OpenEASD External Attack Surface Scan Report
This is the OpenEASD report in the format we deliver. The company (Acme SaaS) and the domain (scan.acmesaas.io) are fictional, and every address shown comes from the ranges reserved for documentation. The structure is the real thing: the cover, the document control block, the Fix These First block, the finding IDs, the CVSS and CWE fields, the affected-endpoint lists, and the remediation wording are what the scanner produces. Run OpenEASD on your own domain and you get this document built from your own attack surface.
6 attack vectors, 27 tools, one report. This is a free attack surface scan: detection-only and open source. All we need is a domain. No signup, no credit card.
Read the full sample below, then scan your own domain to see what it finds on your infrastructure.
External Attack Surface Detection Report
scan.acmesaas.io · Sample report built on fictional data.
Confidential, For Authorized Use Only. This document contains confidential information produced by an automated external attack surface scan. Findings reflect externally observable configuration at the time of scanning and should be validated before remediation.
Document Control
| Title | External Attack Surface Detection Report (OpenEASD) |
|---|---|
| Target | scan.acmesaas.io and associated internet-facing hosts (no authenticated or internal access) |
| Assessment Type | Automated external attack surface detection and vulnerability analysis |
| Scan Window | 2026-05-22 09:14:07 UTC to 2026-05-22 12:41:53 UTC (3h 27m 46s) |
| Scan Status | Completed |
| Report Date | May 22, 2026 |
| Classification | Confidential, Authorized Use Only |
| Scan ID | 7f2a91c4-3d0b-4e58-9a17-c6b2f4e81d35 |
Note on counts: this report consolidates 74 raw scanner detections into 21 unique issues by grouping identical issues repeated across hosts, ports, or CVEs. Headline counts and the risk rating reflect unique issues; every affected endpoint is preserved under each finding.
1. Executive Summary
An automated external attack surface detection scan (OpenEASD) was run against scan.acmesaas.io and the hosts discovered under it. Testing was non-intrusive and performed from the public internet with no authenticated or internal access. The scan surfaced 21 unique findings (1 Critical, 5 High, 8 Medium, 6 Low, 1 Informational) consolidated from 74 raw detections.
This is a point-in-time snapshot of the externally observable attack surface, taken from the public internet. It does not include authenticated, internal, or manual testing, and an attack surface changes over time. Treat it as a baseline, not a certificate.
Priority Actions, Fix These First
The highest-impact issues, ranked. Actively-exploited (CISA KEV) and internet-facing critical issues come first. The full list is in Section 3.
| # | Issue | Why it matters | Severity |
|---|---|---|---|
| 1 | Unencrypted HTTPS TLS / HTTPS · 4 hosts | Data to this service crosses the internet in plaintext, so anyone on the network path can read it. | CRITICAL 9.1 |
| 2 | Missing Content-Security-Policy Web · 12 hosts | A single injected script would run in your users' browsers (cross-site scripting). | HIGH 7.5 |
| 3 | Subdomain takeover possible: old-marketing.scan.acmesaas.io (aws-s3) Attack Surface · 1 host | An attacker can claim this dangling subdomain and serve content under your name: phishing, malware, or session-cookie theft. | HIGH 7.5 |
| 4 | Subdomain takeover possible: promo-2024.scan.acmesaas.io (unknown) Attack Surface · 1 host | An attacker can claim this dangling subdomain and serve content under your name: phishing, malware, or session-cookie theft. | HIGH 7.5 |
| 5 | Subdomain takeover possible: status-old.scan.acmesaas.io (unknown) Attack Surface · 1 host | An attacker can claim this dangling subdomain and serve content under your name: phishing, malware, or session-cookie theft. | HIGH 7.5 |
Severity Distribution
Asset Discovery
Technology Stack
Technologies fingerprinted on reachable web assets (10 distinct). Informational only, no version, end-of-life, or vulnerability inference is implied.
