Skip to content

Attack Surface

Attack Surface Data

Attack Surface Data Collection

The Attack Surface engine relies on a very large graph representing internet-facing assets and their known connections.

Assets are added as nodes to the graph, which continuously runs scans to analyze these nodes for correlations, like enumerating subdomains, brute-force iterations, resolving the IP addresses of different record types, collecting Whois data, extracting BGP AS numbers, or crawling web apps.

The collected data creates elaborate nodes and edges that help find links and correlations between assets.

Attack Surface Data Updates

To ensure the collected data is accurate, up-to-date, and complete, Ostorlab implements bucket-ization of assets into generations. Each generation represents a set of properties to detect changes.

This approach allows for efficient, accurate, and timely detection of asset change.