OpenEASD External Attack Surface Scan Report

This is the OpenEASD report in the format we deliver. The company (Acme SaaS) and the domain (scan.acmesaas.io) are fictional, and every address shown comes from the ranges reserved for documentation. The structure is the real thing: the cover, the document control block, the Fix These First block, the finding IDs, the CVSS and CWE fields, the affected-endpoint lists, and the remediation wording are what the scanner produces. Run OpenEASD on your own domain and you get this document built from your own attack surface.

6 attack vectors, 27 tools, one report. This is a free attack surface scan: detection-only and open source. All we need is a domain. No signup, no credit card.

Read the full sample below, then scan your own domain to see what it finds on your infrastructure.

OpenEASD · External Attack Surface Detection and Vulnerability Analysis

External Attack Surface Detection Report

scan.acmesaas.io · Sample report built on fictional data.

Scan DateMay 22, 2026
GeneratedMay 22, 2026 · 13:05 UTC
Targetscan.acmesaas.io
Scan TypeFull Scan
Scan ID7f2a91c4-3d0b-4e58-9a17-c6b2f4e81d35
1
CRITICAL
5
HIGH
8
MEDIUM
6
LOW
1
INFO

Confidential, For Authorized Use Only. This document contains confidential information produced by an automated external attack surface scan. Findings reflect externally observable configuration at the time of scanning and should be validated before remediation.

Document Control

TitleExternal Attack Surface Detection Report (OpenEASD)
Targetscan.acmesaas.io and associated internet-facing hosts (no authenticated or internal access)
Assessment TypeAutomated external attack surface detection and vulnerability analysis
Scan Window2026-05-22 09:14:07 UTC to 2026-05-22 12:41:53 UTC (3h 27m 46s)
Scan StatusCompleted
Report DateMay 22, 2026
ClassificationConfidential, Authorized Use Only
Scan ID7f2a91c4-3d0b-4e58-9a17-c6b2f4e81d35

Note on counts: this report consolidates 74 raw scanner detections into 21 unique issues by grouping identical issues repeated across hosts, ports, or CVEs. Headline counts and the risk rating reflect unique issues; every affected endpoint is preserved under each finding.

1. Executive Summary

An automated external attack surface detection scan (OpenEASD) was run against scan.acmesaas.io and the hosts discovered under it. Testing was non-intrusive and performed from the public internet with no authenticated or internal access. The scan surfaced 21 unique findings (1 Critical, 5 High, 8 Medium, 6 Low, 1 Informational) consolidated from 74 raw detections.

Overall Risk Rating
CRITICAL

Most urgent: Unencrypted HTTPS, Data to this service crosses the internet in plaintext, so anyone on the network path can read it.

This is a point-in-time snapshot of the externally observable attack surface, taken from the public internet. It does not include authenticated, internal, or manual testing, and an attack surface changes over time. Treat it as a baseline, not a certificate.

Scan Coverage, Edge Blocking Observed

31 of 412 probed endpoints returned WAF/edge block responses (fingerprint suggests Cloudflare). Findings below reflect reachable endpoints. Absence of findings on blocked surfaces is not evidence of absence. For full coverage, allowlist the scanner (OpenEASD/1.0, source IP on file) in your WAF and re-run.

Priority Actions, Fix These First

The highest-impact issues, ranked. Actively-exploited (CISA KEV) and internet-facing critical issues come first. The full list is in Section 3.

#IssueWhy it mattersSeverity
1 Unencrypted HTTPS
TLS / HTTPS · 4 hosts
Data to this service crosses the internet in plaintext, so anyone on the network path can read it. CRITICAL 9.1
2 Missing Content-Security-Policy
Web · 12 hosts
A single injected script would run in your users' browsers (cross-site scripting). HIGH 7.5
3 Subdomain takeover possible: old-marketing.scan.acmesaas.io (aws-s3)
Attack Surface · 1 host
An attacker can claim this dangling subdomain and serve content under your name: phishing, malware, or session-cookie theft. HIGH 7.5
4 Subdomain takeover possible: promo-2024.scan.acmesaas.io (unknown)
Attack Surface · 1 host
An attacker can claim this dangling subdomain and serve content under your name: phishing, malware, or session-cookie theft. HIGH 7.5
5 Subdomain takeover possible: status-old.scan.acmesaas.io (unknown)
Attack Surface · 1 host
An attacker can claim this dangling subdomain and serve content under your name: phishing, malware, or session-cookie theft. HIGH 7.5

Severity Distribution

21
Total Findings
1
CRITICAL
5
HIGH
8
MEDIUM
6
LOW
1
INFO

Asset Discovery

47
Subdomains
19
IP Addresses
23
Open Ports
1,284
Web URLs

Technology Stack

Technologies fingerprinted on reachable web assets (10 distinct). Informational only, no version, end-of-life, or vulnerability inference is implied.

