Skip to main content
All research notes

Attack Surface

7 min read

Your attack surface drifts faster than your test cycle

An annual penetration test measures the estate as it stood on one morning in March. Cloud accounts, DNS records and third party integrations change every week, so the gap between that report and reality starts widening the day it is delivered. Continuous discovery is what keeps the gap small.

Written by the Principal Security Consultant

Most organisations we work with book one external penetration test a year, usually in the same month, usually against a scope agreed in a spreadsheet a few weeks earlier. That is honest work and it produces real findings. The problem is what it measures: the estate as it stood on a single morning, described by the people who remembered to describe it.

By the time the report is signed off, a team has stood up a staging environment on a subdomain, marketing has pointed a CNAME at a new analytics vendor, and somebody opened a management port at eleven at night to debug a deployment and did not close it again. None of that is negligence. It is the ordinary metabolism of a company that ships software, and the test cycle does not run at the same speed.

Drift has a small number of causes

When we compare a client's asset inventory against what we can see from the internet, the differences fall into a handful of recurring shapes. Naming them is useful, because each shape has a different owner and a different fix.

  • DNS entries outlive the things they point at, which is how subdomain takeover keeps appearing years after the technique was first documented.
  • Cloud accounts multiply faster than the inventory that tracks them, particularly where a business unit holds its own billing relationship.
  • Third party integrations bring their own hostnames, their own identity trust and their own login pages inside the perimeter, all outside change control.
  • Temporary infrastructure built for a migration or a load test becomes permanent, because nobody was ever scheduled to remove it.
  • Acquisitions arrive with an estate that was never in scope, often without documentation the acquiring security team can read.

The scope document is part of the problem

A scope of twenty addresses and four hostnames turns an assessment into a verification exercise. We test what we were given, we report what we found, and the assets nobody remembered stay untested by definition. NIST SP 800-115 puts discovery before testing and PTES puts intelligence gathering before vulnerability analysis for the same reason. Where discovery is done by the client, in advance, from memory, the assessment inherits every blind spot the client already had. We have opened engagements by reading certificate transparency logs for a client's domains and returning a list of live hosts longer than the scope we were sent.

The asset nobody remembered to put in scope is the asset nobody has patched, monitored or reviewed either.

What continuous discovery actually involves

Attack surface management is a product category now, and some of the tooling is genuinely good, but the practice is older than the acronym. It is passive DNS and certificate transparency, enumerating the netblocks and cloud tenancies the organisation owns, resolving hostnames on a schedule, fingerprinting whatever answers, and comparing today against last week. The value sits in the comparison. A new host appearing on a Tuesday afternoon is a signal that somebody can still remember deploying; the same host in a report three months later is an archaeology exercise.

Machine speed and human speed

Automation is the wrong tool for judgement and the right tool for coverage, so we split the work along that line. Discovery pipelines and scanners run continuously and answer one question: what is new and what changed. People answer the harder one, which is whether the change matters. An exposed staging host with a default administrative account matters. A new content delivery edge presenting a certificate for a name you already own usually does not. Pushing every difference into a ticket queue without that filter produces noise, and a queue that is mostly noise teaches everybody to ignore it.

Where the scheduled test still earns its place

None of this replaces deep manual testing. Business logic flaws, chained authorisation bypasses and the multi step abuse described in the OWASP Web Security Testing Guide will never fall out of a scanner, and no amount of monitoring finds them. The point is to stop spending expert hours rediscovering an inventory that could have been maintained automatically. When discovery runs continuously, the scheduled engagement starts from an accurate picture and the testers spend their week on the parts of the estate that need a human. That is the split we aim for with clients: machines watching the edges every day, people going deep a few times a year.

Written by the Principal Security Consultant at Nullpath Security. Engagement detail in these notes is anonymised and published only where it cannot identify a client.

  • Engagement Design

    Red team or penetration test: choosing the right engagement

    A penetration test asks how much of a system is broken. A red team engagement asks whether anyone would notice a competent operator coming for a specific objective. Choosing the wrong one wastes the budget and produces a report nobody can act on.

    Read the note

  • Internal Testing

    Five Active Directory misconfigurations that hand over domain admin

    Most internal assessments reach domain admin through configuration rather than a missing patch. Kerberoastable service accounts, permissive certificate templates, wide delegation, available NTLM relay and forgotten access control entries account for most of the paths we walk. All five are fixable in house.

    Read the note

Start here

Find out what an attacker would reach first.

Send us the shape of your environment and a rough deadline. A consultant replies within one business day with a scope, a window and a fixed price. No sales sequence, no discovery deck.

Expires in

Limited time offer

We rebuilt your site for you. Claim it and we handle everything transfer, hosting, and your domain. Then update it anytime, just by asking AI.

Host for only$8 per monthBilled yearly
Claim limited offer now