Shadow IT, forgotten subdomains, open services, and public artefacts create risk before anyone “pentests”. If you do not know the surface, you prioritise blindly and pay twice later.
Analyse attack surface — outside-in, authorised, and actionable.
External attack surface is what attackers and scanners can see without insider access. SHELL-AFFECT analyses it as CASP: passive, only with domain authorisation, with a signed report and prioritisation — so you know what matters first.
- Outside-in picture
- Authorised domains only
- Prioritised map
Example (anonymised)
After a phishing incident leadership wants to “know the attack surface”. CASP Lite on the primary domain shows: old staging subdomain public, SMTP gaps, leaked employee emails in public sources. Priority 1: staging offline, SPF/DKIM, monitoring. No active exploit in CASP; pentest of the customer app recommended as phase 2. Figures and names are anonymised; the flow matches typical engagements.
Outside-in attack surface is a decision basis, not “we hacked everything”. We stay passive, authorised, and prioritising. That is intentional and part of the positioning.
This page’s job: Owns “what is visible outside-in?” (surface picture). Method/kickoff lives on outside-in assessment; DNS-TXT on verification.
Mini inventory: what counts as external attack surface
Not exhaustive — typical outside-in categories:
- 01
Domains & subdomains
Prod, staging, forgotten, takeovers.
- 02
Public services
Web, mail, VPN, admin panels reachable from outside.
- 03
Certificates & DNS
Misconfig, infrastructure hints exposed.
- 04
Leak/OSINT traces
Emails, repos, paste sites — in authorised scope.
- 05
Cloud buckets/objects
When public and attributable to scope.
- 06
Not CASP
Internal lateral movement, social engineering without engagement.
Invisible exposure is expensive
Companies with their own domains and digital presence who want to know what is already exposed outside-in before the next budget decision.
Not for you if…
- You lack domain authority and want third-party systems tested
- You only want a one-off port scan without report ownership
- You expect legal testing without approval
Attack surface analysis: how we differ — and what to watch.
“Attack surface” is a buzzword. Often it is only a port scan. We mean authorised outside-in profiling with prioritisation and a report — and we refuse unauthorised or theatrical scans.
How we differ on attack-surface work
Outside-in with authorisation
DNS-TXT before start — no grey “we will just look from outside”.
Prioritised map
What is visible and urgent — not every technical side note at equal volume.
Connectable next steps
Hardening, audit, or pentest optional and separate — no forced bundle.
High-ticket, honestly priced
Lite/Full publicly oriented — no dumping that makes quality impossible.
What to watch when an offer says “attack surface”
- No domain authorisation proof
- Only port scan/tool export sold as “attack surface assessment”
- Promises of complete risk coverage without scope
- No prioritisation and no leadership language
- Immediate pentest in the same sentence without method separation
- Guarantees of being “secure” or compliance-ready afterwards
Included vs. deliberately not (attack surface)
Typical CASP/outside-in boundaries:
- We do / include
Authorised outside-in analysis with signed report
- We do / include
Prioritisation and next steps
- We do / include
Declining unauthorised or third-party assets
- We do not / exclude
Active exploitation inside CASP
- We do not / exclude
Full internal network review without a separate audit scope
- We do not / exclude
Finding or certification guarantees
If you want a defensible outside-in map: scope meeting. If you want an anonymous cheap scan without ownership, we are not the fit.
What you decide, what is authorised, what is out of scope.
Method boundaries first — no mixed CASP/pentest theatre.
What you can decide
Visible exposure mapped and prioritised.
What is authorised
Authorisation, passive method, analyst, signed report.
How fast you get clarity
Lite/Full in defined day windows.
What comes from you
DNS-TXT and contacts — no deep network access for CASP.
Practical outcomes for you.
Decision basis
What is visible, urgent, or can wait?
Less blind flight
Hardening and test budget follow outside-in reality.
Documented
A report that is explainable inside and outside.
Core offer and clear options.
CASP attack surface profiling
Outside-in analysis of authorised domains.
Prioritised roadmap
Next steps instead of raw data.
Signed report
Clear deliverable boundary.
Audit / pentest
Separate scopes as needed.
Deliverables
- Outside-in exposure overview
- Prioritised findings/notes
- Signed report
- Recommended next steps
How we analyse attack surface
- 01
Scope & approval
Domains, goal, DNS-TXT.
- 02
Outside-in profiling
Passive visibility and context.
- 03
Prioritise
Risk and actionability.
- 04
Report & next steps
Handoff and optional follow-ons.
Objections, answered honestly.
What is external attack surface?
Everything visible and potentially attackable from outside without insider access — domains, services, artefacts.
Is this a pentest?
No. CASP is outside-in and passive. Active work only in separate approved engagements.
How long does it take?
Orientation: Lite 10–14 days, Full 14–21 days — depending on scope.
How do I start?
Contact with domains and goal. See Pricing.
Does social media count as attack surface?
Depends on scope and goal. CASP typically focuses technical outside-in exposure of authorised domains; extensions need explicit agreement.
How often should we re-measure?
After major changes or on intervals (e.g. re-investigation) when the product/contract includes it — not as a fake subscription pressure.
Make attack surface visible
Share primary domain and goal — we propose CASP Lite or Full.