External attack surface scan — how the pipeline works

An external scan is not one action. It is a pipeline, and each stage narrows the next: you cannot fingerprint a service you have not resolved, and you cannot prioritise a finding on an asset you have not attributed.

What this page checks

  1. DNS resolution — establishing what the name points at, and therefore what is in scope.
  2. Subdomain enumeration — the step that finds the assets nobody has an inventory entry for. This is where the estate turns out to be larger than the team believed.
  3. TLS and certificate analysis — expiry, chain and configuration on every host found, not just the primary one.
  4. Service fingerprinting and vulnerability checks — identifying what is running and which known issues apply to that specific deployment.
  5. Takeover detection — records still pointing at deprovisioned infrastructure, which are claimable by anyone.
  6. Analysis and prioritisation — turning the raw output into the handful of things that are genuinely reachable.

How it runs

This page is an interactive demonstration of the check rather than a live assessment of your estate — it shows the shape of the finding and how it is presented. For a real, continuous answer across every asset you own, the same check runs inside Maphra.

Where this sits in Maphra

Maphra is an autonomous External Attack Surface Management platform. It starts from nothing more than a domain name and works outward the way an attacker would: enumerating subdomains, resolving infrastructure, fingerprinting live services, and attributing each discovered asset back to the organisation that owns it. Discovered surface is then classified, analysed and prioritised, so a security team sees the handful of exposures that are genuinely reachable rather than an undifferentiated asset inventory. Maphra also watches the parts of the attack surface that sit outside the perimeter entirely — leaked credentials in breach corpora, look-alike domains, impersonating applications and brand abuse — because those are attack paths that no internal scanner can see. It runs continuously rather than as a quarterly exercise, and every finding carries the evidence that produced it.

Questions

How is this different from running a vulnerability scanner?
A scanner tests a list of assets you give it. Maphra finds the assets first — including the ones nobody remembered — attributes them to your organisation, then analyses them. The discovery step is the product.
Does scanning touch systems we do not own?
Active validation runs only inside an explicit scope boundary you define, and the scope gate prevents active checks from reaching third-party hosts that merely appear in your surface.

A one-off check tells you about one asset today. Maphra runs this continuously across everything it discovers, and a walkthrough uses your own domain rather than a sample.