Amazon S3CloudflareExpressHSTSNginxNode.jsReactSentryStripeWebpack

2. Scope and Methodology

OpenEASD is an automated, external (black-box) attack surface scan. From a single domain it runs a fixed pipeline of 6 vectors backed by 27 tools: subdomain and asset discovery, then per-service checks for known vulnerabilities, TLS/SSL, SSH, web hygiene, and email and DNS posture. This was an active scan, run with the domain owner's authorisation on file. Testing was non-intrusive and performed from the public internet with no authenticated, internal, or application-layer access, and every probe carried an OpenEASD/1.0 user agent.

Scan Pipeline: 6 Vectors, 27 Tools

Attack VectorToolingResult
Domain IntelligenceDomain Security (DNS, DNSSEC chain of trust, SPF/DKIM/DMARC/MTA-STS/TLS-RPT/BIMI, open mail relay, RDAP), Infostealer Exposure (Hudson Rock Cavalier API), GitHub Secret Exposure (gitleaks), Lookalike Domain Detection (public DNS), Breach Exposure (XposedOrNot / HIBP)8 findings
Surface EnumerationSubfinder, Amass, Alterx (Subdomain Permutation), ASN Discovery (ASN and IP ranges), GitHub Org Recon (public repos), DNSx (Resolve), Subdomain Takeover Check (subzy), Cloud Asset Enumeration (cloud_enum)4 findings
Port DiscoveryNaabu (Port Scan), Service Detection (nmap -sV), Shodan Exposure (passive)0 findings
Network ExposureNmap (NSE Vuln Scan), TLS Checker, SSH Checker, Nuclei (Network Scan)1 finding
Web ExposureHTTPx (Web Probe, Technology Fingerprinting), Historical URLs (gau: Wayback, Common Crawl, OTX, URLScan), Katana, Nuclei (Web Vuln Scan), Web Checker, JS Secrets (gitleaks)8 findings
PrioritizationCVE Intel (EPSS + CISA KEV)Discovery

Every finding is traceable to a specific tool, check type, and target in Detailed Findings. Automated version-to-CVE matching can over-report where a vendor backports fixes without changing the version banner; such matches should be validated against the actual package build.

3. Findings Summary

All findings are Open pending remediation. Counts are unique issues after consolidation. "Hosts" is the number of distinct endpoints affected by each finding.

IDTitleScopeSeverityCVSSHostsStatus
OE-2026-001 Unencrypted HTTPS TLS / HTTPS CRITICAL 9.1 4 OPEN
OE-2026-002 Missing Content-Security-Policy Web HIGH 7.5 12 OPEN
OE-2026-003 Subdomain takeover possible: old-marketing.scan.acmesaas.io (aws-s3) Attack Surface HIGH 7.5 1 OPEN
OE-2026-004 Subdomain takeover possible: promo-2024.scan.acmesaas.io (unknown) Attack Surface HIGH 7.5 1 OPEN
OE-2026-005 Subdomain takeover possible: status-old.scan.acmesaas.io (unknown) Attack Surface HIGH 7.5 1 OPEN
OE-2026-006 Subdomain takeover possible: cdn-staging.scan.acmesaas.io (unknown) Attack Surface HIGH 7.5 1 OPEN
OE-2026-007 Missing X-Frame-Options Web MEDIUM 5.3 14 OPEN
OE-2026-008 Missing X-Content-Type-Options Web MEDIUM 5.3 11 OPEN
OE-2026-009 CORS wildcard Access-Control-Allow-Origin Web MEDIUM 5.3 3 OPEN
OE-2026-010 Missing Strict-Transport-Security Web MEDIUM 5.3 6 OPEN
OE-2026-011 DKIM record not found Email / DNS MEDIUM 5.3 1 OPEN
OE-2026-012 SPF policy is soft fail (~all) Email / DNS MEDIUM 5.3 1 OPEN
OE-2026-013 MTA-STS not configured Email / DNS MEDIUM 5.3 1 OPEN
OE-2026-014 Domain delete lock not enabled Domain MEDIUM 5.3 1 OPEN
OE-2026-015 Missing Permissions-Policy Web LOW 3.1 15 OPEN
OE-2026-016 Missing Referrer-Policy Web LOW 3.1 12 OPEN
OE-2026-017 Weak Strict-Transport-Security Web LOW 3.1 2 OPEN
OE-2026-018 DMARC policy is quarantine (not reject) Email / DNS LOW 3.1 1 OPEN
OE-2026-019 Domain update lock not enabled Domain LOW 3.1 1 OPEN
OE-2026-020 TLS-RPT not configured Email / DNS LOW 3.1 1 OPEN
OE-2026-021 BIMI not configured Email / DNS INFO n/a 1 OPEN

