Attack Surface Mapping: Complete External Reconnaissance Guide
Learn to map external attack surfaces using OSINT tools. Master subdomain discovery, service enumeration, and asset inventory for penetration testing and bug bounty hunting.
# Attack Surface Mapping: Complete External Reconnaissance Guide
Attack surface mapping is the process of identifying all externally accessible assets belonging to a target organization. It is the foundation of penetration testing, bug bounty hunting, and security auditing. A comprehensive attack surface map reveals subdomains, IP ranges, open services, web applications, and cloud infrastructure.
External Asset Discovery
An attack surface is the collection of every internet-facing asset an organization exposes. Intelligence gathering focuses on identifying these assets — web applications, email servers, cloud instances, DNS infrastructure, VPN endpoints, and code repositories — because each represents a potential entry point. The goal of attack surface intelligence is to discover assets the target may not know exist or has forgotten to secure.
Attack Surface Mapping Methodology
Phase 1: Domain Intelligence
Start with passive reconnaissance:
# WHOIS for domain ownership
whois example.com
# DNS enumeration
theHarvester -d example.com -b all
# Subdomain discovery
subfinder -d example.com -o subdomains.txt
Phase 2: Subdomain Discovery
Use multiple tools for comprehensive coverage:
# theHarvester for email and subdomain discovery
theHarvester -d example.com -b all -s
# Amass for deep subdomain enumeration
amass enum -passive -d example.com -o amass.txt
# Subfinder for fast passive subdomains
subfinder -d example.com -all -o subfinder.txt
# Combine and deduplicate
cat subdomains.txt | sort -u > combined.txt
Phase 3: Host Verification
Verify which subdomains are live:
# httpx for HTTP probing
httpx -l combined.txt -o live.txt
# Nmap for port scanning
nmap -iL live.txt -T4 -oX nmap_results.xml
Phase 4: Service Enumeration
Identify services on discovered hosts:
# Nmap service detection
nmap -sV -sC -p- target.com
# Nmap NSE scripts
nmap --script=http-enum,http-title,ssl-cert target.com
Phase 5: Risk Assessment
Evaluate discovered assets:
# URL Risk Analyzer for threat assessment
# Use IP Lookup for ASN and hosting information
# Use SSL Checker for certificate validity
Attack Surface Categories
| Category | Examples | Risk Level |
|----------|----------|------------|
| Web Applications | Websites, APIs, admin panels | High |
| Email Infrastructure | MX servers, SPF/DKIM | Medium |
| Cloud Services | S3 buckets, EC2 instances | High |
| VPN Endpoints | VPN gateways, RDP | Critical |
| Code Repositories | GitHub, GitLab | Medium |
| DNS Infrastructure | Name servers, subdomains | Low |
| Staging Environments | Dev, test, QA servers | High |
OSINT Tools for Attack Surface Mapping
| Tool | Purpose | Phase |
|------|---------|-------|
| [TheHarvester](/tools/theharvester) | Email and subdomain discovery | Reconnaissance |
| [Whois Lookup](/cybersecurity-tools/whois-lookup) | Domain ownership | Intelligence |
| [DNS Lookup](/cybersecurity-tools/dns-lookup) | DNS record analysis | Intelligence |
| [Amass](/tools/amass) | Deep subdomain enumeration | Discovery |
| [Subfinder](/tools/subfinder) | Fast passive subdomains | Discovery |
| [Nmap](/tools/nmap) | Port and service scanning | Enumeration |
| [Shodan CLI](/tools/shodan-cli) | Internet-wide service search | Discovery |
Related Tools
Frequently Asked Questions
What is attack surface mapping?
Attack surface mapping is the process of identifying all externally accessible assets belonging to a target organization, including subdomains, IP ranges, open services, and web applications.
Why is attack surface mapping important?
Attack surface mapping reveals the full scope of a target's external presence, identifying potential entry points for attackers and forgotten infrastructure that may contain vulnerabilities.
What tools are used for attack surface mapping?
Common tools include TheHarvester (email/subdomain discovery), Amass (deep subdomain enumeration), Subfinder (passive subdomains), Nmap (port scanning), and Shodan (service discovery).