how the domain can be impersonated, without ever contacting the host. A scanner adds what is currently listening on a port. If your output is a dated, defensible report for a reviewer, records answer most of it. If you need live service state, add a scanner.

The scope declaration is a control, not paperwork.

Attack surface work is where OSINT most often drifts out of bounds, and the drift is usually accidental.

An analyst mapping an estate follows a pivot into a subsidiary, then into a partner, then into a director's personal domain, and nothing in the toolchain ever asked why. Every case here starts with a declared scope and a boundary, which makes the drift visible at the moment it happens.

That is also the answer when somebody asks why the security team was looking at a third party. The scope was recorded before collection started, and it is stamped on the report. Our security page sets out the passive-only guarantee, and third party risk screening covers the vendor-facing version of the same loop.

Run one scoped sweep and see what a sourced finding looks like.

The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.

See how a case runs
  • Passive collection only, from public sources.
  • A domain, never a person. There is no input for one.
  • Your case data stays yours. No card required.

Scope in, evidence out. The demo needs no card.