Disciplines

🔍 Attack Surface Intelligence (ASMINT)

Your Own Exposed Attack Surface
Cyber & Threat

Sources

3
2 no-auth

Mission domains

2
reach

Data points

4
covered

Related INT

2
disciplines

🔌 Sources for Attack Surface Intelligence (3)

SourceCategoryAuthFormat
FireHOL IP Blocklists
Aggregated abusive-IP blocklists.
Operational SecurityNONEtexthome↗ api↗
Gitleaks Rules (secret exposure)
Detect exposed secrets/keys patterns.
Operational SecurityNONEtexthome↗ api↗
Shodan ICS/SCADA
Exposed ICS/SCADA device discovery.
Critical InfrastructureKEYjsonhome↗ api↗

🔍 Lookup

📜 Playbook — Attack Surface Intelligence collection

  1. Direction — frame the requirement for Attack Surface Intelligence: what decision does this support, by when?
  2. Collection — collect from the 3 mapped sources (2 free) — filter the catalog by ASMINT; capture provenance and observe OPSEC.
  3. Processing — normalize, de-duplicate and enrich the collected data.
  4. Analysis — correlate against local holdings; apply ACH; assign confidence.
  5. Dissemination — open a case, draft a report, share via STIX/MISP.
  6. Feedback — set an alert rule / watchlist to monitor for change.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🎯 Mission

Attack Surface Intelligence discovers and continuously inventories an organization's externally reachable assets, services, ports, and misconfigurations as an adversary would see them. It answers what is exposed to the internet, which internet-facing systems are exploitable, and where undocumented shadow IT and forgotten cloud assets are leaking.

📡 Collection methods

  • Internet-wide port and service scanning with banner grabbing across the target's IP and ASN space
  • Subdomain enumeration via passive DNS, CT logs, and DNS brute-forcing
  • Cloud and SaaS asset discovery (S3/GCS/Azure buckets, exposed APIs, dev/staging hosts)
  • Favicon-hash and HTML-title fingerprinting to cluster related web properties
  • TLS certificate correlation to tie hosts to organizational identity
  • Template-based vulnerability probing of discovered services (default creds, known CVEs, exposed panels)

🔧 Tools & frameworks

  • Amass
  • Subfinder
  • httpx
  • Nuclei
  • masscan
  • Nmap
  • Shodan CLI
  • SpiderFoot

📜 Attack Surface Intelligence Tradecraft

  1. Seed collection from authoritative identifiers (root domains, registered ASNs, CIDR allocations) and enumerate all subdomains and live hosts
  2. Normalize and deduplicate discovered assets, resolving them to IPs, ports, technologies, and certificate identities
  3. Score each exposure by service criticality, known CVE presence, and internet-facing sensitivity to rank attack paths
  4. Attribute unknown assets to the organization via certificate SANs, favicon hashes, WHOIS, and shared hosting before flagging shadow IT
  5. Publish a ranked exposure report with reproducible evidence (banners, screenshots, Nuclei findings) to asset owners
  6. Trigger remediation tickets or takedown/decommission workflows and re-scan to confirm the exposure is closed

📊 Dashboard KPIs

Exposed assetsCritical open portsShadow/unknown assetsMean time to detect exposureCert-expiry risk
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php