2. Scope and Methodology
OpenEASD is an automated, external (black-box) attack surface scan. From a single domain it runs a fixed pipeline of 6 vectors backed by 27 tools: subdomain and asset discovery, then per-service checks for known vulnerabilities, TLS/SSL, SSH, web hygiene, and email and DNS posture. This was an active scan, run with the domain owner's authorisation on file. Testing was non-intrusive and performed from the public internet with no authenticated, internal, or application-layer access, and every probe carried an OpenEASD/1.0 user agent.
Scan Pipeline: 6 Vectors, 27 Tools
| Attack Vector | Tooling | Result |
|---|---|---|
| Domain Intelligence | Domain Security (DNS, DNSSEC chain of trust, SPF/DKIM/DMARC/MTA-STS/TLS-RPT/BIMI, open mail relay, RDAP), Infostealer Exposure (Hudson Rock Cavalier API), GitHub Secret Exposure (gitleaks), Lookalike Domain Detection (public DNS), Breach Exposure (XposedOrNot / HIBP) | 8 findings |
| Surface Enumeration | Subfinder, Amass, Alterx (Subdomain Permutation), ASN Discovery (ASN and IP ranges), GitHub Org Recon (public repos), DNSx (Resolve), Subdomain Takeover Check (subzy), Cloud Asset Enumeration (cloud_enum) | 4 findings |
| Port Discovery | Naabu (Port Scan), Service Detection (nmap -sV), Shodan Exposure (passive) | 0 findings |
| Network Exposure | Nmap (NSE Vuln Scan), TLS Checker, SSH Checker, Nuclei (Network Scan) | 1 finding |
| Web Exposure | HTTPx (Web Probe, Technology Fingerprinting), Historical URLs (gau: Wayback, Common Crawl, OTX, URLScan), Katana, Nuclei (Web Vuln Scan), Web Checker, JS Secrets (gitleaks) | 8 findings |
| Prioritization | CVE Intel (EPSS + CISA KEV) | Discovery |
Every finding is traceable to a specific tool, check type, and target in Detailed Findings. Automated version-to-CVE matching can over-report where a vendor backports fixes without changing the version banner; such matches should be validated against the actual package build.
3. Findings Summary
All findings are Open pending remediation. Counts are unique issues after consolidation. "Hosts" is the number of distinct endpoints affected by each finding.
| ID | Title | Scope | Severity | CVSS | Hosts | Status |
|---|---|---|---|---|---|---|
OE-2026-001 | Unencrypted HTTPS | TLS / HTTPS | CRITICAL | 9.1 | 4 | OPEN |
OE-2026-002 | Missing Content-Security-Policy | Web | HIGH | 7.5 | 12 | OPEN |
OE-2026-003 | Subdomain takeover possible: old-marketing.scan.acmesaas.io (aws-s3) | Attack Surface | HIGH | 7.5 | 1 | OPEN |
OE-2026-004 | Subdomain takeover possible: promo-2024.scan.acmesaas.io (unknown) | Attack Surface | HIGH | 7.5 | 1 | OPEN |
OE-2026-005 | Subdomain takeover possible: status-old.scan.acmesaas.io (unknown) | Attack Surface | HIGH | 7.5 | 1 | OPEN |
OE-2026-006 | Subdomain takeover possible: cdn-staging.scan.acmesaas.io (unknown) | Attack Surface | HIGH | 7.5 | 1 | OPEN |
OE-2026-007 | Missing X-Frame-Options | Web | MEDIUM | 5.3 | 14 | OPEN |
OE-2026-008 | Missing X-Content-Type-Options | Web | MEDIUM | 5.3 | 11 | OPEN |
OE-2026-009 | CORS wildcard Access-Control-Allow-Origin | Web | MEDIUM | 5.3 | 3 | OPEN |
OE-2026-010 | Missing Strict-Transport-Security | Web | MEDIUM | 5.3 | 6 | OPEN |
OE-2026-011 | DKIM record not found | Email / DNS | MEDIUM | 5.3 | 1 | OPEN |
OE-2026-012 | SPF policy is soft fail (~all) | Email / DNS | MEDIUM | 5.3 | 1 | OPEN |
OE-2026-013 | MTA-STS not configured | Email / DNS | MEDIUM | 5.3 | 1 | OPEN |
OE-2026-014 | Domain delete lock not enabled | Domain | MEDIUM | 5.3 | 1 | OPEN |
OE-2026-015 | Missing Permissions-Policy | Web | LOW | 3.1 | 15 | OPEN |
