Skip to main content

Asset Discovery & External Attack Surface Mapping

Asset Discovery & External Attack Surface Mapping

A company's external attack surface is the collection of all publicly accessible digital assets that could potentially be exposed to cyber threats. Accurately identifying these assets is a critical foundation of Panorays' Cyber Posture Assessment.

Panorays' Asset Discovery capability automatically detects and maps this attack surface - starting from a single known asset and expanding outward - to provide a comprehensive, accurate view of a company's internet-facing presence. Over 97% of assets in Panorays are detected automatically, making manual asset addition the exception rather than the rule.


What Is an "Asset" in Panorays?

In Panorays, an asset is an internet-facing resource that can be evaluated for security risk.

Supported asset types:

Asset Type

Examples

Definition

Domain

panorays.com, panorays.co.uk

Fully qualified first-level domain

Subdomain

blog.panorays.com, level2.level1.panorays.com

Fully qualified subdomain (all levels)

IP

172.67.36.185

Individual IP address

IP Range

172.67.32.0/20

IP range registered to the company

Other elements (e.g., employees, credentials, cloud services, URLs) may be associated with a company but are not classified as assets for discovery purposes.


Where Discovery Begins: The Primary Domain

When a new company (such as a supplier) is added to Panorays, the user must define a primary domain - typically the company's main website (e.g., panorays.com). This primary domain acts as the starting point for all further asset discovery.

Discovery Methodology: How Panorays Finds Assets

Panorays uses multiple proprietary, non-intrusive discovery collectors to identify additional domains, subdomains, and IP addresses. Each newly discovered asset can then be used recursively to discover more assets, until the full attack surface is mapped.

Discovery techniques include:

  • Reverse IP - Identifying domains hosted on the same IP.

  • DNS records - Mining DNS data for related assets.

  • Public search engines (Google dorking) - Finding exposed assets.

  • TLS certificate mining - Identifying domains sharing certificates.

  • Web crawling - Discovering assets via hyperlinks.

  • Additional proprietary methods - Panorays intellectual property.

All discovery methods rely on public data sources or non-intrusive probes only.

Discovery on its own can surface a large number of candidate assets - but not all of them necessarily belong to the company being assessed. Before any candidate is attached, it has to pass through the affiliation process described next.


Asset Affiliation: Preventing False Positives

To ensure accuracy, every discovered candidate asset passes through Panorays' Affiliation Pipeline, which checks it against a set of signals before it's confirmed as belonging to the company.

Affiliation signals include:

  • WHOIS - Domain registrant details.

  • DNS - Shared IPs and infrastructure.

  • Redirects - HTTP redirection between domains.

  • Web relationships - Cross-linking between sites.

  • Additional proprietary affiliation checks.

These signals are what drive the domain discovery logic below - a candidate domain is only attached once it accumulates enough of them.


Domain Discovery Logic

Fixed domains - Domains that always remain attached:

  • The primary domain

  • Domains manually added by users or evaluators

  • Domains verified by Panorays' back office

Ignored domains - Domains explicitly marked as not belonging to the company, often following disputes. These domains will never be auto-attached again.

Auto discovery process:

Auto discovery starts from existing fixed domains and runs in three iterative cycles. A domain is added only if it has at least two strong affiliation signals and meets a predefined similarity threshold.

Built-in safeguards:

  • If more than 25% of discovered domains are new, discovery pauses for manual review.

  • Domain relationships are re-evaluated on every assessment.

  • Domains that no longer meet criteria are automatically removed.


Subdomain Discovery

For every confirmed domain, Panorays automatically discovers subdomains using TLS certificate analysis, reverse DNS lookups, and additional reconnaissance techniques. Once a parent domain is confirmed, all of its subdomains are automatically attributed - no affiliation model required.

Special cases:

  • Ambiguous ownership (e.g., looker.company.com) is handled via dispute.

  • Subdomains without active IPs are removed from the company.

  • Manually added subdomains are never auto-removed.

IP & IP Range Discovery

Some organizations register IP ranges for internal or external use. Panorays identifies and attributes IP ranges using public registration data.


Disputing Asset Affiliation

The full discovered attack surface is visible to both Panorays evaluators and assessed suppliers. If an asset is believed to be incorrectly attributed, users can submit a dispute directly from the platform. Simply hover over the lightning bolt icon on the right and select Place in Dispute. All disputes are reviewed by a Panorays Cyber Analyst, ensuring transparency and accuracy.

Did this answer your question?