TrustFlare Surface · Patterns without an outside inventory

You only defend
what you already named.

Most perimeters are a list someone typed: official domains, a cloud account, last year’s pentest appendix. Shadow IT and forgotten systems do not live on that list. They live on the internet. The work is to look from the outside, continuously, with your own team.

This is what it looks like from the outside.

That’s not ours.

It resolves to your registrar and serves a login page.

The pentest covered the perimeter.

It covered the hosts you pointed at. That was nine months ago.

We have a WAF.

The admin panel on a forgotten subdomain does not.

01

The CMDB is not the internet

Asset databases describe what IT meant to own. They do not describe a developer’s weekend DNS record, a partner’s test box still on your prefix, or a cloud region nobody budgeted. Treating the CMDB as ground truth is how shadow IT stays off the programme.

How it shows up

  • A staging host in an old AWS account is missing from every official list.
  • Marketing bought a domain. Security never saw the ticket.
  • The CMDB is updated after the incident, not before the scan.

02

Annual pentest as discovery

A pentest is a test of a scope you already believe. It is not a search for the systems you forgot. If discovery only happens when an external team is on site, everything that appeared in between had a free year.

How it shows up

  • The report’s appendix becomes next year’s asset list.
  • New product domains go live in March. The next test is in November.
  • The pentester finds the forgotten panel. That is celebrated as coverage.

03

Scan only the names you already have

A scanner pointed at known domains will never invent the subdomain a teammate created at 1 a.m. Shadow IT is, by definition, outside the seed list. If the seed is the official inventory, the interesting hosts stay dark.

How it shows up

  • The job file is a copy of last year’s Excel.
  • Cloud ranges are “too noisy” so they are left out.
  • A subsidiary’s brand domain is nobody’s problem until a journalist finds it.

04

Forgotten clouds, forgotten prefixes

Companies collect accounts the way they collect Slack channels. An old sandbox still has a public IP. A proof-of-concept load balancer still answers. Nobody is on-call for it because it is not in the runbook.

How it shows up

  • A departed contractor’s personal card still pays for a small VM.
  • An unused region was never attached to the CSPM.
  • IPv6 is “not in production” and still has a management port open.

05

Open ports without a name

A port scan without service classification is a list of numbers. Dangerous exposure is a login page, a database banner, an admin interface, a missing authentication check. If the team cannot say what is behind 443, they cannot say who should close it.

How it shows up

  • Nmap output sits in a ticket with no owner.
  • Everything on 443 is “just HTTPS”.
  • A Redis on the internet is filed as “info, low” because the scanner did not know the product.

06

No change feed

The interesting event is not that a host exists. It is that it appeared on Tuesday, or that a closed finding opened again. Without a current outside inventory, change is a feeling. Incidents start with “when did this go live?” and no one can answer.

How it shows up

  • A subdomain is hijacked. Detection is a customer email.
  • A panel that was fixed in January is open in March. Nobody noticed the reopen.
  • The weekly scan is a screenshot, not a diff.

07

One engineer’s laptop is the ASM programme

Someone runs masscan, Nuclei, a few scripts. It works until they are on leave, until the API key expires, until the laptop is reimaged. There is no owner, no baseline, no reopen rule. The organisation has a hobby, not a product.

How it shows up

  • Results live in a personal Drive folder.
  • The scan user is a human who left in Q2.
  • Nobody can rerun last month’s scope with last month’s config.

08

WAF and CDN as a substitute for inventory

A WAF in front of the main site does not list the other ninety-seven names that still resolve. CDN logs are not an asset database. “We are behind Cloudflare” is a control for the hosts you put there.

How it shows up

  • The marketing microsite is on a raw IP.
  • An old origin still answers when someone guesses the hostname.
  • The WAF dashboard is clean. The forgotten /admin is not on it.

09

Findings without an owner

Discovery without a route to a team becomes a PDF. Shadow IT is especially bad here: the host is real, the org chart is not. If the product cannot carry ownership and reopen rules, the interesting things you found go back to being unknown.

How it shows up

  • A critical admin panel sits in a shared inbox.
  • Two teams each think the other shut it.
  • The same host is “fixed” in the ticket and still live on the next scan.

Look from the outside.
Keep looking.

TrustFlare Surface is the product your team runs to find shadow IT and obscure internet-facing systems. Analyst help stays optional after the product has found something.

See TrustFlare Surface