🔍 Attack Surface Intelligence (ASMINT)
Your Own Exposed Attack Surface
Cyber & Threat
Sources
3
2 no-auth
Mission domains
2
reach
Data points
4
covered
Related INT
2
disciplines
🔌 Sources for Attack Surface Intelligence (3)
| Source | Category | Auth | Format | |
|---|---|---|---|---|
| FireHOL IP Blocklists Aggregated abusive-IP blocklists. | Operational Security | NONE | text | home↗ api↗ |
| Gitleaks Rules (secret exposure) Detect exposed secrets/keys patterns. | Operational Security | NONE | text | home↗ api↗ |
| Shodan ICS/SCADA Exposed ICS/SCADA device discovery. | Critical Infrastructure | KEY | json | home↗ api↗ |
🎯 Mission Domains served
🎫 Data Points
🔍 Lookup
📊 Pre-built Queries · Attack Surface Intelligence
🔄 Live Datasets & APIs (2 key-free · ingestible)
📜 Playbook — Attack Surface Intelligence collection
- Direction — frame the requirement for Attack Surface Intelligence: what decision does this support, by when?
- Collection — collect from the 3 mapped sources (2 free) — filter the catalog by ASMINT; capture provenance and observe OPSEC.
- Processing — normalize, de-duplicate and enrich the collected data.
- Analysis — correlate against local holdings; apply ACH; assign confidence.
- Dissemination — open a case, draft a report, share via STIX/MISP.
- Feedback — set an alert rule / watchlist to monitor for change.
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🧩 Advanced Capabilities
🔗 Pivot to related disciplines
✨ Enrichment pathways
🎯 Mission
Attack Surface Intelligence discovers and continuously inventories an organization's externally reachable assets, services, ports, and misconfigurations as an adversary would see them. It answers what is exposed to the internet, which internet-facing systems are exploitable, and where undocumented shadow IT and forgotten cloud assets are leaking.
📡 Collection methods
- Internet-wide port and service scanning with banner grabbing across the target's IP and ASN space
- Subdomain enumeration via passive DNS, CT logs, and DNS brute-forcing
- Cloud and SaaS asset discovery (S3/GCS/Azure buckets, exposed APIs, dev/staging hosts)
- Favicon-hash and HTML-title fingerprinting to cluster related web properties
- TLS certificate correlation to tie hosts to organizational identity
- Template-based vulnerability probing of discovered services (default creds, known CVEs, exposed panels)
📚 Key sources & datasets
🎫 Data points produced
🔧 Tools & frameworks
- Amass
- Subfinder
- httpx
- Nuclei
- masscan
- Nmap
- Shodan CLI
- SpiderFoot
📜 Attack Surface Intelligence Tradecraft
- Seed collection from authoritative identifiers (root domains, registered ASNs, CIDR allocations) and enumerate all subdomains and live hosts
- Normalize and deduplicate discovered assets, resolving them to IPs, ports, technologies, and certificate identities
- Score each exposure by service criticality, known CVE presence, and internet-facing sensitivity to rank attack paths
- Attribute unknown assets to the organization via certificate SANs, favicon hashes, WHOIS, and shared hosting before flagging shadow IT
- Publish a ranked exposure report with reproducible evidence (banners, screenshots, Nuclei findings) to asset owners
- Trigger remediation tickets or takedown/decommission workflows and re-scan to confirm the exposure is closed
📊 Dashboard KPIs
Exposed assetsCritical open portsShadow/unknown assetsMean time to detect exposureCert-expiry risk
🔍 Pre-built queries
🔗 Cross-discipline pivots
🧩 Advanced Capabilities
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron