Insights

5 Types of Unknown Assets That Expand Your Attack Surface

When we run discovery on a new engagement, the assets that end up mattering most are rarely the ones already in the client’s inventory. They’re the ones nobody remembers: still reachable, still running, and completely outside anyone’s current attention. Here are five categories that come up repeatedly, and why each one is worth specifically checking for.

1. Abandoned staging and development environments

Staging environments are usually built with less security rigor than production: default credentials, verbose error messages, outdated dependencies, sometimes a full copy of production data for realistic testing. They’re meant to be temporary. In practice, a huge number of them outlive the project they were built for, quietly reachable at a predictable subdomain like stg- or dev-, long after everyone involved has moved on. An attacker who finds one gets a lower-friction path into the same systems production would otherwise protect more carefully.

2. Subsidiary and acquisition infrastructure

After a merger or acquisition, IT integration is rarely instantaneous, and security ownership is often the last thing to get clarified. The acquired company’s domains, cloud accounts, and applications frequently keep running exactly as they were, under whatever security posture they had before the deal closed, for months or years. From an attacker’s perspective, your attack surface includes every subsidiary’s infrastructure, regardless of whose internal team is supposed to be responsible for it.

3. Marketing and campaign microsites

Product launches, conferences, and marketing campaigns often spin up their own short-lived websites, frequently built and hosted outside the usual engineering process: by an agency, on a personal cloud account, on a CMS nobody in IT selected. They’re built for speed, not longevity, and once the campaign ends, decommissioning is rarely anyone’s job. Years later, they’re still live, still branded with your company name, and running software that hasn’t been patched since launch.

4. Third-party-hosted assets carrying your brand

Status pages, help centers, community forums, and similar services are frequently hosted on a third-party platform but presented under a subdomain of your own domain (status.example.com, support.example.com). Because they’re “someone else’s infrastructure,” they’re often left out of internal asset inventories entirely, but they’re still part of your externally visible footprint, still capable of leaking information about your internal systems and vendor relationships, and still a plausible target for anyone researching your organization.

5. Forgotten remote-access and administrative interfaces

VPN concentrators, admin panels, and remote-access tools set up for a specific project, vendor, or temporary need have a habit of staying reachable long after the need has passed. These are disproportionately valuable to an attacker precisely because they’re designed to grant access. Because nobody is actively managing them, patches and credential rotations also tend to lapse first.

Why this keeps happening

None of this is really a technology failure. It’s an organizational one. Asset inventories are built and maintained by people, and people move roles, projects end, ownership changes hands, and documentation doesn’t always keep up. The result is a persistent gap between what a security team believes it’s responsible for and what’s actually reachable from the internet under the company’s name.

That gap is exactly what external discovery is built to close, not by asking your team what they think is exposed, but by independently reconstructing what actually is, using the same reconnaissance techniques an attacker would use. You can read more about how that discovery process works on our methodology page, or see a fictional example inventory, including exactly this kind of unexpected asset, on our sample assessment.

See what this looks like for your organization

An External Attack Surface Check applies exactly this kind of discovery, analysis, and human validation to your real environment, not a hypothetical one.

Get started

What does your organization look like from the outside?

Request an External Attack Surface Check and find out what an attacker can see before they do.