[{"data":1,"prerenderedAt":1016},["ShallowReactive",2],{"blog-index-articles":3},[4,118,206,299,399,499,584,637,695,746,833,885,938],{"id":5,"title":6,"articleSection":7,"body":8,"breadcrumbs":64,"cta":72,"description":75,"extension":76,"keywords":77,"listingDescription":91,"listingTitle":92,"meta":93,"navigation":94,"path":95,"publishedAt":96,"readingTime":97,"references":98,"seo":111,"seoTitle":92,"stem":112,"tags":113,"updatedAt":96,"__hash__":117},"blog\u002Fblog\u002Fasset-discovery-cybersecurity-external-attack-surface.md","What is asset discovery in cybersecurity? a practical guide to finding what you need to protect","Asset discovery",{"type":9,"value":10,"toc":56},"minimark",[11,15,18,23,28,32,36,40,45,49,53],[12,13,14],"p",{},"Asset discovery is the process of finding the systems, services, domains, applications, APIs, identities, and infrastructure your organization needs to protect. In cybersecurity, discovery is foundational because you cannot patch, monitor, test, or retire something you do not know exists.",[12,16,17],{},"External asset discovery focuses on what can be observed from outside the organization: domains, subdomains, public IPs, open ports, web applications, TLS certificates, DNS records, exposed admin panels, cloud services, and public metadata.",[19,20,22],"h2",{"id":21},"what-asset-discovery-should-find","What asset discovery should find",[24,25],"blog-info-table",{":columns":26,":rows":27},"[{\"key\":\"category\",\"label\":\"Category\"},{\"key\":\"examples\",\"label\":\"Examples\"},{\"key\":\"why\",\"label\":\"Why it matters\"}]","[{\"category\":\"Domain assets\",\"examples\":\"Root domains, subdomains, DNS records, redirects.\",\"why\":\"Attackers often start from public naming and forgotten subdomains.\"},{\"category\":\"Web services\",\"examples\":\"Apps, APIs, admin panels, staging environments.\",\"why\":\"Reachable web surfaces can expose vulnerabilities or sensitive data.\"},{\"category\":\"Transport signals\",\"examples\":\"Certificates, TLS versions, ports, protocols.\",\"why\":\"Weak or expired transport controls reduce trust and reveal drift.\"},{\"category\":\"Ownership context\",\"examples\":\"Teams, vendors, repositories, business units.\",\"why\":\"Findings need owners before remediation can move.\"}]",[19,29,31],{"id":30},"discovery-methods","Discovery methods",[33,34],"blog-card-grid",{":cards":35},"[{\"title\":\"Passive discovery\",\"icon\":\"i-lucide-eye\",\"body\":\"Uses public data such as DNS, certificates, Whois, search indexes, and internet datasets.\"},{\"title\":\"Active validation\",\"icon\":\"i-lucide-radar\",\"body\":\"Safely checks whether discovered assets are reachable and what services they expose.\"},{\"title\":\"Internal enrichment\",\"icon\":\"i-lucide-tags\",\"body\":\"Connects public assets to teams, cloud accounts, billing records, repositories, or vendors.\"},{\"title\":\"Continuous monitoring\",\"icon\":\"i-lucide-refresh-cw\",\"body\":\"Repeats discovery because assets change whenever teams ship, migrate, test, or retire services.\"}]",[19,37,39],{"id":38},"from-inventory-to-prioritization","From inventory to prioritization",[41,42],"blog-step-flow",{":numbered":43,":steps":44},"true","[{\"title\":\"Find assets\",\"body\":\"Gather domains, subdomains, services, certificates, and DNS records.\"},{\"title\":\"Validate exposure\",\"body\":\"Confirm which assets are reachable and what they expose externally.\"},{\"title\":\"Enrich context\",\"body\":\"Add ownership, technology, environment, and business importance.\"},{\"title\":\"Detect risk\",\"body\":\"Identify vulnerabilities, weak configuration, stale services, and sensitive exposure.\"},{\"title\":\"Assign action\",\"body\":\"Route findings to the right owners and track closure.\"}]",[19,46,48],{"id":47},"practical-checklist","Practical checklist",[50,51],"blog-checklist",{":items":52},"[\"Start with domains and subdomains because they reveal a large part of the public surface.\",\"Validate whether discovered assets are actually reachable before prioritizing.\",\"Track ownership as a first-class field, not an afterthought.\",\"Mark stale, duplicate, and unknown assets for review.\",\"Repeat discovery continuously; point-in-time inventories become outdated quickly.\"]",[12,54,55],{},"Asset discovery is not just an inventory exercise. It is the first step in reducing exposure, assigning responsibility, and finding risky systems before attackers do.",{"title":57,"searchDepth":58,"depth":58,"links":59},"",2,[60,61,62,63],{"id":21,"depth":58,"text":22},{"id":30,"depth":58,"text":31},{"id":38,"depth":58,"text":39},{"id":47,"depth":58,"text":48},[65,68,71],{"label":66,"to":67},"Home","\u002F",{"label":69,"to":70},"Blog","\u002Fblog",{"label":7},{"title":73,"description":74},"Ready to see what your external inventory is missing?","Discover authorized domains, subdomains, services, and metadata in one external attack surface workspace.","Asset discovery is the foundation of security visibility. You cannot patch, monitor, test, or retire assets your team does not know exist.","md",[78,79,80,81,82,83,84,85,86,87,88,89,90],"what is asset discovery","cybersecurity asset discovery","external asset discovery","asset inventory","attack surface visibility","internet-facing assets","unknown assets","subdomain discovery","open ports","service discovery","passive discovery","active discovery","vulnerability management","Learn how cybersecurity asset discovery helps teams find unknown assets, close inventory gaps, understand external exposure, and prioritize attack surface risk.","What Is Asset Discovery in Cybersecurity? A Practical Guide to Finding What You Need to Protect",{},true,"\u002Fblog\u002Fasset-discovery-cybersecurity-external-attack-surface","2026-05-28","10 min read",[99,102,105,108],{"label":100,"href":101},"OWASP Asset Management Cheat Sheet","https:\u002F\u002Fcheatsheetseries.owasp.org\u002Fcheatsheets\u002FAsset_Management_Cheat_Sheet.html",{"label":103,"href":104},"CISA Cyber Hygiene Services","https:\u002F\u002Fwww.cisa.gov\u002Fresources-tools\u002Fservices\u002Fcyber-hygiene-services",{"label":106,"href":107},"NIST Cybersecurity Framework","https:\u002F\u002Fwww.nist.gov\u002Fcyberframework",{"label":109,"href":110},"NIST attack surface glossary","https:\u002F\u002Fcsrc.nist.gov\u002Fglossary\u002Fterm\u002Fattack_surface",{"title":6,"description":75},"blog\u002Fasset-discovery-cybersecurity-external-attack-surface",[7,114,115,116],"External attack surface management","Asset inventory","Cybersecurity fundamentals","eU4rxChguTBqCQrhhpLtIdZMoVSm0QbXHivCPxBwadA",{"id":119,"title":120,"articleSection":114,"body":121,"breadcrumbs":168,"cta":173,"description":176,"extension":76,"keywords":177,"listingDescription":189,"listingTitle":190,"meta":191,"navigation":94,"path":192,"publishedAt":193,"readingTime":97,"references":194,"seo":201,"seoTitle":190,"stem":202,"tags":203,"updatedAt":193,"__hash__":205},"blog\u002Fblog\u002Fattack-surface-reduction-guide.md","Attack surface reduction: a practical guide to reducing what attackers can reach",{"type":9,"value":122,"toc":162},[123,126,129,133,137,141,145,149,152,156,159],[12,124,125],{},"Attack surface reduction is the disciplined work of removing, restricting, hardening, and monitoring the paths attackers can use to interact with your systems. It is not only about patching vulnerabilities. It is about reducing what can be reached in the first place.",[12,127,128],{},"The external attack surface includes domains, subdomains, APIs, ports, admin panels, cloud services, identity endpoints, certificates, third-party integrations, and public metadata. Every unnecessary exposure gives attackers more room to probe.",[19,130,132],{"id":131},"core-reduction-concepts","Core reduction concepts",[24,134],{":columns":135,":rows":136},"[{\"key\":\"concept\",\"label\":\"Concept\"},{\"key\":\"meaning\",\"label\":\"Meaning\"},{\"key\":\"example\",\"label\":\"Example action\"}]","[{\"concept\":\"Remove\",\"meaning\":\"Eliminate assets or services that no longer need to be public.