OE-2026-016 | Missing Referrer-Policy | Web | LOW | 3.1 | 12 | OPEN |
OE-2026-017 | Weak Strict-Transport-Security | Web | LOW | 3.1 | 2 | OPEN |
OE-2026-018 | DMARC policy is quarantine (not reject) | Email / DNS | LOW | 3.1 | 1 | OPEN |
OE-2026-019 | Domain update lock not enabled | Domain | LOW | 3.1 | 1 | OPEN |
OE-2026-020 | TLS-RPT not configured | Email / DNS | LOW | 3.1 | 1 | OPEN |
OE-2026-021 | BIMI not configured | Email / DNS | INFO | n/a | 1 | OPEN |
4. Detailed Findings
Each finding is documented with description, evidence, and remediation. Affected Endpoints list every host or port on which the issue was detected. Critical and high findings also carry a plain-language Business Impact line.
Not shown in this sample: the fictional scan behind this page returned no CVE findings, so no finding below carries the two rows that only appear on them. A CVE finding adds a CVEs row listing every matched identifier, and an Exploitation row that flags the finding when CISA lists a matched CVE as actively exploited in the wild (KEV) and states its EPSS exploit-probability percentile. Those two signals also drive the ranking in Priority Actions above: an actively-exploited issue outranks a higher-CVSS one that nobody is exploiting.
Unencrypted HTTPS
OPENData to this service crosses the internet in plaintext, so anyone on the network path can read it.
HTTPS on 192.0.2.24:8443 is accepting connections without TLS. Sensitive data exchanged over this service is exposed to interception and man-in-the-middle attacks.
tls_checker reported unencrypted_service on 4 endpoints (first observed 2026-05-22 10:06).
Disable the plaintext listener and configure TLS. Consult your service documentation for TLS/SSL configuration.
Missing Content-Security-Policy
OPENA single injected script would run in your users' browsers (cross-site scripting).
Without CSP, the browser has no restrictions on inline scripts, eval(), or resource origins, so an XSS flaw can execute arbitrary JavaScript.
web_checker reported missing_csp on 12 endpoints (first observed 2026-05-22 12:18).
Add a Content-Security-Policy header. Start with a report-only policy: Content-Security-Policy-Report-Only: default-src 'self'; script-src 'self'; report-uri /csp-report. Then tighten and enforce once violations are reviewed.
Subdomain takeover possible: old-marketing.scan.acmesaas.io (aws-s3)
OPENAn attacker can claim this dangling subdomain and serve content under your name: phishing, malware, or session-cookie theft.
old-marketing.scan.acmesaas.io appears to point at an unclaimed aws-s3 resource. An attacker who registers that resource on the hosting service could serve arbitrary content under your subdomain: credential phishing, malware delivery, or SSO-cookie theft from the same eTLD context.
takeover_check reported subdomain_takeover on 1 endpoint (first observed 2026-05-22 09:52).
Either remove the dangling DNS record or reclaim the unused resource on aws-s3. Verify by manually visiting the subdomain. A stale CNAME with an unclaimed third-party target is the signature pattern.
Subdomain takeover possible: promo-2024.scan.acmesaas.io (unknown)
OPENAn attacker can claim this dangling subdomain and serve content under your name: phishing, malware, or session-cookie theft.
promo-2024.scan.acmesaas.io appears to point at an unclaimed unknown resource. An attacker who registers that resource on the hosting service could serve arbitrary content under your subdomain: credential phishing, malware delivery, or SSO-cookie theft from the same eTLD context.
takeover_check reported subdomain_takeover on 1 endpoint (first observed 2026-05-22 09:52).