4. Detailed Findings

Each finding is documented with description, evidence, and remediation. Affected Endpoints list every host or port on which the issue was detected. Critical and high findings also carry a plain-language Business Impact line.

Not shown in this sample: the fictional scan behind this page returned no CVE findings, so no finding below carries the two rows that only appear on them. A CVE finding adds a CVEs row listing every matched identifier, and an Exploitation row that flags the finding when CISA lists a matched CVE as actively exploited in the wild (KEV) and states its EPSS exploit-probability percentile. Those two signals also drive the ranking in Priority Actions above: an actively-exploited issue outranks a higher-CVSS one that nobody is exploiting.

CRITICAL · 1 Finding
OE-2026-001 · TLS / HTTPS · TLS_CHECKER

Unencrypted HTTPS

OPEN
SeverityCRITICAL
CVSS v3.19.1
CategoryCWE-319: Cleartext Transmission of Sensitive Information
Source / Checktls_checker · unencrypted_service
Affected Endpoints
192.0.2.24:8443192.0.2.24:443198.51.100.61:8443198.51.100.61:443
Business Impact

Data to this service crosses the internet in plaintext, so anyone on the network path can read it.

Description

HTTPS on 192.0.2.24:8443 is accepting connections without TLS. Sensitive data exchanged over this service is exposed to interception and man-in-the-middle attacks.

Evidence
tls_checker reported unencrypted_service on 4 endpoints (first observed 2026-05-22 10:06).
Remediation

Disable the plaintext listener and configure TLS. Consult your service documentation for TLS/SSL configuration.

HIGH · 5 Findings
OE-2026-002 · WEB · WEB_CHECKER

Missing Content-Security-Policy

OPEN
SeverityHIGH
CVSS v3.17.5
CategoryCWE-1021: Improper Restriction of Rendered UI Layers
Source / Checkweb_checker · missing_csp
Affected Endpoints
https://app.scan.acmesaas.io/https://app.scan.acmesaas.io:443https://app.scan.acmesaas.io:8443http://app.scan.acmesaas.io:80http://app.scan.acmesaas.io:8080https://api.scan.acmesaas.io/https://api.scan.acmesaas.io:443http://api.scan.acmesaas.io:80https://docs.scan.acmesaas.io/https://staging.scan.acmesaas.io/http://staging.scan.acmesaas.io:8080https://scan.acmesaas.io/
Business Impact

A single injected script would run in your users' browsers (cross-site scripting).

Description

Without CSP, the browser has no restrictions on inline scripts, eval(), or resource origins, so an XSS flaw can execute arbitrary JavaScript.

Evidence
web_checker reported missing_csp on 12 endpoints (first observed 2026-05-22 12:18).
Remediation

Add a Content-Security-Policy header. Start with a report-only policy: Content-Security-Policy-Report-Only: default-src 'self'; script-src 'self'; report-uri /csp-report. Then tighten and enforce once violations are reviewed.