\",\"example\":\"Retire stale subdomains and decommission forgotten staging apps.\"},{\"concept\":\"Restrict\",\"meaning\":\"Limit who can reach sensitive systems.\",\"example\":\"Put admin panels behind VPN, SSO, allow-lists, or private networks.\"},{\"concept\":\"Harden\",\"meaning\":\"Improve the security posture of assets that must remain public.\",\"example\":\"Patch software, improve TLS, add headers, and remove defaults.\"},{\"concept\":\"Monitor\",\"meaning\":\"Watch for drift, recurrence, and newly exposed services.\",\"example\":\"Alert when a new public endpoint or weak certificate appears.\"}]",[19,138,140],{"id":139},"exposure-matrix","Exposure matrix",[24,142],{":columns":143,":rows":144},"[{\"key\":\"exposure\",\"label\":\"Exposure\"},{\"key\":\"risk\",\"label\":\"Risk\"},{\"key\":\"reduction\",\"label\":\"Reduction move\"}]","[{\"exposure\":\"Public admin panel\",\"risk\":\"Brute force, credential reuse, exposed actions.\",\"reduction\":\"Restrict access and require strong identity controls.\"},{\"exposure\":\"Forgotten subdomain\",\"risk\":\"Takeover, stale software, unknown ownership.\",\"reduction\":\"Validate ownership and remove unused DNS records.\"},{\"exposure\":\"Open service port\",\"risk\":\"Direct probing and exploit attempts.\",\"reduction\":\"Close the port or limit source networks.\"},{\"exposure\":\"Weak TLS or headers\",\"risk\":\"Browser-side and transport security gaps.\",\"reduction\":\"Enforce modern TLS and security headers.\"}]",[19,146,148],{"id":147},"reduction-playbook","Reduction playbook",[41,150],{":numbered":43,":steps":151},"[{\"title\":\"Discover exposed assets\",\"body\":\"Build a current inventory of public domains, subdomains, services, and metadata.\"},{\"title\":\"Classify what matters\",\"body\":\"Add environment, owner, technology, business importance, and data sensitivity.\"},{\"title\":\"Remove what is unnecessary\",\"body\":\"Decommission stale services and clean up unused records.\"},{\"title\":\"Restrict sensitive paths\",\"body\":\"Limit public access to admin, staging, debug, and internal workflows.\"},{\"title\":\"Monitor recurrence\",\"body\":\"Keep watching so exposure does not silently return.\"}]",[19,153,155],{"id":154},"team-checklist","Team checklist",[50,157],{":items":158},"[\"Keep an accurate external asset inventory.\",\"Treat unknown ownership as a risk signal.\",\"Remove stale subdomains, unused ports, and abandoned services.\",\"Restrict public access to administrative and non-production systems.\",\"Prioritize reachable assets with known vulnerabilities or sensitive workflows.\",\"Recheck after remediation to confirm the exposure is closed.\"]",[12,160,161],{},"Attack surface reduction works best as a recurring operating practice. The surface changes whenever teams deploy, test, migrate, integrate, or forget resources.",{"title":57,"searchDepth":58,"depth":58,"links":163},[164,165,166,167],{"id":131,"depth":58,"text":132},{"id":139,"depth":58,"text":140},{"id":147,"depth":58,"text":148},{"id":154,"depth":58,"text":155},[169,170,171],{"label":66,"to":67},{"label":69,"to":70},{"label":172},"Attack surface reduction",{"title":174,"description":175},"Ready to reduce public exposure?","Continuously discover, monitor, and prioritize authorized external assets before risk drifts.","Attack surface reduction is the disciplined work of removing, restricting, hardening, and monitoring the paths attackers can use to interact with your systems.",[178,179,180,181,182,183,86,184,185,186,187,188],"attack surface reduction","reduce attack surface","exposure reduction","internet exposure reduction","external attack surface management","public admin interfaces","unused services","asset discovery","vulnerability remediation","risk reduction","security hardening","Learn how to reduce exposed assets, risky ports, unused services, public admin interfaces, and external attack paths with practical attack surface reduction methods.","Attack Surface Reduction: A Practical Guide to Reducing What Attackers Can Reach",{},"\u002Fblog\u002Fattack-surface-reduction-guide","2026-05-29",[195,196,197,198],{"label":109,"href":110},{"label":100,"href":101},{"label":103,"href":104},{"label":199,"href":200},"CISA Known Exploited Vulnerabilities Catalog","https:\u002F\u002Fwww.cisa.gov\u002Fknown-exploited-vulnerabilities-catalog",{"title":120,"description":176},"blog\u002Fattack-surface-reduction-guide",[172,114,204,116],"Exposure reduction","0xLS2RDcP3ksg-kCL3DiQZWjZc5M-ybmAek226QSSik",{"id":207,"title":208,"articleSection":114,"body":209,"breadcrumbs":256,"cta":261,"description":264,"extension":76,"keywords":265,"listingDescription":272,"listingTitle":273,"meta":274,"navigation":94,"path":275,"publishedAt":276,"readingTime":277,"references":278,"seo":292,"seoTitle":273,"stem":293,"tags":294,"updatedAt":276,"__hash__":298},"blog\u002Fblog\u002Fattack-vector-vs-attack-surface.md","Attack vector vs attack surface: what is the difference?",{"type":9,"value":210,"toc":250},[211,214,217,221,224,228,232,236,240,244,247],[12,212,213],{},"An attack surface is the collection of exposed places an attacker could interact with: domains, subdomains, APIs, login pages, cloud services, ports, identities, integrations, and data flows. An attack vector is the method used to attack one of those exposed places.",[12,215,216],{},"A public login page is part of the surface. Credential stuffing against that login page is a vector. A public API is part of the surface. Broken authorization or injection attempts against that API are vectors.",[19,218,220],{"id":219},"how-the-concepts-connect","How the concepts connect",[41,222],{":steps":223},"[{\"label\":\"Asset exposure\",\"icon\":\"i-lucide-globe-2\",\"body\":\"Domains, APIs, login pages, cloud resources, and public services.\"},{\"label\":\"Attack surface\",\"icon\":\"i-lucide-panels-top-left\",\"body\":\"The reachable places that need control, ownership, and monitoring.\"},{\"label\":\"Attack vectors\",\"icon\":\"i-lucide-route\",\"body\":\"The methods used to exploit or abuse that exposure.\"},{\"label\":\"Exploit path\",\"icon\":\"i-lucide-git-branch\",\"body\":\"A realistic chain from exposure to business impact.\"}]",[19,225,227],{"id":226},"attack-surface-vs-attack-vector","Attack surface vs attack vector",[24,229],{":columns":230,":rows":231},"[{\"key\":\"dimension\",\"label\":\"Dimension\"},{\"key\":\"surface\",\"label\":\"Attack surface\"},{\"key\":\"vector\",\"label\":\"Attack vector\"}]","[{\"dimension\":\"Simple meaning\",\"surface\":\"What is exposed and could be targeted.\",\"vector\":\"How an attacker may try to gain access or cause impact.\"},{\"dimension\":\"Scope\",\"surface\":\"Assets, endpoints, services, identities, integrations, and data flows.\",\"vector\":\"Phishing, credential stuffing, SQL injection, exposed admin access, or token abuse.\"},{\"dimension\":\"Primary question\",\"surface\":\"What can be reached, misused, or probed?\",\"vector\":\"Which method could exploit a weakness on that surface?\"},{\"dimension\":\"Reduction strategy\",\"surface\":\"Remove unnecessary exposure, retire stale assets, and restrict access.\",\"vector\":\"Add MFA, patching, validation, hardening, monitoring, and response controls.\"}]",[19,233,235],{"id":234},"saas-examples","SaaS examples",[24,237],{":columns":238,":rows":239},"[{\"key\":\"surface\",\"label\":\"Surface\"},{\"key\":\"vectors\",\"label\":\"Likely vectors\"},{\"key\":\"action\",\"label\":\"Practical action\"}]","[{\"surface\":\"Login page\",\"vectors\":\"Credential stuffing, password spraying, MFA fatigue.\",\"action\":\"Rate limit login attempts, enforce MFA, and monitor unusual authentication.\"},{\"surface\":\"Public API endpoint\",\"vectors\":\"Broken object authorization, injection payloads, token replay.