Attack surface

Your exposed services, with their context.

Connect exposed applications, domains and external services to available information about your business. Examine the evidence before setting priorities.

Swipe across the visual to read the details.

Sorvek example: exposed Azure and Google services, .example domains and applications associated with fictional accounts.
About this visual

Approved composition of Sorvek views, with .example domains and fictional or anonymized data. Vendor names and logos identify services; they do not prove a partnership. An observed association alone does not confirm service ownership or data exposure.

Connect the observations. Keep their evidence.

A domain name or vendor on its own is not enough. The source and connection to your environment give meaning to the observation.

Exposed applications
Find accessible services associated with observed domains. A service visible on the Internet is not, by itself, a vulnerability.
Domains and external services
Browse domains, subdomains and associated vendors. A DNS observation, such as a CNAME, provides a clue to verify in context.
Company information
Connect discovered applications and accounts to available information. A discovered account does not prove that a recent sign-in was observed.

From an observed service to the right priority.

Start with items connected to your business and the data your team wants to protect.

  1. Confirm the connection

    Check the domain, source and observation date. Confirm who manages the service before assigning an owner.

  2. Examine the context

    Review available vendor information and associated access. An incident at a vendor does not demonstrate that your business is affected.

  3. Prepare an action

    Prioritize checks with your team, then prepare appropriate interventions and track their status.

Scope matters

An observed view, with its limits.

Coverage depends on the domains examined, sources, scans and their dates. It is not an exhaustive inventory of all assets or a complete test of their security.

A detected association or an absence of results still needs interpretation. Available evidence guides verification; it does not replace confirmation by the service owner.