OE-2026-003 · ATTACK SURFACE · TAKEOVER_CHECK

Subdomain takeover possible: old-marketing.scan.acmesaas.io (aws-s3)

OPEN
SeverityHIGH
CVSS v3.17.5
CategoryNot mapped
Source / Checktakeover_check · subdomain_takeover
Affected Endpoints
old-marketing.scan.acmesaas.io
Business Impact

An attacker can claim this dangling subdomain and serve content under your name: phishing, malware, or session-cookie theft.

Description

old-marketing.scan.acmesaas.io appears to point at an unclaimed aws-s3 resource. An attacker who registers that resource on the hosting service could serve arbitrary content under your subdomain: credential phishing, malware delivery, or SSO-cookie theft from the same eTLD context.

Evidence
takeover_check reported subdomain_takeover on 1 endpoint (first observed 2026-05-22 09:52).
Remediation

Either remove the dangling DNS record or reclaim the unused resource on aws-s3. Verify by manually visiting the subdomain. A stale CNAME with an unclaimed third-party target is the signature pattern.

OE-2026-004 · ATTACK SURFACE · TAKEOVER_CHECK

Subdomain takeover possible: promo-2024.scan.acmesaas.io (unknown)

OPEN
SeverityHIGH
CVSS v3.17.5
CategoryNot mapped
Source / Checktakeover_check · subdomain_takeover
Affected Endpoints
promo-2024.scan.acmesaas.io
Business Impact

An attacker can claim this dangling subdomain and serve content under your name: phishing, malware, or session-cookie theft.

Description

promo-2024.scan.acmesaas.io appears to point at an unclaimed unknown resource. An attacker who registers that resource on the hosting service could serve arbitrary content under your subdomain: credential phishing, malware delivery, or SSO-cookie theft from the same eTLD context.

Evidence
takeover_check reported subdomain_takeover on 1 endpoint (first observed 2026-05-22 09:52).
Remediation

Either remove the dangling DNS record or reclaim the unused resource on unknown. Verify by manually visiting the subdomain. A stale CNAME with an unclaimed third-party target is the signature pattern.

OE-2026-005 · ATTACK SURFACE · TAKEOVER_CHECK

Subdomain takeover possible: status-old.scan.acmesaas.io (unknown)

OPEN
SeverityHIGH
CVSS v3.17.5
CategoryNot mapped
Source / Checktakeover_check · subdomain_takeover
Affected Endpoints
status-old.scan.acmesaas.io
Business Impact

An attacker can claim this dangling subdomain and serve content under your name: phishing, malware, or session-cookie theft.

Description

status-old.scan.acmesaas.io appears to point at an unclaimed unknown resource. An attacker who registers that resource on the hosting service could serve arbitrary content under your subdomain: credential phishing, malware delivery, or SSO-cookie theft from the same eTLD context.

Evidence
takeover_check reported subdomain_takeover on 1 endpoint (first observed 2026-05-22 09:52).
Remediation

Either remove the dangling DNS record or reclaim the unused resource on unknown. Verify by manually visiting the subdomain. A stale CNAME with an unclaimed third-party target is the signature pattern.

OE-2026-006 · ATTACK SURFACE · TAKEOVER_CHECK

Subdomain takeover possible: cdn-staging.scan.acmesaas.io (unknown)

OPEN
SeverityHIGH
CVSS v3.17.5
CategoryNot mapped
Source / Checktakeover_check · subdomain_takeover
Affected Endpoints
cdn-staging.scan.acmesaas.io
Business Impact

An attacker can claim this dangling subdomain and serve content under your name: phishing, malware, or session-cookie theft.

Description

cdn-staging.scan.acmesaas.io appears to point at an unclaimed unknown resource. An attacker who registers that resource on the hosting service could serve arbitrary content under your subdomain: credential phishing, malware delivery, or SSO-cookie theft from the same eTLD context.

Evidence
takeover_check reported subdomain_takeover on 1 endpoint (first observed 2026-05-22 09:52).
Remediation

Either remove the dangling DNS record or reclaim the unused resource on unknown. Verify by manually visiting the subdomain. A stale CNAME with an unclaimed third-party target is the signature pattern.