\",\"action\":\"Validate authorization per object and require scoped tokens.\"},{\"surface\":\"Forgotten subdomain\",\"vectors\":\"Subdomain takeover, exposed staging app, default credentials.\",\"action\":\"Continuously discover subdomains and remove stale DNS or cloud resources.\"},{\"surface\":\"Admin panel\",\"vectors\":\"Brute force, credential reuse, exposed debug actions.\",\"action\":\"Restrict access and alert on public exposure.\"}]",[19,241,243],{"id":242},"reduction-checklist","Reduction checklist",[50,245],{":items":246},"[\"Keep an accurate inventory of internet-facing domains, subdomains, APIs, ports, and cloud services.\",\"Remove unused public services instead of only adding controls around them.\",\"Separate production, staging, and internal environments so temporary exposure does not become permanent.\",\"Review DNS, SSL, Whois, security.txt, and service metadata because attackers use the same public signals.\",\"Monitor changes continuously; attack surface grows whenever teams ship, migrate, test, or forget resources.\"]",[12,248,249],{},"Knowing the difference helps teams prioritize. Surface work asks what exists and what should be reachable. Vector work asks how that reachable thing could be abused.",{"title":57,"searchDepth":58,"depth":58,"links":251},[252,253,254,255],{"id":219,"depth":58,"text":220},{"id":226,"depth":58,"text":227},{"id":234,"depth":58,"text":235},{"id":242,"depth":58,"text":243},[257,258,259],{"label":66,"to":67},{"label":69,"to":70},{"label":260},"Attack vector vs attack surface",{"title":262,"description":263},"Ready to map your authorized external surface?","Add domains you control, discover reachable assets, and monitor practical attack paths continuously.","Attack surface is what your organization exposes. Attack vectors are the methods attackers can use against that exposure. Learn the difference with practical SaaS, API, and domain examples.",[266,267,268,269,182,178,270,271],"attack vector vs attack surface","difference between attack vector and attack surface","what is an attack surface","what is an attack vector","cybersecurity risk management","SaaS security monitoring","Understand the difference between attack vectors and attack surfaces, with practical examples for SaaS, APIs, domains, and external exposure management.","Attack Vector vs Attack Surface: What's the Difference?",{},"\u002Fblog\u002Fattack-vector-vs-attack-surface","2026-05-23","7 min read",[279,282,283,286,289],{"label":280,"href":281},"NordStellar attack vector vs attack surface","https:\u002F\u002Fnordstellar.com\u002Fblog\u002Fattack-vector-vs-attack-surface\u002F",{"label":109,"href":110},{"label":284,"href":285},"IBM attack vector overview","https:\u002F\u002Fwww.ibm.com\u002Fthink\u002Ftopics\u002Fattack-vector",{"label":287,"href":288},"Cloudflare attack vector glossary","https:\u002F\u002Fwww.cloudflare.com\u002Flearning\u002Fsecurity\u002Fglossary\u002Fattack-vector\u002F",{"label":290,"href":291},"TechTarget attack vector definition","https:\u002F\u002Fwww.techtarget.com\u002Fsearchsecurity\u002Fdefinition\u002Fattack-vector",{"title":208,"description":264},"blog\u002Fattack-vector-vs-attack-surface",[295,296,114,297],"Attack surface","Attack vector","Cybersecurity basics","taE7zBz2gDHV3yrVEj_qIgZXFNI2L1bERTQabteRJ3w",{"id":300,"title":301,"articleSection":302,"body":303,"breadcrumbs":350,"cta":355,"description":358,"extension":76,"keywords":359,"listingDescription":370,"listingTitle":371,"meta":372,"navigation":94,"path":373,"publishedAt":374,"readingTime":375,"references":376,"seo":392,"seoTitle":371,"stem":393,"tags":394,"updatedAt":374,"__hash__":398},"blog\u002Fblog\u002Fautomated-pentest-vs-manual-pentest.md","Automated pentest vs manual pentest: what security teams should use and when","Penetration testing",{"type":9,"value":304,"toc":344},[305,308,311,315,318,322,326,330,333,337,341],[12,306,307],{},"Automated pentesting and manual pentesting solve different problems. Automation gives repeatable coverage across assets, known vulnerability patterns, and configuration drift. Manual testing adds expert judgment, business context, exploit chaining, and review of logic that scanners cannot fully understand.",[12,309,310],{},"Security teams should not frame the choice as one or the other. The stronger model is continuous automated validation for breadth, plus focused manual review when risk, complexity, or compliance requires deeper analysis.",[19,312,314],{"id":313},"where-each-approach-fits","Where each approach fits",[33,316],{":cards":317},"[{\"title\":\"Automated pentesting\",\"icon\":\"i-lucide-bot\",\"body\":\"Repeatable scans, known checks, external exposure monitoring, and regression detection across many assets.\"},{\"title\":\"Manual pentesting\",\"icon\":\"i-lucide-user-check\",\"body\":\"Expert analysis, business logic testing, creative attack chaining, and validation of high-impact paths.\"}]",[19,319,321],{"id":320},"comparison","Comparison",[24,323],{":columns":324,":rows":325},"[{\"key\":\"dimension\",\"label\":\"Dimension\"},{\"key\":\"automated\",\"label\":\"Automated pentest\"},{\"key\":\"manual\",\"label\":\"Manual pentest\"}]","[{\"dimension\":\"Coverage\",\"automated\":\"Broad, frequent, and consistent across many domains or endpoints.\",\"manual\":\"Narrower, deeper, and focused on scoped systems.\"},{\"dimension\":\"Strength\",\"automated\":\"Detects known vulnerabilities, drift, weak configuration, exposed files, and recurring issues.\",\"manual\":\"Explores business logic, chained exploitation, authorization flaws, and unusual workflows.\"},{\"dimension\":\"Timing\",\"automated\":\"Continuous, scheduled, or triggered after deployment.\",\"manual\":\"Periodic, milestone-based, or tied to major releases.\"},{\"dimension\":\"Evidence\",\"automated\":\"Standardized findings, timestamps, and repeatable checks.\",\"manual\":\"Narrative risk, proof of exploitability, and contextual impact.\"}]",[19,327,329],{"id":328},"a-practical-workflow","A practical workflow",[41,331],{":numbered":43,":steps":332},"[{\"title\":\"Discover assets\",\"body\":\"Keep an accurate inventory of domains, subdomains, APIs, and services.\"},{\"title\":\"Run continuous checks\",\"body\":\"Use automation for known vulnerabilities, headers, TLS, exposed routes, and drift.\"},{\"title\":\"Prioritize findings\",\"body\":\"Focus human review on confirmed exposure, high-value assets, and business-critical systems.\"},{\"title\":\"Perform manual testing\",\"body\":\"Validate exploitability, authorization boundaries, and attack chains.\"},{\"title\":\"Retest and monitor\",\"body\":\"Confirm remediation and keep watching for recurrence.\"}]",[19,334,336],{"id":335},"decision-guide","Decision guide",[24,338],{":columns":339,":rows":340},"[{\"key\":\"situation\",\"label\":\"Situation\"},{\"key\":\"recommended\",\"label\":\"Recommended approach\"}]","[{\"situation\":\"Large external surface with frequent changes\",\"recommended\":\"Automated monitoring first, then manual review for risky findings.\"},{\"situation\":\"New application launch\",\"recommended\":\"Manual pentest supported by automated baseline scans.\"},{\"situation\":\"Compliance deadline\",\"recommended\":\"Manual engagement plus evidence from continuous checks.\"},{\"situation\":\"Repeated exposure drift\",\"recommended\":\"Automated recurring validation and ownership workflows.