ACME Bank — External perimeterENG · ACME-EXT-04
Authorized
SR
Always on
Continuously checking · iterating · chaining — last pass 2s ago
1,247Assets watched
3,204Checks today
128Chains explored
6Exploits validated
41,980Iterations total
1,247 assets mapped ACME-EXT-04 · external perimeter · re-mapped continuously

It isn't 40 assets. It's everything you forgot you had.

Fourteen years of DNS records, staging sites, acquisitions and abandoned projects. 38 of them have no owner. That sprawl is where an autonomous attacker starts, because nobody is watching it — so Red maps all of it, continuously, and shows you what is actually reachable.

1,247DNS recordssince 2011
341Live subdomains
9Dangling DNStakeover-prone
23End-of-life
Operator is re-mapping — certificate-transparency sweep running

Attack surface intelligence

accumulated over ~14 years · continuously re-mapped
1,247DNS records
341Subdomains
58Live services
23EOL / legacy
9Dangling DNS
6Shadow IT
9 subdomain-takeover-prone 23 end-of-life software 11 exposed non-prod 17 expired TLS 3 public storage
vpn-old.acme.safirst seen 2018 · owner unknownCitrix NetScaler · EOL firmwareExploitable CVE
legacy-blog.acme.safirst seen 2014 · marketing (former)WordPress 4.2.1 · 14 plugin CVEsEnd-of-life
promo-bf.acme.saCNAME → deleted S3 bucketDangling CNAMETakeover-prone
jenkins-ci.acme.sainternal-ish · internet-reachableJenkins · Log4j presentRCE · in chain
autodiscover.acme.safirst seen 2013Exchange 2013 · unpatchedProxyShell
staging-payments.acme.sanon-prod · exposedStaging env · debug onInternet-reachable
wiki-2019.acme.safirst seen 2019Confluence · unpatchedOGNL RCE
ftp.acme.safirst seen 2014Plaintext FTPCleartext creds
app-ios-beta.acme.saCNAME → dead Heroku appDangling CNAMETakeover-prone
careers-2019.acme.saorphaned micrositeUnmanaged · no ownerShadow IT
s3-acme-backupspublic ACLObject storage · readablePublic exports
intranet-old.acme.safirst seen 2015Forgotten intranet · expired TLSExpired cert

How these were discovered

passive first · nothing intrusive
Certificate-transparency logsEvery TLS certificate ever issued for the domain is public. Subdomains that were never meant to be found are found here first.341 subdomains recovered
Passive DNS historyRecords that still resolve, and records that point at infrastructure you no longer own — the takeover surface.9 dangling records flagged
Service fingerprintingBanner and behaviour analysis on what answers, matched against version and end-of-life data.23 end-of-life systems
Cloud tenant enumerationStorage, functions and endpoints spun up outside the change process and never decommissioned.6 shadow-IT assets
All discovery above is passive and read-only. Nothing here touched a system. Intrusive validation happens only behind an approval gate.