from the outside, like an attacker
Attack Surface Analysis
Our Attack Surface Analysis service shows you your infrastructure from an attacker's perspective. We identify known and unknown assets, evaluate their exposure, and reveal what information about you is freely accessible on the internet, using the same methods and tools that real-world attackers use.
Request AnalysisAll ServicesAttack Surface Analysis
External Perimeter • Shadow IT • Exposure Mapping
Perspective
Starting Point
as little as a domain name
Outcome
complete overview of your attack surface
Effort
minimal effort on your part
When an Analysis Is Worth It
- You are unsure which parts of your infrastructure are actually publicly accessible.
- Prior to a penetration test, to define the most meaningful test scope based on data rather than guesswork.
- Following mergers, acquisitions, or corporate buyouts where the complete IT landscape is unknown.
- Legacy subdomains, staging systems, or past project environments might still be live without anyone’s knowledge.
- An audit according to ISO 27001, BSI IT-Grundschutz, or NIS2 requires verification of your external attack surface.
- You want to discover what information about your organization and employees is publicly available before an attacker finds it.
- As technical evidence for a SOC 2 audit or comparable vendor assessments by your customers.
What We Uncover
We provide full clarity across all facets of your external presence:
How Much Information You Provide
No extensive technical prerequisites are required on your end. You simply provide us with a starting point, as minimal or detailed as you prefer:
Minimal
A company name or a single domain, exactly what an external attacker would know.
Moderate
Known domains and subdomains to deepen the analysis in a more targeted manner.
Comprehensive
A preliminary asset list for cross-referencing your internal view with external reality.
In every case, we go beyond what you provide and actively look for assets you might not be aware of. This very delta between what you know and what is actually exposed often delivers the most valuable insight.
How the Analysis Works
The process is straightforward, structured, and requires zero intervention in your running systems:
Define Starting Point
You provide what you already know; minimal (e.g., domain name) or comprehensive (asset list).
Reconnaissance
Systematic mapping using the methods and tools of real attackers: domain intelligence, certificate transparency, search engines, public registries, and passive reconnaissance without active interaction with your systems.
Assessment
Classification of discovered assets by exposure and criticality – because not every finding carries the same significance.
Report & Recommendations
Delivery of the comprehensive overview with prioritized recommendations for your next steps.
What You Gain from It
The Attack Surface Analysis provides you not only with a clear overview of your external attack surface, but also with a solid foundation for further measures such as a targeted Penetration Test or the hardening of exposed systems, for instance with our Microsoft M365 Hardening. Upon request, we also support you beyond the analysis.
Specifically, you receive:
Asset Inventory
All discovered systems and services, including those previously unknown to you.
Exposure Assessment
Clear classification of how critical and vulnerable each individual finding is.
Prioritized Recommendations
Actionable next steps so you know exactly where to begin.
Basis for Follow-Up Projects
A data-driven foundation for targeted penetration testing instead of an arbitrary scope.
Analysis vs. Penetration Testing
Attack Surface Analysis answers what is externally visible and reachable. It does not exploit whether a discovered system is actually vulnerable, that is the role of a Penetration Test. Both services complement each other: The analysis delivers the map, while the test probes the paths marked on it.
For continuous monitoring of discovered assets, Vulnerability Scanning & Management is an ideal addition, whereas an Attack Surface Analysis is typically conducted selectively or at regular intervals, such as annually or following major organizational changes.
Attack Surface Analysis
A domain name is all it takes to get started. In an initial conversation, we clarify the scope and how much information you wish to provide.
- Zero active interference with your systems
- Uncovers forgotten shadow IT
- Assessment based on exposure and criticality
- Foundation for a targeted penetration test
Results & Compliance
You receive a structured final report with a complete attack surface map and prioritized recommendations. This serves as reliable evidence for:
Confidentiality & Data Protection
Research & Best Practices
We conduct our own security research and publish findings through responsible disclosure processes (e.g., vulnerabilities in federal systems, path traversal in surveillance software).
Case Study: Hidden Shadow IT
Initial situation: A corporation assumed it had 15 public web servers, but had undergone multiple acquisitions and spin-offs over the past 5 years.
Approach: Complete passive Attack Surface Analysis using DNS, certificate transparency, and historical registration data.
Result: Identification of over 40 forgotten subdomains and 3 unprotected staging servers with database access, which were immediately decommissioned.
What Clients Want to Know Beforehand
Frequently asked questions and answers regarding the process and value of an Attack Surface Analysis.
Do you actively access our systems during the analysis?
The analysis relies predominantly on passive reconnaissance—that is, publicly accessible information and metadata—without actively penetrating your systems. This distinguishes it from a penetration test.
How quickly do we receive results?
That depends on the size and complexity of your infrastructure. You will receive an accurate timeframe directly following our initial consultation.
What if you find something acutely critical?
We report critical findings immediately and out of band, regardless of the scheduled reporting date.
Is this sufficient as a standalone security measure?
No, the analysis maps the attack surface but does not exploit actual vulnerabilities. A penetration test is the logical next step for that.
Who benefits most from this service?
For organizations seeking to understand how their infrastructure appears from an outside perspective—especially following mergers, acquisitions, or where IT environments have grown historically complex.