\"}]",[12,342,343],{},"Mature programs use automation to avoid blind spots and manual review to understand the paths that matter most.",{"title":57,"searchDepth":58,"depth":58,"links":345},[346,347,348,349],{"id":313,"depth":58,"text":314},{"id":320,"depth":58,"text":321},{"id":328,"depth":58,"text":329},{"id":335,"depth":58,"text":336},[351,352,353],{"label":66,"to":67},{"label":69,"to":70},{"label":354},"Automated vs manual pentest",{"title":356,"description":357},"Ready to keep external testing continuous?","Use Splorix to monitor authorized domains between deeper manual reviews.","Automated pentesting gives teams continuous breadth. Manual pentesting adds expert depth, business context, and creative attack chaining. Mature programs use both.",[360,361,362,363,364,365,366,367,368,369],"automated pentest vs manual pentest","automated penetration testing","manual penetration testing","continuous pentesting","PTaaS","vulnerability validation","security testing automation","expert pentest validation","web application security testing","external attack surface monitoring","Compare automated pentesting and manual pentesting, including when to use continuous validation, expert review, exploitability testing, and remediation workflows.","Automated Pentest vs Manual Pentest: What Security Teams Should Use and When",{},"\u002Fblog\u002Fautomated-pentest-vs-manual-pentest","2026-05-26","9 min read",[377,380,383,386,389],{"label":378,"href":379},"OWASP Web Security Testing Guide","https:\u002F\u002Fowasp.org\u002Fwww-project-web-security-testing-guide\u002F",{"label":381,"href":382},"OWASP Application Security Verification Standard","https:\u002F\u002Fowasp.org\u002Fwww-project-application-security-verification-standard\u002F",{"label":384,"href":385},"NIST SP 800-115 technical guide","https:\u002F\u002Fcsrc.nist.gov\u002Fpubs\u002Fsp\u002F800\u002F115\u002Ffinal",{"label":387,"href":388},"PTES technical guidelines","http:\u002F\u002Fwww.pentest-standard.org\u002Findex.php\u002FPTES_Technical_Guidelines",{"label":390,"href":391},"PortSwigger web security academy","https:\u002F\u002Fportswigger.net\u002Fweb-security",{"title":301,"description":358},"blog\u002Fautomated-pentest-vs-manual-pentest",[395,396,397,114],"Automated pentesting","Manual pentesting","Continuous security testing","l2vz135hf35a3kbFEPCPxq-fxC1dlApGhYl0Kv8XLLg",{"id":400,"title":401,"articleSection":402,"body":403,"breadcrumbs":453,"cta":458,"description":461,"extension":76,"keywords":462,"listingDescription":470,"listingTitle":471,"meta":472,"navigation":94,"path":473,"publishedAt":474,"readingTime":475,"references":476,"seo":492,"seoTitle":471,"stem":493,"tags":494,"updatedAt":474,"__hash__":498},"blog\u002Fblog\u002Fdast-detect-production-application-vulnerabilities.md","DAST: detect vulnerabilities in production applications","Application security",{"type":9,"value":404,"toc":447},[405,408,411,415,418,421,425,429,433,437,441,444],[12,406,407],{},"DAST, or dynamic application security testing, tests a running application through the same external surface an attacker can reach. A DAST scanner sends HTTP requests, follows reachable paths, injects safe test payloads, and analyzes responses for signs of vulnerabilities.",[12,409,410],{},"In production, the value is visibility. Teams can detect weak headers, exposed files, unsafe routes, outdated TLS behavior, and known vulnerability patterns on the exact service customers use. Production scanning must still be scoped, rate-limited, authorized, and designed to avoid destructive actions.",[19,412,414],{"id":413},"how-dast-observes-a-running-application","How DAST observes a running application",[41,416],{":steps":417},"[{\"label\":\"Target application\",\"icon\":\"i-lucide-server\",\"body\":\"Start from an authorized domain, app, API, or production-like environment.\"},{\"label\":\"Crawl\",\"icon\":\"i-lucide-route\",\"body\":\"Discover reachable paths, redirects, forms, headers, and service responses.\"},{\"label\":\"Test payloads\",\"icon\":\"i-lucide-bug\",\"body\":\"Send scoped checks that look for known vulnerability behavior.\"},{\"label\":\"Response analysis\",\"icon\":\"i-lucide-file-search\",\"body\":\"Compare status codes, timing, headers, content, and evidence.\"},{\"label\":\"Findings\",\"icon\":\"i-lucide-list-checks\",\"body\":\"Keep reproducible evidence, timestamps, and remediation context.\"}]",[12,419,420],{},"DAST is useful when risk depends on runtime behavior. It sees redirects, cookies, headers, reverse proxies, public endpoints, deployed configuration, and production-only exposure that source-code analysis may miss.",[19,422,424],{"id":423},"dast-vs-sast","DAST vs SAST",[24,426],{":columns":427,":rows":428},"[{\"key\":\"dimension\",\"label\":\"Dimension\"},{\"key\":\"dast\",\"label\":\"DAST\"},{\"key\":\"sast\",\"label\":\"SAST\"}]","[{\"dimension\":\"Testing view\",\"dast\":\"Black-box testing against a running application.\",\"sast\":\"White-box analysis of source code or compiled artifacts.\"},{\"dimension\":\"Strong at finding\",\"dast\":\"Runtime behavior, exposed endpoints, headers, TLS, and exploitable responses.\",\"sast\":\"Unsafe code patterns, tainted data flows, secrets, and framework mistakes.\"},{\"dimension\":\"Blind spots\",\"dast\":\"Hidden business logic and paths behind complex authentication.\",\"sast\":\"Reverse proxies, WAF behavior, deployed config, and production-only exposure.\"},{\"dimension\":\"Best outcome\",\"dast\":\"Confirm exploitable behavior from the outside.\",\"sast\":\"Prevent vulnerable code before it reaches runtime.\"}]",[19,430,432],{"id":431},"what-production-dast-can-cover","What production DAST can cover",[24,434],{":columns":435,":rows":436},"[{\"key\":\"category\",\"label\":\"Category\"},{\"key\":\"examples\",\"label\":\"Examples\"},{\"key\":\"risk\",\"label\":\"Production risk\"}]","[{\"category\":\"Injection signals\",\"examples\":\"SQL injection probes, command injection hints, template injection behavior.\",\"risk\":\"Data leakage, account takeover, or full application compromise.\"},{\"category\":\"Cross-site scripting\",\"examples\":\"Reflected payloads, unsafe output encoding, DOM-exposed inputs.\",\"risk\":\"Session theft, phishing, and client-side compromise.\"},{\"category\":\"Headers and TLS\",\"examples\":\"Missing HSTS, weak CSP, insecure redirects, certificate issues.\",\"risk\":\"Downgrade attacks, browser exposure, and avoidable trust failures.\"},{\"category\":\"Exposed routes\",\"examples\":\"Backup files, debug endpoints, admin panels, default pages.\",\"risk\":\"Information disclosure and faster attacker reconnaissance.\"}]",[19,438,440],{"id":439},"production-guardrails","Production guardrails",[50,442],{":items":443},"[\"Scan only domains and applications you own or are explicitly authorized to test.\",\"Start with read-only, non-destructive templates before enabling intrusive checks.\",\"Use rate limits, scan windows, and alerting so production teams can distinguish testing from incidents.\",\"Exclude dangerous paths such as logout, payment confirmation, destructive admin actions, and data mutation endpoints.\",\"Keep evidence, timestamps, and request context so findings can be reproduced without repeating noisy scans.\"]",[12,445,446],{},"DAST should not replace secure design, code review, dependency management, or manual testing. It is strongest as a runtime control that confirms what your deployed application actually exposes.",{"title":57,"searchDepth":58,"depth":58,"links":448},[449,450,451,452],{"id":413,"depth":58,"text":414},{"id":423,"depth":58,"text":424},{"id":431,"depth":58,"text":432},{"id":439,"depth":58,"text":440},[454,455,456],{"label":66,"to":67},{"label":69,"to":70},{"label":457},"DAST for production applications",{"title":459,"description":460},"Ready to monitor an authorized production surface?","Create a workspace and run scoped external checks against domains you are allowed to test.","Dynamic application security testing helps teams observe a running application from the outside, identify exploitable behavior, and keep production exposure visible without needing source code access.",[463,464,465,466,368,467,468,469],"DAST","detect vulnerabilities in production applications","dynamic application security testing","production vulnerability scanning","authorized production scanning","application security testing","Nuclei vulnerability scanning","Learn how dynamic application security testing helps teams detect