Either remove the dangling DNS record or reclaim the unused resource on unknown. Verify by manually visiting the subdomain. A stale CNAME with an unclaimed third-party target is the signature pattern.
Subdomain takeover possible: status-old.scan.acmesaas.io (unknown)
OPENAn attacker can claim this dangling subdomain and serve content under your name: phishing, malware, or session-cookie theft.
status-old.scan.acmesaas.io appears to point at an unclaimed unknown resource. An attacker who registers that resource on the hosting service could serve arbitrary content under your subdomain: credential phishing, malware delivery, or SSO-cookie theft from the same eTLD context.
takeover_check reported subdomain_takeover on 1 endpoint (first observed 2026-05-22 09:52).
Either remove the dangling DNS record or reclaim the unused resource on unknown. Verify by manually visiting the subdomain. A stale CNAME with an unclaimed third-party target is the signature pattern.
Subdomain takeover possible: cdn-staging.scan.acmesaas.io (unknown)
OPENAn attacker can claim this dangling subdomain and serve content under your name: phishing, malware, or session-cookie theft.
cdn-staging.scan.acmesaas.io appears to point at an unclaimed unknown resource. An attacker who registers that resource on the hosting service could serve arbitrary content under your subdomain: credential phishing, malware delivery, or SSO-cookie theft from the same eTLD context.
takeover_check reported subdomain_takeover on 1 endpoint (first observed 2026-05-22 09:52).
Either remove the dangling DNS record or reclaim the unused resource on unknown. Verify by manually visiting the subdomain. A stale CNAME with an unclaimed third-party target is the signature pattern.
Missing X-Frame-Options
OPENWithout X-Frame-Options, attackers can embed this page in an iframe on a malicious site and perform clickjacking attacks.
web_checker reported missing_xfo on 14 endpoints (first observed 2026-05-22 12:18).
Add: X-Frame-Options: DENY (or SAMEORIGIN if framing is needed). Also set the CSP frame-ancestors directive for modern browsers.
Missing X-Content-Type-Options
OPENWithout X-Content-Type-Options: nosniff, browsers may MIME-sniff responses and interpret non-executable content as scripts, enabling XSS.
web_checker reported missing_xcto on 11 endpoints (first observed 2026-05-22 12:18).
Add: X-Content-Type-Options: nosniff
CORS wildcard Access-Control-Allow-Origin
OPENThe server at https://api.scan.acmesaas.io/ sets Access-Control-Allow-Origin: *. Any website can make cross-origin requests. Credentials are not included, but this may expose non-public API data.
web_checker reported cors_wildcard on 3 endpoints (first observed 2026-05-22 12:18).
Restrict CORS to specific trusted origins. Use an allowlist instead of the wildcard (*) value.
Missing Strict-Transport-Security
OPENThe HTTPS response from https://app.scan.acmesaas.io/ does not set Strict-Transport-Security. Browsers may allow future visits over HTTP, leaving users exposed to downgrade and SSL-stripping attacks.
web_checker reported missing_hsts on 6 endpoints (first observed 2026-05-22 12:18).
Add a Strict-Transport-Security header with a max-age of at least six months. Example: Strict-Transport-Security: max-age=31536000; includeSubDomains
DKIM record not found
OPENNo DKIM record found for common selectors on scan.acmesaas.io.
domain_security reported email on 1 endpoint (first observed 2026-05-22 09:14).
Configure DKIM signing with your email provider and publish the public key as a TXT record.
SPF policy is soft fail (~all)
OPENSPF is set to ~all (soft fail). Spoofed emails may still be delivered.
domain_security reported email on 1 endpoint (first observed 2026-05-22 09:14).
Change ~all to -all for strict enforcement.
MTA-STS not configured
OPENscan.acmesaas.io has no MTA-STS policy. Inbound email delivery is not protected against TLS downgrade, so an in-path attacker can force plaintext delivery even when your mail server supports TLS.
domain_security reported email on 1 endpoint (first observed 2026-05-22 09:14).