MEDIUM · 8 Findings
OE-2026-007 · WEB · WEB_CHECKER

Missing X-Frame-Options

OPEN
SeverityMEDIUM
CVSS v3.15.3
CategoryCWE-1021: Improper Restriction of Rendered UI Layers
Source / Checkweb_checker · missing_xfo
Affected Endpoints
https://app.scan.acmesaas.io/https://app.scan.acmesaas.io:443https://app.scan.acmesaas.io:8443http://app.scan.acmesaas.io:80http://app.scan.acmesaas.io:8080https://api.scan.acmesaas.io/https://api.scan.acmesaas.io:443http://api.scan.acmesaas.io:80https://docs.scan.acmesaas.io/https://staging.scan.acmesaas.io/http://staging.scan.acmesaas.io:8080https://scan.acmesaas.io/http://scan.acmesaas.io/https://legacy.scan.acmesaas.io/
Description

Without X-Frame-Options, attackers can embed this page in an iframe on a malicious site and perform clickjacking attacks.

Evidence
web_checker reported missing_xfo on 14 endpoints (first observed 2026-05-22 12:18).
Remediation

Add: X-Frame-Options: DENY (or SAMEORIGIN if framing is needed). Also set the CSP frame-ancestors directive for modern browsers.

OE-2026-008 · WEB · WEB_CHECKER

Missing X-Content-Type-Options

OPEN
SeverityMEDIUM
CVSS v3.15.3
CategoryCWE-693: Protection Mechanism Failure
Source / Checkweb_checker · missing_xcto
Affected Endpoints
https://app.scan.acmesaas.io/https://app.scan.acmesaas.io:443https://app.scan.acmesaas.io:8443http://app.scan.acmesaas.io:80http://app.scan.acmesaas.io:8080https://api.scan.acmesaas.io/https://api.scan.acmesaas.io:443http://api.scan.acmesaas.io:80https://docs.scan.acmesaas.io/https://staging.scan.acmesaas.io/http://staging.scan.acmesaas.io:8080
Description

Without X-Content-Type-Options: nosniff, browsers may MIME-sniff responses and interpret non-executable content as scripts, enabling XSS.

Evidence
web_checker reported missing_xcto on 11 endpoints (first observed 2026-05-22 12:18).
Remediation

Add: X-Content-Type-Options: nosniff

OE-2026-009 · WEB · WEB_CHECKER

CORS wildcard Access-Control-Allow-Origin

OPEN
SeverityMEDIUM
CVSS v3.15.3
CategoryNot mapped
Source / Checkweb_checker · cors_wildcard
Affected Endpoints
https://api.scan.acmesaas.io/https://app.scan.acmesaas.io/https://scan.acmesaas.io/
Description

The server at https://api.scan.acmesaas.io/ sets Access-Control-Allow-Origin: *. Any website can make cross-origin requests. Credentials are not included, but this may expose non-public API data.

Evidence
web_checker reported cors_wildcard on 3 endpoints (first observed 2026-05-22 12:18).
Remediation

Restrict CORS to specific trusted origins. Use an allowlist instead of the wildcard (*) value.

OE-2026-010 · WEB · WEB_CHECKER

Missing Strict-Transport-Security

OPEN
SeverityMEDIUM
CVSS v3.15.3
CategoryCWE-319: Cleartext Transmission of Sensitive Information
Source / Checkweb_checker · missing_hsts
Affected Endpoints
https://app.scan.acmesaas.io/https://app.scan.acmesaas.io:443https://app.scan.acmesaas.io:8443https://api.scan.acmesaas.io/https://api.scan.acmesaas.io:443https://docs.scan.acmesaas.io/
Description

The HTTPS response from https://app.scan.acmesaas.io/ does not set Strict-Transport-Security. Browsers may allow future visits over HTTP, leaving users exposed to downgrade and SSL-stripping attacks.

Evidence
web_checker reported missing_hsts on 6 endpoints (first observed 2026-05-22 12:18).
Remediation

Add a Strict-Transport-Security header with a max-age of at least six months. Example: Strict-Transport-Security: max-age=31536000; includeSubDomains

OE-2026-011 · EMAIL / DNS · DOMAIN_SECURITY

DKIM record not found

OPEN
SeverityMEDIUM
CVSS v3.15.3
CategoryCWE-358: Improperly Implemented Security Check for Standard
Source / Checkdomain_security · email
Affected Endpoints
scan.acmesaas.io
Description

No DKIM record found for common selectors on scan.acmesaas.io.