vulnerabilities in production applications safely and continuously.","DAST: Detect Vulnerabilities in Production Applications",{},"\u002Fblog\u002Fdast-detect-production-application-vulnerabilities","2026-05-15","8 min read",[477,480,483,486,489],{"label":478,"href":479},"Stephane Robert DAST guide","https:\u002F\u002Fblog.stephane-robert.info\u002Fdocs\u002Fsecuriser\u002Fanalyser-code\u002Fdast\u002F",{"label":481,"href":482},"OWASP DevSecOps DAST guideline","https:\u002F\u002Fowasp.org\u002Fwww-project-devsecops-guideline\u002Flatest\u002F02b-Dynamic-Application-Security-Testing",{"label":484,"href":485},"OWASP Developer Guide DAST tools","https:\u002F\u002Fdevguide.owasp.org\u002Fen\u002F06-verification\u002F02-tools\u002F01-dast\u002F",{"label":487,"href":488},"PortSwigger DAST overview","https:\u002F\u002Fportswigger.net\u002Fburp\u002Fapplication-security-testing\u002Fdast",{"label":490,"href":491},"ProjectDiscovery Nuclei templates","https:\u002F\u002Fdocs.projectdiscovery.io\u002Ftemplates\u002Fintroduction",{"title":401,"description":461},"blog\u002Fdast-detect-production-application-vulnerabilities",[463,495,496,497],"Production security","Vulnerability scanning","Web application security","uZs4lklhIusTsMf3NSKF_Lz0P6sfd3yBBnCVc4lQ0lg",{"id":500,"title":501,"articleSection":114,"body":502,"breadcrumbs":548,"cta":553,"description":556,"extension":76,"keywords":557,"listingDescription":566,"listingTitle":567,"meta":568,"navigation":94,"path":569,"publishedAt":570,"readingTime":375,"references":571,"seo":578,"seoTitle":567,"stem":579,"tags":580,"updatedAt":570,"__hash__":583},"blog\u002Fblog\u002Fdetect-shadow-it-continuously-external-attack-surface.md","How to detect shadow IT continuously before it expands your attack surface",{"type":9,"value":503,"toc":542},[504,507,510,514,517,521,524,528,532,536,539],[12,505,506],{},"Shadow IT is technology used without the normal visibility, ownership, or review of IT and security teams. In external attack surface management, the most dangerous form is an internet-facing asset nobody is watching: a forgotten subdomain, a trial SaaS instance, a staging app, a cloud service, or a temporary API that became permanent.",[12,508,509],{},"The issue is rarely malicious. Teams ship quickly, test vendors, run pilots, or create temporary infrastructure. Risk grows when those assets keep running after ownership, patching, monitoring, or access control disappears.",[19,511,513],{"id":512},"why-shadow-it-expands-attack-surface","Why shadow IT expands attack surface",[33,515],{":cards":516},"[{\"title\":\"Unknown ownership\",\"icon\":\"i-lucide-circle-help\",\"body\":\"Security teams cannot assign remediation if nobody knows which team owns the asset.\"},{\"title\":\"Missing hardening\",\"icon\":\"i-lucide-shield-off\",\"body\":\"Temporary apps often skip TLS, headers, authentication, and monitoring standards.\"},{\"title\":\"Patch gaps\",\"icon\":\"i-lucide-wrench\",\"body\":\"Forgotten services keep old frameworks, admin panels, or dependencies online.\"},{\"title\":\"Weak response\",\"icon\":\"i-lucide-clock-alert\",\"body\":\"Incidents take longer when responders first have to discover who built the system.\"}]",[19,518,520],{"id":519},"continuous-detection-workflow","Continuous detection workflow",[41,522],{":numbered":43,":steps":523},"[{\"title\":\"Discover\",\"body\":\"Enumerate domains, subdomains, certificates, DNS records, open ports, and public services.\"},{\"title\":\"Enrich\",\"body\":\"Add hosting, technology, TLS, Whois, redirects, and service metadata.\"},{\"title\":\"Match ownership\",\"body\":\"Link assets to teams, repositories, cloud accounts, vendors, or business units.\"},{\"title\":\"Prioritize\",\"body\":\"Focus first on reachable, unauthenticated, sensitive, or vulnerable assets.\"},{\"title\":\"Close the loop\",\"body\":\"Assign action, retire stale services, and monitor for recurrence.\"}]",[19,525,527],{"id":526},"shadow-it-signals","Shadow IT signals",[24,529],{":columns":530,":rows":531},"[{\"key\":\"signal\",\"label\":\"Signal\"},{\"key\":\"what\",\"label\":\"What it suggests\"},{\"key\":\"action\",\"label\":\"Action\"}]","[{\"signal\":\"Unrecognized subdomain\",\"what\":\"A team or vendor created an asset outside the normal inventory.\",\"action\":\"Identify owner, purpose, data exposure, and lifecycle.\"},{\"signal\":\"Default page\",\"what\":\"A service is deployed but not fully configured.\",\"action\":\"Restrict access or retire it if no owner exists.\"},{\"signal\":\"Expired certificate\",\"what\":\"The asset may be unmanaged or abandoned.\",\"action\":\"Validate business need and update or remove.\"},{\"signal\":\"Exposed staging app\",\"what\":\"Non-production code is reachable from the internet.\",\"action\":\"Add access controls and separate environments.\"}]",[19,533,535],{"id":534},"detection-checklist","Detection checklist",[50,537],{":items":538},"[\"Scan external assets continuously, not only during annual audits.\",\"Treat unknown ownership as a risk signal even before a vulnerability is confirmed.\",\"Track changes in DNS, certificates, technologies, redirects, and open services.\",\"Give engineering teams a fast way to claim, explain, or retire discovered assets.\",\"Review third-party and vendor-hosted assets that use your domains or brand.\"]",[12,540,541],{},"Continuous shadow IT detection turns asset discovery into an operational habit. The goal is not to block every experiment; it is to make sure experiments become owned, secured, and retired when no longer needed.",{"title":57,"searchDepth":58,"depth":58,"links":543},[544,545,546,547],{"id":512,"depth":58,"text":513},{"id":519,"depth":58,"text":520},{"id":526,"depth":58,"text":527},{"id":534,"depth":58,"text":535},[549,550,551],{"label":66,"to":67},{"label":69,"to":70},{"label":552},"Shadow IT detection",{"title":554,"description":555},"Ready to make unknown external assets visible?","Continuously discover domains, subdomains, and services that may otherwise drift outside ownership.","Shadow IT becomes dangerous when unknown internet-facing assets drift outside ownership, patching, monitoring, and security review. Continuous discovery closes that gap.",[558,559,560,561,80,85,562,563,564,565],"detect shadow IT","continuous shadow IT detection","shadow IT risks","unknown internet-facing assets","asset inventory gaps","shadow IT monitoring","internet exposed assets","attack surface discovery","Learn how to detect shadow IT continuously by discovering unknown internet-facing assets, validating exposure, enriching metadata, and assigning ownership before risk grows.","How to Detect Shadow IT Continuously Before It Expands Your Attack Surface",{},"\u002Fblog\u002Fdetect-shadow-it-continuously-external-attack-surface","2026-05-27",[572,573,574,577],{"label":106,"href":107},{"label":103,"href":104},{"label":575,"href":576},"Microsoft cloud security posture management","https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fdefender-for-cloud\u002Fconcept-cloud-security-posture-management",{"label":100,"href":101},{"title":501,"description":556},"blog\u002Fdetect-shadow-it-continuously-external-attack-surface",[581,114,7,582],"Shadow IT","Continuous monitoring","5XTjJuSbG1wAaQ9Gv79reCg-mwfdxjHDXWVM5MSdIxM",{"id":585,"title":586,"articleSection":587,"body":588,"breadcrumbs":592,"cta":597,"description":602,"extension":76,"keywords":603,"listingDescription":612,"listingTitle":613,"meta":614,"navigation":94,"path":615,"publishedAt":616,"readingTime":97,"references":617,"seo":631,"seoTitle":632,"stem":633,"tags":634,"updatedAt":616,"__hash__":636},"blog\u002Fblog\u002Fmalware-as-a-service.md","Malware-as-a-Service: how commoditized cybercrime changes business risk","Threat intelligence",{"type":9,"value":589,"toc":590},[],{"title":57,"searchDepth":58,"depth":58,"links":591},[],[593,594,595],{"label":66,"to":67},{"label":69,"to":70},{"label":596},"Malware-as-a-Service",{"title":598,"description":599,"buttonLabel":600,"to":601},"Watch