Sample External Attack Surface Check

Northstar Industries

A fictional demonstration assessment, built to show exactly what a real engagement produces — not a features list.

Fictional demonstration data — Northstar Industries is not a real client. All assets, findings and figures below are illustrative.
Assessment overview

External attack surface

214
Assets identified
31
Assets requiring ownership review
17
Externally exposed services reviewed
9
Attack hypotheses tested
4
Validated security findings
1
Viable attack path demonstrated
Discovered asset overview · sample

Asset inventory (excerpt)

A small excerpt from the full asset inventory delivered as part of the report.

AssetTypeFirst observedExposureStatus
portal.northstar-example.comWeb ApplicationDiscovery phaseAuthentication SurfaceReviewed
api.northstar-example.comAPIDiscovery phasePublic APIFinding
legacy.northstar-example.comLegacy ApplicationDiscovery phaseUnexpected AssetInvestigate
vpn.northstar-example.comRemote AccessDiscovery phaseAuthentication SurfaceReviewed
stg-checkout.northstar-example.comStaging EnvironmentDiscovery phaseUnexpected AssetInvestigate
mail.northstar-example.comMail InfrastructureDiscovery phaseMail SurfaceReviewed
status.northstar-example.comThird-Party HostedDiscovery phaseInformation DisclosureReviewed

Full reports include the complete inventory, asset ownership notes, and technology fingerprints for every discovered asset.

Attack path AP-01 · fictional example

Legacy customer portal to business impact

Discovery
Legacy customer portal (legacy.northstar-example.com)
Not present in Northstar's known asset inventory. Discovered via certificate transparency logs and subdomain enumeration.
Exposure
Outdated internet-facing component
Technology fingerprinting identified a component version with known, publicly documented weaknesses.
Weakness
Authentication control weakness
Manually validated by an offensive-security professional — not scanner output.
Access
Unauthorized application access
Access obtained to an authenticated area of the legacy portal, within agreed scope and Rules of Engagement.
Impact
Potential access to sensitive business data
Validated — Fictional Example
Evidence

Authenticated screenshots, request/response captures, and a reproducible step-by-step chain, included in full in the technical appendix.

Affected asset

legacy.northstar-example.com — legacy customer portal, not in known inventory.

Impact

Potential unauthorized access to customer records held within the legacy portal.

Recommended action

Decommission or isolate the legacy portal; if retained, patch the outdated component and remediate the authentication weakness.

A clean result matters too

Attack hypothesis AH-04

Not every tested scenario produces a finding — and that is itself useful evidence.

Can the externally exposed remote-access infrastructure provide a viable initial-access path?

Not validated during the assessment
Evidence
  • Expected authentication controls present
  • No material externally exploitable weakness identified within scope
  • Relevant exposed services reviewed
  • No viable attack path demonstrated
Interpretation

An assessment does not need a critical finding to provide value. Knowing which attack scenarios were tested and resisted provides evidence about your external security posture.

The full report

What's included beyond this excerpt

  • Executive Summary for leadership
  • Complete external attack surface overview
  • Full discovered asset inventory
  • All attack hypotheses tested, validated or not
  • Evidence for every validated finding
  • Prioritized remediation recommendations
  • Positive security observations
  • Assessment limitations, stated honestly
  • Technical appendix
  • Live debrief / results call
Get started

What does your organization look like from the outside?

Request an External Attack Surface Check and find out what an attacker can see before they do.