Add a TXT record at _mta-sts.scan.acmesaas.io with v=STSv1 and an id value, then publish the policy at https://mta-sts.scan.acmesaas.io/.well-known/mta-sts.txt with version STSv1, mode enforce, your MX host, and max_age 86400.
Domain delete lock not enabled
OPENscan.acmesaas.io does not have a delete lock (clientDeleteProhibited). The domain could be accidentally or maliciously deleted, causing immediate service outage.
domain_security reported rdap on 1 endpoint (first observed 2026-05-22 09:14).
Enable the 'clientDeleteProhibited' lock at your domain registrar.
Missing Permissions-Policy
OPENWithout Permissions-Policy (formerly Feature-Policy), the page can access sensitive browser APIs (camera, microphone, geolocation) by default.
web_checker reported missing_permissions_policy on 15 endpoints (first observed 2026-05-22 12:18).
Add a Permissions-Policy header restricting unused APIs: Permissions-Policy: camera=(), microphone=(), geolocation=()
Missing Referrer-Policy
OPENWithout Referrer-Policy, the full URL (including query parameters and paths) may be leaked to third-party sites via the Referer header.
web_checker reported missing_referrer_policy on 12 endpoints (first observed 2026-05-22 12:18).
Add: Referrer-Policy: strict-origin-when-cross-origin (or no-referrer for maximum privacy)
Weak Strict-Transport-Security
OPENThe Strict-Transport-Security header on https://scan.acmesaas.io/ has an insufficient max-age. Short HSTS lifetimes reduce protection against HTTPS downgrade attacks.
web_checker reported weak_hsts on 2 endpoints (first observed 2026-05-22 12:18).
Set Strict-Transport-Security with a max-age of at least 15552000 seconds. Example: Strict-Transport-Security: max-age=31536000; includeSubDomains
DMARC policy is quarantine (not reject)
OPENDMARC p=quarantine sends failing emails to spam. p=reject is stronger.
domain_security reported email on 1 endpoint (first observed 2026-05-22 09:14).
Consider upgrading the DMARC policy to p=reject.
Domain update lock not enabled
OPENscan.acmesaas.io does not have an update lock (clientUpdateProhibited). Nameserver and contact records could be modified without an additional authorization step.
domain_security reported rdap on 1 endpoint (first observed 2026-05-22 09:14).
Enable the 'clientUpdateProhibited' lock at your domain registrar.
TLS-RPT not configured
OPENscan.acmesaas.io has no SMTP TLS Reporting (TLS-RPT) record. You will not receive reports when TLS negotiation fails for inbound email.
domain_security reported email on 1 endpoint (first observed 2026-05-22 09:14).
Add a TXT record at _smtp._tls.scan.acmesaas.io with v=TLSRPTv1 and a rua mailto address for the reports.
BIMI not configured
OPENscan.acmesaas.io has no BIMI record. BIMI displays your brand logo in email clients and requires DMARC p=reject, signalling mature email security.
domain_security reported email on 1 endpoint (first observed 2026-05-22 09:14).
Implement BIMI after setting DMARC p=reject. Add a TXT record at default._bimi.scan.acmesaas.io with v=BIMI1, your logo URL, and a VMC URL.
5. Disclaimer
This document contains confidential information produced by an automated external attack surface scan. Findings reflect externally observable configuration at the time of scanning and should be validated before remediation. The assessment covered public-facing hosts only; no authenticated, internal, or application-layer testing was performed. Where the scanner reported a non-clean status, coverage may be partial and a re-scan is recommended. Automated version-to-CVE matching can over-report where a vendor backports fixes without changing the version banner; such matches should be validated against the actual package build before treating them as confirmed exploitation. TLS and HTTPS findings observed on shared, CDN, or edge IP addresses may reflect the edge infrastructure rather than an origin misconfiguration, and should be confirmed against the origin before remediation.