Evidence
domain_security reported email on 1 endpoint (first observed 2026-05-22 09:14).
Remediation

Configure DKIM signing with your email provider and publish the public key as a TXT record.

OE-2026-012 · EMAIL / DNS · DOMAIN_SECURITY

SPF policy is soft fail (~all)

OPEN
SeverityMEDIUM
CVSS v3.15.3
CategoryCWE-358: Improperly Implemented Security Check for Standard
Source / Checkdomain_security · email
Affected Endpoints
scan.acmesaas.io
Description

SPF is set to ~all (soft fail). Spoofed emails may still be delivered.

Evidence
domain_security reported email on 1 endpoint (first observed 2026-05-22 09:14).
Remediation

Change ~all to -all for strict enforcement.

OE-2026-013 · EMAIL / DNS · DOMAIN_SECURITY

MTA-STS not configured

OPEN
SeverityMEDIUM
CVSS v3.15.3
CategoryCWE-358: Improperly Implemented Security Check for Standard
Source / Checkdomain_security · email
Affected Endpoints
scan.acmesaas.io
Description

scan.acmesaas.io has no MTA-STS policy. Inbound email delivery is not protected against TLS downgrade, so an in-path attacker can force plaintext delivery even when your mail server supports TLS.

Evidence
domain_security reported email on 1 endpoint (first observed 2026-05-22 09:14).
Remediation

Add a TXT record at _mta-sts.scan.acmesaas.io with v=STSv1 and an id value, then publish the policy at https://mta-sts.scan.acmesaas.io/.well-known/mta-sts.txt with version STSv1, mode enforce, your MX host, and max_age 86400.

OE-2026-014 · DOMAIN · DOMAIN_SECURITY

Domain delete lock not enabled

OPEN
SeverityMEDIUM
CVSS v3.15.3
CategoryNot mapped
Source / Checkdomain_security · rdap
Affected Endpoints
scan.acmesaas.io
Description

scan.acmesaas.io does not have a delete lock (clientDeleteProhibited). The domain could be accidentally or maliciously deleted, causing immediate service outage.

Evidence
domain_security reported rdap on 1 endpoint (first observed 2026-05-22 09:14).
Remediation

Enable the 'clientDeleteProhibited' lock at your domain registrar.

LOW · 6 Findings
OE-2026-015 · WEB · WEB_CHECKER

Missing Permissions-Policy

OPEN
SeverityLOW
CVSS v3.13.1
CategoryNot mapped
Source / Checkweb_checker · missing_permissions_policy
Affected Endpoints
https://app.scan.acmesaas.io/https://app.scan.acmesaas.io:443https://app.scan.acmesaas.io:8443http://app.scan.acmesaas.io:80http://app.scan.acmesaas.io:8080https://api.scan.acmesaas.io/https://api.scan.acmesaas.io:443http://api.scan.acmesaas.io:80https://docs.scan.acmesaas.io/https://staging.scan.acmesaas.io/http://staging.scan.acmesaas.io:8080https://scan.acmesaas.io/http://scan.acmesaas.io/https://legacy.scan.acmesaas.io/https://status.scan.acmesaas.io/
Description

Without Permissions-Policy (formerly Feature-Policy), the page can access sensitive browser APIs (camera, microphone, geolocation) by default.

Evidence
web_checker reported missing_permissions_policy on 15 endpoints (first observed 2026-05-22 12:18).
Remediation

Add a Permissions-Policy header restricting unused APIs: Permissions-Policy: camera=(), microphone=(), geolocation=()

OE-2026-016 · WEB · WEB_CHECKER

Missing Referrer-Policy

OPEN
SeverityLOW
CVSS v3.13.1
CategoryNot mapped
Source / Checkweb_checker · missing_referrer_policy
Affected Endpoints
https://app.scan.acmesaas.io/https://app.scan.acmesaas.io:443https://app.scan.acmesaas.io:8443http://app.scan.acmesaas.io:80http://app.scan.acmesaas.io:8080https://api.scan.acmesaas.io/https://api.scan.acmesaas.io:443http://api.scan.acmesaas.io:80https://docs.scan.acmesaas.io/https://staging.scan.acmesaas.io/http://staging.scan.acmesaas.io:8080https://scan.acmesaas.io/
Description

Without Referrer-Policy, the full URL (including query parameters and paths) may be leaked to third-party sites via the Referer header.

