GO KALI FREE
IntermediateOSINT

Attack Surface Mapping: Complete External Reconnaissance Guide

Learn to map external attack surfaces using OSINT tools. Master subdomain discovery, service enumeration, and asset inventory for penetration testing and bug bounty hunting.

#attack surface#OSINT#reconnaissance#subdomain enumeration#penetration testing

# Attack Surface Mapping: Complete External Reconnaissance Guide

Attack surface mapping is the process of identifying all externally accessible assets belonging to a target organization. It is the foundation of penetration testing, bug bounty hunting, and security auditing. A comprehensive attack surface map reveals subdomains, IP ranges, open services, web applications, and cloud infrastructure.

External Asset Discovery

An attack surface is the collection of every internet-facing asset an organization exposes. Intelligence gathering focuses on identifying these assets — web applications, email servers, cloud instances, DNS infrastructure, VPN endpoints, and code repositories — because each represents a potential entry point. The goal of attack surface intelligence is to discover assets the target may not know exist or has forgotten to secure.

Attack Surface Mapping Methodology

Phase 1: Domain Intelligence

Start with passive reconnaissance:

# WHOIS for domain ownership
whois example.com

# DNS enumeration
theHarvester -d example.com -b all

# Subdomain discovery
subfinder -d example.com -o subdomains.txt

Phase 2: Subdomain Discovery

Use multiple tools for comprehensive coverage:

# theHarvester for email and subdomain discovery
theHarvester -d example.com -b all -s

# Amass for deep subdomain enumeration
amass enum -passive -d example.com -o amass.txt

# Subfinder for fast passive subdomains
subfinder -d example.com -all -o subfinder.txt

# Combine and deduplicate
cat subdomains.txt | sort -u > combined.txt

Phase 3: Host Verification

Verify which subdomains are live:

# httpx for HTTP probing
httpx -l combined.txt -o live.txt

# Nmap for port scanning
nmap -iL live.txt -T4 -oX nmap_results.xml

Phase 4: Service Enumeration

Identify services on discovered hosts:

# Nmap service detection
nmap -sV -sC -p- target.com

# Nmap NSE scripts
nmap --script=http-enum,http-title,ssl-cert target.com

Phase 5: Risk Assessment

Evaluate discovered assets:

# URL Risk Analyzer for threat assessment
# Use IP Lookup for ASN and hosting information
# Use SSL Checker for certificate validity

Attack Surface Categories

| Category | Examples | Risk Level |

|----------|----------|------------|

| Web Applications | Websites, APIs, admin panels | High |

| Email Infrastructure | MX servers, SPF/DKIM | Medium |

| Cloud Services | S3 buckets, EC2 instances | High |

| VPN Endpoints | VPN gateways, RDP | Critical |

| Code Repositories | GitHub, GitLab | Medium |

| DNS Infrastructure | Name servers, subdomains | Low |

| Staging Environments | Dev, test, QA servers | High |

OSINT Tools for Attack Surface Mapping

| Tool | Purpose | Phase |

|------|---------|-------|

| [TheHarvester](/tools/theharvester) | Email and subdomain discovery | Reconnaissance |

| [Whois Lookup](/cybersecurity-tools/whois-lookup) | Domain ownership | Intelligence |

| [DNS Lookup](/cybersecurity-tools/dns-lookup) | DNS record analysis | Intelligence |

| [Amass](/tools/amass) | Deep subdomain enumeration | Discovery |

| [Subfinder](/tools/subfinder) | Fast passive subdomains | Discovery |

| [Nmap](/tools/nmap) | Port and service scanning | Enumeration |

| [Shodan CLI](/tools/shodan-cli) | Internet-wide service search | Discovery |

Related Tools

  • [TheHarvester](/tools/theharvester) — Initial email and subdomain discovery
  • [Amass](/tools/amass) — Deep subdomain enumeration with 40+ sources
  • [Subfinder](/tools/subfinder) — Fast passive subdomain discovery
  • [Nmap](/tools/nmap) — Port scanning and service detection
  • [Whois Lookup](/cybersecurity-tools/whois-lookup) — Domain registration intelligence
  • [DNS Lookup](/cybersecurity-tools/dns-lookup) — DNS record verification
  • [IP Lookup](/cybersecurity-tools/ip-lookup) — IP and ASN investigation
  • Frequently Asked Questions

    What is attack surface mapping?

    Attack surface mapping is the process of identifying all externally accessible assets belonging to a target organization, including subdomains, IP ranges, open services, and web applications.

    Why is attack surface mapping important?

    Attack surface mapping reveals the full scope of a target's external presence, identifying potential entry points for attackers and forgotten infrastructure that may contain vulnerabilities.

    What tools are used for attack surface mapping?

    Common tools include TheHarvester (email/subdomain discovery), Amass (deep subdomain enumeration), Subfinder (passive subdomains), Nmap (port scanning), and Shodan (service discovery).

    Frequently Asked Questions

    What is attack surface mapping?

    Attack surface mapping identifies all externally accessible assets belonging to a target organization, including subdomains, IP ranges, open services, web applications, cloud infrastructure, and code repositories.

    Why is attack surface mapping important?

    It reveals the full scope of a target's external presence, identifying potential entry points, forgotten infrastructure, and assets that may contain vulnerabilities. A larger attack surface increases risk.

    What are the phases of attack surface mapping?

    Phases include: domain intelligence (WHOIS, DNS), subdomain discovery (theHarvester, Amass, Subfinder), host verification (httpx), service enumeration (Nmap), and risk assessment of discovered assets.

    What tools are used for attack surface mapping?

    TheHarvester (email/subdomain discovery), Amass (deep subdomain enumeration), Subfinder (fast passive subdomains), Nmap (port scanning), and Shodan (internet-wide service search).

    What is an attack surface?

    An attack surface includes every point where an unauthorized user can enter or extract data: web applications, email infrastructure, cloud services, DNS, VPN endpoints, code repositories, and staging environments.

    How do you verify which subdomains are live?

    Use httpx (`httpx -l subdomains.txt -o live.txt`) for HTTP probing, then Nmap (`nmap -iL live.txt -T4`) for port scanning. This filters non-responsive hosts from the subdomain list.

    What are high-risk attack surface categories?

    VPN endpoints (critical), web applications (high), cloud services (high), staging environments (high), code repositories (medium), email infrastructure (medium), and DNS infrastructure (low).

    How do you combine multiple OSINT tools?

    Run theHarvester, Amass, and Subfinder separately, then combine results with `cat *.txt | sort -u > combined.txt`. Deduplication ensures comprehensive coverage without redundant entries.