Sample note, not part of a delivered report. Acme SaaS, scan.acmesaas.io, every subdomain, and every IP address on this page are fictional. Addresses are drawn from the RFC 5737 documentation ranges. Use this sample to judge format and depth. It is not a benchmark for how many findings, or how severe, a real scan returns.
What an external scan does not cover
OpenEASD sees your infrastructure from the outside, the way an attacker without credentials would. It reports what is exposed and the direction to close it. It cannot see your internal architecture, your code, or your data model, so two things stay out of reach:
- Authenticated application testing. Business logic flaws, authorisation gaps between user roles, IDOR, payment race conditions. That is a founder-led pentest.
- Internal network testing. Lateral movement, internal service exposure, Active Directory hardening. Out of scope for any external scan.
- Authenticated and internal testing. Every check runs from the public internet, so anything behind a login or inside your network is out of reach by design. That is the boundary to hold in mind when reading a clean result: it means nothing was visible from outside, not that nothing is there.
See What OpenEASD Finds On Your Attack Surface, Free.
Same format you just read, built from your own infrastructure. Your exposed subdomains, takeover risks, open ports, TLS and header gaps, and DNS and email posture, each scored and traced to the check that found it. Detection-only, open source, no signup. All we need is a domain.
Frequently Asked Questions
What is external attack surface detection?
External attack surface detection is the practice of mapping everything about an organisation that is reachable from the public internet: subdomains, open ports and services, DNS, domain-lock and email records, TLS configuration, and the live web surface. It looks at your infrastructure the way an outside attacker would, using only publicly observable information. No access to your internal systems is needed or used.
What does an OpenEASD scan find?
An OpenEASD scan runs a fixed pipeline of 6 vectors backed by 27 tools. It surfaces exposed subdomains and forgotten environments, the ASNs and IP ranges registered to the organisation, subdomain takeover risks from dangling DNS records, open ports and internet-reachable services, TLS and HTTPS misconfiguration, SSH configuration weaknesses, known CVEs on exposed services, hardcoded secrets in served JavaScript, corporate logins for the domain appearing in infostealer logs, the technologies running on reachable web assets, missing or weak HTTP security headers and CORS problems, and DNS, domain-lock and email authentication gaps across DNSSEC, SPF, DKIM, DMARC, MTA-STS, TLS-RPT and open mail relay. Every finding carries a CVSS v3.1 score, a CWE category where one maps, the tool and check that produced it, and every affected endpoint. CVE findings additionally carry an EPSS exploit-probability percentile and a CISA KEV flag when the vulnerability is actively exploited in the wild.
How does the report decide what to fix first?
The report opens with a Priority Actions block listing the top five issues, each with a plain-language line explaining what is at stake for the business rather than for the engineer. Ranking is severity first, then CVSS, with a dominant boost for anything CISA lists as actively exploited in the wild and a nudge for a high EPSS exploit-probability score. That means a vulnerability attackers are using right now outranks a higher-scoring one nobody is exploiting. The full list stays in the Findings Summary section.
Is an OpenEASD scan safe? Will it touch my systems?
Yes, it is safe. OpenEASD is external and non-intrusive. It reads publicly observable information such as DNS records, service banners, TLS handshakes, and HTTP response headers. It does not log in, does not exploit anything, and performs no authenticated, internal, or application-layer testing. There are two modes. A passive scan uses public sources only, sends nothing to your infrastructure, and needs no authorisation. An active scan, which is what produced the sample above, probes your hosts directly and therefore requires that you own the domain or hold written authorisation from the owner. Every active probe carries an honest OpenEASD/1.0 user agent so you can identify it in your logs.
How is external attack surface detection different from a penetration test?
External attack surface detection maps what is exposed from the outside and points at the direction to fix it, but it does not log in or exploit anything. A penetration test is authenticated and hands-on: it tests business logic, privilege escalation, and access-control flaws inside the application, with reproduction steps and remediation for each issue. OpenEASD is a free first look at your perimeter. A founder-led pentest is the deeper engagement that follows.