your external exposure before attackers do.","Use Splorix to monitor authorized domains, discovered assets, exposed endpoints, leaked credential signals, and security metadata in one workspace.","Create account","\u002Fregister","Malware-as-a-Service makes cybercrime easier to buy, operate, and scale. Learn how MaaS ecosystems work, what business risks they create, and practical defenses for reducing exposure.",[604,605,606,607,608,609,182,610,611],"malware as a service","MaaS","cybercrime as a service","ransomware as a service","infostealer malware","credential theft","threat intelligence","attack surface monitoring","Malware-as-a-Service turns malware, access, and criminal infrastructure into reusable services. Learn how MaaS works, why it matters, and how teams can reduce exposure.","Malware-as-a-Service and Business Risk",{},"\u002Fblog\u002Fmalware-as-a-service","2026-06-23",[618,621,624,627,630],{"label":619,"href":620},"NordStellar: Malware-as-a-Service","https:\u002F\u002Fnordstellar.com\u002Fblog\u002Fmalware-as-a-service\u002F",{"label":622,"href":623},"CISA StopRansomware guide","https:\u002F\u002Fwww.cisa.gov\u002Fstopransomware\u002Fransomware-guide",{"label":625,"href":626},"Microsoft: ransomware as a service","https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2022\u002F05\u002F09\u002Fransomware-as-a-service-understanding-the-cybercrime-gig-economy-and-how-to-protect-yourself\u002F",{"label":628,"href":629},"MITRE ATT&CK software matrix","https:\u002F\u002Fattack.mitre.org\u002Fsoftware\u002F",{"label":106,"href":107},{"title":586,"description":602},"Malware-as-a-Service: What It Is, How It Works, and How to Reduce Risk","blog\u002Fmalware-as-a-service",[596,635,587,295],"Cybercrime","u_iBlent4tP16pJQPedon-ANVZ0fyHQHAIEgOCN54IA",{"id":638,"title":639,"articleSection":402,"body":640,"breadcrumbs":647,"cta":652,"description":655,"extension":76,"keywords":656,"listingDescription":664,"listingTitle":665,"meta":666,"navigation":94,"path":667,"publishedAt":668,"readingTime":669,"references":670,"seo":687,"seoTitle":688,"stem":689,"tags":690,"updatedAt":668,"__hash__":694},"blog\u002Fblog\u002Fowasp-top-10-2025-changes-2026-priorities.md","OWASP Top 10 2025: what changed and how to act in 2026",{"type":9,"value":641,"toc":645},[642],[12,643,644],{},"The OWASP Top 10:2025 is more than a reordered list. It reflects how application risk now spans design decisions, dependencies, build systems, deployment configuration, runtime behavior, and the assets exposed to the internet. This guide explains the changes and turns them into an actionable security plan for 2026.",{"title":57,"searchDepth":58,"depth":58,"links":646},[],[648,649,650],{"label":66,"to":67},{"label":69,"to":70},{"label":651},"OWASP Top 10 2025",{"title":653,"description":654,"buttonLabel":600,"to":601},"Turn application security priorities into external visibility","Continuously discover public assets, endpoints, technologies, certificate signals, and exposed weaknesses across your attack surface.","Explore the OWASP Top 10 2025 changes, new risk categories, ranking shifts, and practical steps to strengthen application security priorities in 2026.",[651,657,658,659,660,661,662,663,90,182],"what changed in OWASP Top 10 2025","OWASP 2025 categories","application security risks 2026","AppSec priorities","software supply chain failures","security misconfiguration","mishandling exceptional conditions","A practical guide to the OWASP Top 10:2025 changes, new application security priorities, and the actions engineering and security teams should take in 2026.","OWASP Top 10 2025: What Changed",{},"\u002Fblog\u002Fowasp-top-10-2025-changes-2026-priorities","2026-07-13","12 min read",[671,674,677,680,681,684],{"label":672,"href":673},"OWASP Top 10:2025","https:\u002F\u002Fowasp.org\u002FTop10\u002F2025\u002F",{"label":675,"href":676},"OWASP Top 10:2025 Introduction and Methodology","https:\u002F\u002Fowasp.org\u002FTop10\u002F2025\u002F0x00_2025-Introduction\u002F",{"label":678,"href":679},"OWASP: Establishing a Modern Application Security Program","https:\u002F\u002Fowasp.org\u002FTop10\u002F2025\u002F0x03_2025-Establishing_a_Modern_Application_Security_Program\u002F",{"label":381,"href":382},{"label":682,"href":683},"NIST SP 800-218: Secure Software Development Framework","https:\u002F\u002Fcsrc.nist.gov\u002Fpubs\u002Fsp\u002F800\u002F218\u002Ffinal",{"label":685,"href":686},"CISA: Secure by Design","https:\u002F\u002Fwww.cisa.gov\u002Fsecurebydesign",{"title":639,"description":655},"OWASP Top 10 2025: Changes and 2026 AppSec Priorities","blog\u002Fowasp-top-10-2025-changes-2026-priorities",[691,402,692,693],"OWASP Top 10","AppSec","Vulnerability management","UiY75Csj6UROWZ1nv2gSy792ZhQr9QZ-fF-lsBZdp40",{"id":696,"title":697,"articleSection":698,"body":699,"breadcrumbs":703,"cta":708,"description":711,"extension":76,"keywords":712,"listingDescription":723,"listingTitle":724,"meta":725,"navigation":94,"path":726,"publishedAt":727,"readingTime":728,"references":729,"seo":740,"seoTitle":741,"stem":742,"tags":743,"updatedAt":727,"__hash__":745},"blog\u002Fblog\u002Fpenetration-testing-types.md","Types of penetration testing: how to choose the right pentest for your security goals","Security testing",{"type":9,"value":700,"toc":701},[],{"title":57,"searchDepth":58,"depth":58,"links":702},[],[704,705,706],{"label":66,"to":67},{"label":69,"to":70},{"label":707},"Penetration testing types",{"title":709,"description":710,"buttonLabel":600,"to":601},"Make external security testing continuous.","Use Splorix to monitor authorized domains, discovered assets, endpoints, SSL state, technology signals, and actionable security findings between manual assessments.","Understand the main types of penetration testing, how each pentest method works, when to use it, and how continuous attack surface monitoring supports stronger security testing.",[713,714,715,716,717,718,719,720,721,722,182],"types of penetration testing","penetration testing types","web application penetration testing","API penetration testing","cloud penetration testing","network penetration testing","red team assessment","black box pentest","white box pentest","gray box pentest","Learn the main types of penetration testing, when to use each one, and how to combine manual, automated, web, API, cloud, network, and red team testing.","Types of Penetration Testing",{},"\u002Fblog\u002Fpenetration-testing-types","2026-06-29","11 min read",[730,732,733,734,737],{"label":731,"href":385},"NIST SP 800-115 technical security testing guide",{"label":378,"href":379},{"label":381,"href":382},{"label":735,"href":736},"Penetration Testing Execution Standard","http:\u002F\u002Fwww.pentest-standard.org\u002F",{"label":738,"href":739},"MITRE ATT&CK Enterprise","https:\u002F\u002Fattack.mitre.org\u002Fmatrices\u002Fenterprise\u002F",{"title":697,"description":711},"Types of Penetration Testing: Web, API, Cloud, Network, Red Team, and More","blog\u002Fpenetration-testing-types",[302,698,497,744],"Attack surface management","m2J3xYP_vZsUleksBqYq08rRgP1PJPXTBEe9ha09y2A",{"id":747,"title":748,"articleSection":749,"body":750,"breadcrumbs":796,"cta":801,"description":804,"extension":76,"keywords":805,"listingDescription":815,"listingTitle":816,"meta":817,"navigation":94,"path":818,"publishedAt":819,"readingTime":475,"references":820,"seo":827,"seoTitle":816,"stem":828,"tags":829,"updatedAt":819,"__hash__":832},"blog\u002Fblog\u002Fproactive-threat-detection-reactive-security.md","Proactive threat detection: why reactive security is no longer enough","Security operations",{"type":9,"value":751,"toc":790},[752,755,758,762,766,770,773,777,780,784,787],[12,753,754],{},"Reactive security responds after something triggers: an alert, a user report, a vendor bulletin, or an incident. Proactive threat detection looks earlier. It searches for exposed assets, weak signals, vulnerable services, suspicious changes, and attacker opportunities before they become urgent.",[12,756,757],{},"The shift matters because modern environments change constantly. New domains appear, cloud services drift, staging apps become public, and dependencies age. Waiting for a high-confidence alert often means waiting until the attacker has already found the opportunity.",[19,759,761],{"id":760},"reactive-vs-proactive-security","Reactive vs proactive security",[24,763],{":columns":764,":rows":765},"[{\"key\":\"dimension\",\"label\":\"Dimension\"},{\"key\":\"reactive\",\"label\":\"Reactive security\"},{\"key\":\"proactive\",\"label\":\"Proactive threat detection\"}]","[{\"dimension\":\"Timing\",\"reactive\":\"After an alert, incident, or known report.