Evidence
web_checker reported missing_referrer_policy on 12 endpoints (first observed 2026-05-22 12:18).
Remediation

Add: Referrer-Policy: strict-origin-when-cross-origin (or no-referrer for maximum privacy)

OE-2026-017 · WEB · WEB_CHECKER

Weak Strict-Transport-Security

OPEN
SeverityLOW
CVSS v3.13.1
CategoryNot mapped
Source / Checkweb_checker · weak_hsts
Affected Endpoints
https://scan.acmesaas.io/https://legacy.scan.acmesaas.io/
Description

The Strict-Transport-Security header on https://scan.acmesaas.io/ has an insufficient max-age. Short HSTS lifetimes reduce protection against HTTPS downgrade attacks.

Evidence
web_checker reported weak_hsts on 2 endpoints (first observed 2026-05-22 12:18).
Remediation

Set Strict-Transport-Security with a max-age of at least 15552000 seconds. Example: Strict-Transport-Security: max-age=31536000; includeSubDomains

OE-2026-018 · EMAIL / DNS · DOMAIN_SECURITY

DMARC policy is quarantine (not reject)

OPEN
SeverityLOW
CVSS v3.13.1
CategoryCWE-358: Improperly Implemented Security Check for Standard
Source / Checkdomain_security · email
Affected Endpoints
scan.acmesaas.io
Description

DMARC p=quarantine sends failing emails to spam. p=reject is stronger.

Evidence
domain_security reported email on 1 endpoint (first observed 2026-05-22 09:14).
Remediation

Consider upgrading the DMARC policy to p=reject.

OE-2026-019 · DOMAIN · DOMAIN_SECURITY

Domain update lock not enabled

OPEN
SeverityLOW
CVSS v3.13.1
CategoryNot mapped
Source / Checkdomain_security · rdap
Affected Endpoints
scan.acmesaas.io
Description

scan.acmesaas.io does not have an update lock (clientUpdateProhibited). Nameserver and contact records could be modified without an additional authorization step.

Evidence
domain_security reported rdap on 1 endpoint (first observed 2026-05-22 09:14).
Remediation

Enable the 'clientUpdateProhibited' lock at your domain registrar.

OE-2026-020 · EMAIL / DNS · DOMAIN_SECURITY

TLS-RPT not configured

OPEN
SeverityLOW
CVSS v3.13.1
CategoryCWE-358: Improperly Implemented Security Check for Standard
Source / Checkdomain_security · email
Affected Endpoints
scan.acmesaas.io
Description

scan.acmesaas.io has no SMTP TLS Reporting (TLS-RPT) record. You will not receive reports when TLS negotiation fails for inbound email.

Evidence
domain_security reported email on 1 endpoint (first observed 2026-05-22 09:14).
Remediation

Add a TXT record at _smtp._tls.scan.acmesaas.io with v=TLSRPTv1 and a rua mailto address for the reports.

INFO · 1 Finding
OE-2026-021 · EMAIL / DNS · DOMAIN_SECURITY

BIMI not configured

OPEN
SeverityINFO
CVSS v3.1n/a
CategoryCWE-358: Improperly Implemented Security Check for Standard
Source / Checkdomain_security · email
Affected Endpoints
scan.acmesaas.io
Description

scan.acmesaas.io has no BIMI record. BIMI displays your brand logo in email clients and requires DMARC p=reject, signalling mature email security.

Evidence
domain_security reported email on 1 endpoint (first observed 2026-05-22 09:14).
Remediation

Implement BIMI after setting DMARC p=reject. Add a TXT record at default._bimi.scan.acmesaas.io with v=BIMI1, your logo URL, and a VMC URL.

5. Disclaimer

This document contains confidential information produced by an automated external attack surface scan. Findings reflect externally observable configuration at the time of scanning and should be validated before remediation. The assessment covered public-facing hosts only; no authenticated, internal, or application-layer testing was performed. Where the scanner reported a non-clean status, coverage may be partial and a re-scan is recommended. Automated version-to-CVE matching can over-report where a vendor backports fixes without changing the version banner; such matches should be validated against the actual package build before treating them as confirmed exploitation. TLS and HTTPS findings observed on shared, CDN, or edge IP addresses may reflect the edge infrastructure rather than an origin misconfiguration, and should be confirmed against the origin before remediation.

