Analyse attack surface — outside-in, authorised, and actionable.

External attack surface is what attackers and scanners can see without insider access. SHELL-AFFECT analyses it as CASP: passive, only with domain authorisation, with a signed report and prioritisation — so you know what matters first.

  • Outside-in picture
  • Authorised domains only
  • Prioritised map
Concrete example

Example (anonymised)

After a phishing incident leadership wants to “know the attack surface”. CASP Lite on the primary domain shows: old staging subdomain public, SMTP gaps, leaked employee emails in public sources. Priority 1: staging offline, SPF/DKIM, monitoring. No active exploit in CASP; pentest of the customer app recommended as phase 2. Figures and names are anonymised; the flow matches typical engagements.

Outside-in attack surface is a decision basis, not “we hacked everything”. We stay passive, authorised, and prioritising. That is intentional and part of the positioning.

This page’s job: Owns “what is visible outside-in?” (surface picture). Method/kickoff lives on outside-in assessment; DNS-TXT on verification.

Checklist

Mini inventory: what counts as external attack surface

Not exhaustive — typical outside-in categories:

  1. 01

    Domains & subdomains

    Prod, staging, forgotten, takeovers.

  2. 02

    Public services

    Web, mail, VPN, admin panels reachable from outside.

  3. 03

    Certificates & DNS

    Misconfig, infrastructure hints exposed.

  4. 04

    Leak/OSINT traces

    Emails, repos, paste sites — in authorised scope.

  5. 05

    Cloud buckets/objects

    When public and attributable to scope.

  6. 06

    Not CASP

    Internal lateral movement, social engineering without engagement.

Problem & fit

Invisible exposure is expensive

Cost of the status quo

Shadow IT, forgotten subdomains, open services, and public artefacts create risk before anyone “pentests”. If you do not know the surface, you prioritise blindly and pay twice later.

What “done” looks likeA clear outside-in picture of your visible attack surface with prioritised actions and an optional path to audit or pentest.
Who this analysis is for

Companies with their own domains and digital presence who want to know what is already exposed outside-in before the next budget decision.

Not for you if…

  • You lack domain authority and want third-party systems tested
  • You only want a one-off port scan without report ownership
  • You expect legal testing without approval
Differentiation & buying guide

Attack surface analysis: how we differ — and what to watch.

“Attack surface” is a buzzword. Often it is only a port scan. We mean authorised outside-in profiling with prioritisation and a report — and we refuse unauthorised or theatrical scans.

How we differ on attack-surface work

Outside-in with authorisation

DNS-TXT before start — no grey “we will just look from outside”.

Prioritised map

What is visible and urgent — not every technical side note at equal volume.

Connectable next steps

Hardening, audit, or pentest optional and separate — no forced bundle.

High-ticket, honestly priced

Lite/Full publicly oriented — no dumping that makes quality impossible.

What to watch when an offer says “attack surface”

  • No domain authorisation proof
  • Only port scan/tool export sold as “attack surface assessment”
  • Promises of complete risk coverage without scope
  • No prioritisation and no leadership language
  • Immediate pentest in the same sentence without method separation
  • Guarantees of being “secure” or compliance-ready afterwards

Included vs. deliberately not (attack surface)

Typical CASP/outside-in boundaries:

  • We do / include

    Authorised outside-in analysis with signed report

  • We do / include

    Prioritisation and next steps

  • We do / include

    Declining unauthorised or third-party assets

  • We do not / exclude

    Active exploitation inside CASP

  • We do not / exclude

    Full internal network review without a separate audit scope

  • We do not / exclude

    Finding or certification guarantees

If you want a defensible outside-in map: scope meeting. If you want an anonymous cheap scan without ownership, we are not the fit.

How delivery works

What you decide, what is authorised, what is out of scope.

Method boundaries first — no mixed CASP/pentest theatre.

/ 01

What you can decide

Visible exposure mapped and prioritised.

/ 02

What is authorised

Authorisation, passive method, analyst, signed report.

/ 03

How fast you get clarity

Lite/Full in defined day windows.

/ 04

What comes from you

DNS-TXT and contacts — no deep network access for CASP.

What changes

Practical outcomes for you.

01

Decision basis

What is visible, urgent, or can wait?

02

Less blind flight

Hardening and test budget follow outside-in reality.

03

Documented

A report that is explainable inside and outside.

In the package

Core offer and clear options.

01
Core

CASP attack surface profiling

Outside-in analysis of authorised domains.

02
Bonus

Prioritised roadmap

Next steps instead of raw data.

03
Bonus

Signed report

Clear deliverable boundary.

04
Optional

Audit / pentest

Separate scopes as needed.

Deliverables

  • Outside-in exposure overview
  • Prioritised findings/notes
  • Signed report
  • Recommended next steps
Steps

How we analyse attack surface

  1. 01

    Scope & approval

    Domains, goal, DNS-TXT.

  2. 02

    Outside-in profiling

    Passive visibility and context.

  3. 03

    Prioritise

    Risk and actionability.

  4. 04

    Report & next steps

    Handoff and optional follow-ons.

FAQ

Objections, answered honestly.

What is external attack surface?

Everything visible and potentially attackable from outside without insider access — domains, services, artefacts.

Is this a pentest?

No. CASP is outside-in and passive. Active work only in separate approved engagements.

How long does it take?

Orientation: Lite 10–14 days, Full 14–21 days — depending on scope.

How do I start?

Contact with domains and goal. See Pricing.

Does social media count as attack surface?

Depends on scope and goal. CASP typically focuses technical outside-in exposure of authorised domains; extensions need explicit agreement.

How often should we re-measure?

After major changes or on intervals (e.g. re-investigation) when the product/contract includes it — not as a fake subscription pressure.

Next step

Make attack surface visible

Share primary domain and goal — we propose CASP Lite or Full.

Scope before active workNext step
Request a scope meeting