\",\"proactive\":\"Before impact, based on exposure, weak signals, and threat intelligence.\"},{\"dimension\":\"Main question\",\"reactive\":\"What happened and how do we contain it?\",\"proactive\":\"What could happen and how do we reduce the opportunity?\"},{\"dimension\":\"Inputs\",\"reactive\":\"Alerts, tickets, logs, incidents, and user reports.\",\"proactive\":\"Asset discovery, vulnerability data, threat intel, attack paths, and drift.\"},{\"dimension\":\"Outcome\",\"reactive\":\"Faster response and recovery.\",\"proactive\":\"Smaller attack surface and earlier remediation.\"}]",[19,767,769],{"id":768},"what-proactive-detection-looks-for","What proactive detection looks for",[33,771],{":cards":772},"[{\"title\":\"Unknown assets\",\"icon\":\"i-lucide-radar\",\"body\":\"Domains, subdomains, APIs, or cloud services that are reachable but not owned by a team.\"},{\"title\":\"Exploitable exposure\",\"icon\":\"i-lucide-bug\",\"body\":\"Known vulnerable software, exposed admin routes, weak TLS, or missing browser controls.\"},{\"title\":\"Risky change\",\"icon\":\"i-lucide-git-branch\",\"body\":\"New records, ports, certificates, redirects, or technologies that expand reachability.\"},{\"title\":\"Weak signals\",\"icon\":\"i-lucide-activity\",\"body\":\"Small indicators that do not prove compromise but deserve review before they combine.\"}]",[19,774,776],{"id":775},"practical-workflow","Practical workflow",[41,778],{":numbered":43,":steps":779},"[{\"title\":\"Discover\",\"body\":\"Continuously find internet-facing domains, services, and metadata.\"},{\"title\":\"Enrich\",\"body\":\"Add ownership, technology, certificate, DNS, Whois, and vulnerability context.\"},{\"title\":\"Prioritize\",\"body\":\"Focus on reachable, business-critical, exploitable, or unknown assets first.\"},{\"title\":\"Validate\",\"body\":\"Confirm whether the signal is real, reproducible, and within authorized scope.\"},{\"title\":\"Remediate\",\"body\":\"Assign ownership, fix exposure, and monitor for recurrence.\"}]",[19,781,783],{"id":782},"proactive-security-checklist","Proactive security checklist",[50,785],{":items":786},"[\"Maintain an inventory of internet-facing assets and update it continuously.\",\"Track newly discovered domains, subdomains, open ports, certificates, and exposed services.\",\"Combine vulnerability severity with exploitability, reachability, and business ownership.\",\"Watch known exploited vulnerability sources and map them to your actual assets.\",\"Retest after remediation so closed risk does not quietly return.\"]",[12,788,789],{},"Proactive detection does not remove the need for incident response. It makes incident response less frequent, less surprising, and better informed.",{"title":57,"searchDepth":58,"depth":58,"links":791},[792,793,794,795],{"id":760,"depth":58,"text":761},{"id":768,"depth":58,"text":769},{"id":775,"depth":58,"text":776},{"id":782,"depth":58,"text":783},[797,798,799],{"label":66,"to":67},{"label":69,"to":70},{"label":800},"Proactive threat detection",{"title":802,"description":803},"Ready to move from reactive to continuous visibility?","Monitor authorized external assets and identify exposure before it becomes incident work.","Reactive security waits for alerts. Proactive threat detection looks for exposed assets, weak signals, and attacker opportunities before they become incidents.",[806,807,808,809,810,182,811,812,813,814],"proactive threat detection","reactive security","why reactive security is no longer enough","continuous security monitoring","threat hunting","vulnerability prioritization","security operations","known exploited vulnerabilities","cyber threat intelligence","Learn why reactive security is no longer enough and how proactive threat detection combines continuous monitoring, threat hunting, and attack surface visibility.","Proactive Threat Detection: Why Reactive Security Is No Longer Enough",{},"\u002Fblog\u002Fproactive-threat-detection-reactive-security","2026-05-24",[821,822,823,826],{"label":199,"href":200},{"label":106,"href":107},{"label":824,"href":825},"MITRE ATT&CK","https:\u002F\u002Fattack.mitre.org\u002F",{"label":103,"href":104},{"title":748,"description":804},"blog\u002Fproactive-threat-detection-reactive-security",[800,830,831,744],"Threat hunting","Reactive security","UOR_jNwz0Yep32lHEBNX0YE__m7-qu2FR6j6ZMEJzrg",{"id":834,"title":835,"articleSection":402,"body":836,"breadcrumbs":843,"cta":848,"description":851,"extension":76,"keywords":852,"listingDescription":861,"listingTitle":862,"meta":863,"navigation":94,"path":864,"publishedAt":865,"readingTime":97,"references":866,"seo":877,"seoTitle":878,"stem":879,"tags":880,"updatedAt":865,"__hash__":884},"blog\u002Fblog\u002Fsoftware-supply-chain-security.md","What is software supply chain security and how can businesses protect themselves?",{"type":9,"value":837,"toc":841},[838],[12,839,840],{},"Software supply chain security protects the people, dependencies, build systems, vendors, and deployment paths that move software from source code to production. This guide explains the risk in practical terms and shows how teams can reduce exposure without slowing delivery.",{"title":57,"searchDepth":58,"depth":58,"links":842},[],[844,845,846],{"label":66,"to":67},{"label":69,"to":70},{"label":847},"Software supply chain security",{"title":849,"description":850,"buttonLabel":600,"to":601},"Reduce supply chain exposure across your public assets","Use Splorix to monitor domains, endpoints, SSL signals, technology exposure, and credential leak indicators before small changes become visible risk.","Learn what software supply chain security means, how supply chain attacks happen, why dependencies and CI\u002FCD systems matter, and how businesses can reduce risk.",[853,854,855,856,857,858,859,860,182],"software supply chain security","supply chain attack","dependency security","SBOM","CI\u002FCD security","open source security","third-party risk management","signed artifacts","A practical guide to software supply chain security, dependency risk, CI\u002FCD exposure, SBOMs, signed artifacts, vendor trust, and continuous monitoring.","Software Supply Chain Security",{},"\u002Fblog\u002Fsoftware-supply-chain-security","2026-06-30",[867,870,873,876],{"label":868,"href":869},"NIST: Software Supply Chain Security Guidance","https:\u002F\u002Fwww.nist.gov\u002Fitl\u002Fexecutive-order-14028-improving-nations-cybersecurity\u002Fsoftware-supply-chain-security-guidance",{"label":871,"href":872},"OWASP: Top 10 CI\u002FCD Security Risks","https:\u002F\u002Fowasp.org\u002Fwww-project-top-10-ci-cd-security-risks\u002F",{"label":874,"href":875},"SLSA: Supply-chain Levels for Software Artifacts","https:\u002F\u002Fslsa.dev\u002F",{"label":685,"href":686},{"title":835,"description":851},"Software Supply Chain Security: What It Is and How to Reduce Risk","blog\u002Fsoftware-supply-chain-security",[881,402,882,883],"Supply chain security","Third-party