That’s not ours.
It resolves to your registrar and serves a login page.
TrustFlare Surface · Patterns without an outside inventory
Most perimeters are a list someone typed: official domains, a cloud account, last year’s pentest appendix. Shadow IT and forgotten systems do not live on that list. They live on the internet. The work is to look from the outside, continuously, with your own team.
That’s not ours.
It resolves to your registrar and serves a login page.
The pentest covered the perimeter.
It covered the hosts you pointed at. That was nine months ago.
We have a WAF.
The admin panel on a forgotten subdomain does not.
01
Asset databases describe what IT meant to own. They do not describe a developer’s weekend DNS record, a partner’s test box still on your prefix, or a cloud region nobody budgeted. Treating the CMDB as ground truth is how shadow IT stays off the programme.
How it shows up
02
A pentest is a test of a scope you already believe. It is not a search for the systems you forgot. If discovery only happens when an external team is on site, everything that appeared in between had a free year.
How it shows up
03
A scanner pointed at known domains will never invent the subdomain a teammate created at 1 a.m. Shadow IT is, by definition, outside the seed list. If the seed is the official inventory, the interesting hosts stay dark.
How it shows up
04
Companies collect accounts the way they collect Slack channels. An old sandbox still has a public IP. A proof-of-concept load balancer still answers. Nobody is on-call for it because it is not in the runbook.
How it shows up
05
A port scan without service classification is a list of numbers. Dangerous exposure is a login page, a database banner, an admin interface, a missing authentication check. If the team cannot say what is behind 443, they cannot say who should close it.
How it shows up
06
The interesting event is not that a host exists. It is that it appeared on Tuesday, or that a closed finding opened again. Without a current outside inventory, change is a feeling. Incidents start with “when did this go live?” and no one can answer.
How it shows up
07
Someone runs masscan, Nuclei, a few scripts. It works until they are on leave, until the API key expires, until the laptop is reimaged. There is no owner, no baseline, no reopen rule. The organisation has a hobby, not a product.
How it shows up
08
A WAF in front of the main site does not list the other ninety-seven names that still resolve. CDN logs are not an asset database. “We are behind Cloudflare” is a control for the hosts you put there.
How it shows up
09
Discovery without a route to a team becomes a PDF. Shadow IT is especially bad here: the host is real, the org chart is not. If the product cannot carry ownership and reopen rules, the interesting things you found go back to being unknown.
How it shows up
TrustFlare Surface is the product your team runs to find shadow IT and obscure internet-facing systems. Analyst help stays optional after the product has found something.
See TrustFlare Surface