Sample note, not part of a delivered report. Acme SaaS, scan.acmesaas.io, every subdomain, and every IP address on this page are fictional. Addresses are drawn from the RFC 5737 documentation ranges. Use this sample to judge format and depth. It is not a benchmark for how many findings, or how severe, a real scan returns.

What an external scan does not cover

OpenEASD sees your infrastructure from the outside, the way an attacker without credentials would. It reports what is exposed and the direction to close it. It cannot see your internal architecture, your code, or your data model, so two things stay out of reach:

  • Authenticated application testing. Business logic flaws, authorisation gaps between user roles, IDOR, payment race conditions. That is a founder-led pentest.
  • Internal network testing. Lateral movement, internal service exposure, Active Directory hardening. Out of scope for any external scan.
  • Authenticated and internal testing. Every check runs from the public internet, so anything behind a login or inside your network is out of reach by design. That is the boundary to hold in mind when reading a clean result: it means nothing was visible from outside, not that nothing is there.

See What OpenEASD Finds On Your Attack Surface, Free.

Same format you just read, built from your own infrastructure. Your exposed subdomains, takeover risks, open ports, TLS and header gaps, and DNS and email posture, each scored and traced to the check that found it. Detection-only, open source, no signup. All we need is a domain.

Frequently Asked Questions

What is external attack surface detection?

External attack surface detection is the practice of mapping everything about an organisation that is reachable from the public internet: subdomains, open ports and services, DNS, domain-lock and email records, TLS configuration, and the live web surface. It looks at your infrastructure the way an outside attacker would, using only publicly observable information. No access to your internal systems is needed or used.

What does an OpenEASD scan find?

An OpenEASD scan runs a fixed pipeline of 6 vectors backed by 27 tools. It surfaces exposed subdomains and forgotten environments, the ASNs and IP ranges registered to the organisation, subdomain takeover risks from dangling DNS records, open ports and internet-reachable services, TLS and HTTPS misconfiguration, SSH configuration weaknesses, known CVEs on exposed services, hardcoded secrets in served JavaScript, corporate logins for the domain appearing in infostealer logs, the technologies running on reachable web assets, missing or weak HTTP security headers and CORS problems, and DNS, domain-lock and email authentication gaps across DNSSEC, SPF, DKIM, DMARC, MTA-STS, TLS-RPT and open mail relay. Every finding carries a CVSS v3.1 score, a CWE category where one maps, the tool and check that produced it, and every affected endpoint. CVE findings additionally carry an EPSS exploit-probability percentile and a CISA KEV flag when the vulnerability is actively exploited in the wild.

How does the report decide what to fix first?

The report opens with a Priority Actions block listing the top five issues, each with a plain-language line explaining what is at stake for the business rather than for the engineer. Ranking is severity first, then CVSS, with a dominant boost for anything CISA lists as actively exploited in the wild and a nudge for a high EPSS exploit-probability score. That means a vulnerability attackers are using right now outranks a higher-scoring one nobody is exploiting. The full list stays in the Findings Summary section.

Is an OpenEASD scan safe? Will it touch my systems?

Yes, it is safe. OpenEASD is external and non-intrusive. It reads publicly observable information such as DNS records, service banners, TLS handshakes, and HTTP response headers. It does not log in, does not exploit anything, and performs no authenticated, internal, or application-layer testing. There are two modes. A passive scan uses public sources only, sends nothing to your infrastructure, and needs no authorisation. An active scan, which is what produced the sample above, probes your hosts directly and therefore requires that you own the domain or hold written authorisation from the owner. Every active probe carries an honest OpenEASD/1.0 user agent so you can identify it in your logs.

How is external attack surface detection different from a penetration test?

External attack surface detection maps what is exposed from the outside and points at the direction to fix it, but it does not log in or exploit anything. A penetration test is authenticated and hands-on: it tests business logic, privilege escalation, and access-control flaws inside the application, with reproduction steps and remediation for each issue. OpenEASD is a free first look at your perimeter. A founder-led pentest is the deeper engagement that follows.