risk","DevSecOps","0unMo0IyJDN8hoBbO8Ra6RRBxX3Y-zHNLPn-DS_WAow",{"id":886,"title":887,"articleSection":888,"body":889,"breadcrumbs":893,"cta":898,"description":901,"extension":76,"keywords":902,"listingDescription":913,"listingTitle":914,"meta":915,"navigation":94,"path":916,"publishedAt":917,"readingTime":97,"references":918,"seo":931,"seoTitle":932,"stem":933,"tags":934,"updatedAt":917,"__hash__":937},"blog\u002Fblog\u002Fwhat-is-cybersquatting-domain-risks-prevention.md","What is cybersquatting? Domain risks, examples, and prevention","Domain security",{"type":9,"value":890,"toc":891},[],{"title":57,"searchDepth":58,"depth":58,"links":892},[],[894,895,896],{"label":66,"to":67},{"label":69,"to":70},{"label":897},"Cybersquatting",{"title":899,"description":900,"buttonLabel":600,"to":601},"Monitor domain abuse before it reaches customers.","Use Splorix to monitor authorized domains, suspicious lookalike signals, SSL state, Whois context, and external attack surface changes.","Learn what cybersquatting is, how domain squatting creates phishing and brand risk, how it differs from typosquatting, and how teams can monitor and prevent domain abuse.",[903,904,905,906,907,908,909,910,911,912],"cybersquatting","domain squatting","brand impersonation domains","domain abuse prevention","UDRP","domain monitoring","domain security","brand protection","phishing prevention","attack surface management","Cybersquatting abuses brand, product, and trademark confusion through domain names. Learn the risks, detection signals, and prevention steps for security teams.","What Is Cybersquatting?",{},"\u002Fblog\u002Fwhat-is-cybersquatting-domain-risks-prevention","2026-06-26",[919,922,925,928],{"label":920,"href":921},"NordStellar: cybersquatting","https:\u002F\u002Fnordstellar.com\u002Fblog\u002Fcybersquatting\u002F",{"label":923,"href":924},"ICANN Uniform Domain Name Dispute Resolution Policy","https:\u002F\u002Fwww.icann.org\u002Fen\u002Fcontracted-parties\u002Fconsensus-policies\u002Funiform-domain-name-dispute-resolution-policy\u002Funiform-domain-name-dispute-resolution-policy-01-01-2020-en",{"label":926,"href":927},"WIPO Domain Name Dispute Resolution","https:\u002F\u002Fwww.wipo.int\u002Famc\u002Fen\u002Fdomains\u002F",{"label":929,"href":930},"CISA: avoiding social engineering and phishing attacks","https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fnews\u002Favoiding-social-engineering-and-phishing-attacks",{"title":887,"description":901},"What Is Cybersquatting? Domain Risks, Examples, and Prevention","blog\u002Fwhat-is-cybersquatting-domain-risks-prevention",[897,888,935,936],"Brand protection","Phishing prevention","R97Uba-buF3vRKfd6WAUj0iOnjigHfnARAXQ1Y0U72k",{"id":939,"title":940,"articleSection":888,"body":941,"breadcrumbs":979,"cta":984,"description":987,"extension":76,"keywords":988,"listingDescription":995,"listingTitle":996,"meta":997,"navigation":94,"path":998,"publishedAt":999,"readingTime":375,"references":1000,"seo":1012,"seoTitle":996,"stem":1013,"tags":1014,"updatedAt":999,"__hash__":1015},"blog\u002Fblog\u002Fwhat-is-typosquatting-domain-risks-prevention.md","What is typosquatting? domain risks, examples, and prevention",{"type":9,"value":942,"toc":974},[943,946,949,953,956,960,964,968,971],[12,944,945],{},"Typosquatting is the abuse of misspelled, lookalike, or confusingly similar domains. Attackers register domains that resemble a trusted brand, then use them for phishing, credential theft, malware delivery, traffic redirection, or fraud.",[12,947,948],{},"The risk is not limited to obvious spelling mistakes. Attackers can combine keyboard-near characters, missing letters, extra separators, homoglyphs, alternate top-level domains, and brand-adjacent wording to make a domain look familiar at a glance.",[19,950,952],{"id":951},"how-typosquatting-works","How typosquatting works",[41,954],{":steps":955},"[{\"label\":\"Brand signal\",\"icon\":\"i-lucide-building-2\",\"body\":\"The attacker chooses a domain, product, or company name users already trust.\"},{\"label\":\"Domain variant\",\"icon\":\"i-lucide-text-cursor-input\",\"body\":\"They register a typo, lookalike, homoglyph, or adjacent phrase.\"},{\"label\":\"Deceptive use\",\"icon\":\"i-lucide-mail-warning\",\"body\":\"The domain hosts phishing, redirects users, sends email, or imitates a login flow.\"},{\"label\":\"Impact\",\"icon\":\"i-lucide-shield-alert\",\"body\":\"Users lose credentials, customers are misled, and brand trust is damaged.\"}]",[19,957,959],{"id":958},"common-typosquatting-patterns","Common typosquatting patterns",[24,961],{":columns":962,":rows":963},"[{\"key\":\"pattern\",\"label\":\"Pattern\"},{\"key\":\"example\",\"label\":\"Example style\"},{\"key\":\"risk\",\"label\":\"Risk\"}]","[{\"pattern\":\"Missing letters\",\"example\":\"Dropping a character from the brand.\",\"risk\":\"Looks normal when users scan quickly.\"},{\"pattern\":\"Extra separators\",\"example\":\"Adding hyphens, dots, or words around the brand.\",\"risk\":\"Can appear legitimate in emails or ads.\"},{\"pattern\":\"Lookalike characters\",\"example\":\"Swapping visually similar letters or Unicode characters.\",\"risk\":\"Hard to detect without normalization.\"},{\"pattern\":\"Alternate TLDs\",\"example\":\"Reusing the brand on another top-level domain.\",\"risk\":\"Can confuse users who remember the name but not the suffix.\"}]",[19,965,967],{"id":966},"prevention-and-monitoring","Prevention and monitoring",[50,969],{":items":970},"[\"Monitor newly registered domains that resemble important brands, products, and customer-facing services.\",\"Normalize domain variants for common typos, homoglyphs, separators, and alternate top-level domains.\",\"Use SPF, DKIM, DMARC, and brand indicators to reduce email impersonation.\",\"Provide clear login and support URLs so customers know where to go.\",\"Triage suspicious domains by DNS, web content, certificate data, mail records, and hosting behavior.\",\"Coordinate takedown, registrar reports, and user communication when abuse is confirmed.\"]",[12,972,973],{},"Typosquatting is an external attack surface problem because the risky asset is often outside your infrastructure. Monitoring must therefore combine domain intelligence, brand context, and response workflows.",{"title":57,"searchDepth":58,"depth":58,"links":975},[976,977,978],{"id":951,"depth":58,"text":952},{"id":958,"depth":58,"text":959},{"id":966,"depth":58,"text":967},[980,981,982],{"label":66,"to":67},{"label":69,"to":70},{"label":983},"Typosquatting",{"title":985,"description":986},"Ready to monitor lookalike domain risk?","Track suspicious domain variants and reduce impersonation risk before customers encounter it.","Typosquatting abuses misspelled and lookalike domains to impersonate trusted brands, steal credentials, deliver malware, redirect users, and damage customer trust.",[989,990,991,992,993,911,910,909,903,994,182],"what is typosquatting","typosquatting examples","typosquatting prevention","lookalike domains","domain impersonation","homoglyph domains","Learn how typosquatting abuses misspelled and lookalike domains for phishing, fraud, malware delivery, and brand impersonation, plus how to reduce the risk.","What Is Typosquatting? Domain Risks, Examples, and Prevention",{},"\u002Fblog\u002Fwhat-is-typosquatting-domain-risks-prevention","2026-05-25",[1001,1004,1006,1009],{"label":1002,"href":1003},"ICANN domain name basics","https:\u002F\u002Fwww.icann.org\u002Fresources\u002Fpages\u002Fdomain-name-basics-2017-10-10-en",{"label":1005,"href":930},"CISA phishing guidance",{"label":1007,"href":1008},"Microsoft digital defense report","https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fsecurity-insider\u002Fintelligence-reports\u002Fmicrosoft-digital-defense-report-2024",{"label":1010,"href":1011},"Cloudflare phishing overview","https:\u002F\u002Fwww.cloudflare.com\u002Flearning\u002Faccess-management\u002Fphishing-attack\u002F",{"title":940,"description":987},"blog\u002Fwhat-is-typosquatting-domain-risks-prevention",[983,888,936,935],"R2QYToDQ92Hmyx_BAR3y8RNjCwgCrZPB1mEKuMKzYy0",1786639717547]