Map your entire external footprint — passively.

Subdomains, exposed services, open doors an attacker would walk through — we map your external footprint passively, silently, without touching your network, so you can close gaps before someone else finds them.

Subdomains & shadow ITExposed services & portsCloud & hosting footprintAttack surface findings

Passive only — no active scanning, no agents, nothing installed.

External Attack Surface Report

Velocity Cyber

Sample

Acme Corporation (Sample)

acme-corp-sample.com

Elevated

Risk score: 68 / 100

Passive reconnaissance identified 14 subdomains, 3 exposed services, and 5 attack surface findings. Several legacy systems remain internet-facing and should be reviewed for removal or hardening.

Subdomains (8 of 14 shown)

• www.acme-corp-sample.com

• mail.acme-corp-sample.com

• vpn.acme-corp-sample.com

• api.acme-corp-sample.com

• staging.acme-corp-sample.com

• dev.acme-corp-sample.com

• portal.acme-corp-sample.com

• remote.acme-corp-sample.com

Exposed services

HTTPS (443) — vpn.acme-corp-sample.comSSL VPN portal exposed to the internet. Outdated TLS configuration detected.Medium
RDP (3389) — remote.acme-corp-sample.comRemote Desktop Protocol directly exposed. Should be behind ZTNA / PRA.High
SMTP (25) — mail.acme-corp-sample.comOpen mail relay configuration detected.Low

SSL certificates

• acme-corp-sample.com — Let's Encrypt · expires 2026-11-15

• vpn.acme-corp-sample.com — DigiCert · expires 2026-09-02

Cloud & hosting

• AWS (us-east-1), Cloudflare (CDN/DNS), Google Workspace (MX)

Technologies

• Microsoft IIS, nginx, WordPress, jQuery, PHP

Findings

RDP exposed to the internetRemote Desktop Protocol on remote.acme-corp-sample.com is directly accessible. Recommend replacing with Zscaler Private Access (ZPA) or Privileged Access (PRA).High
Outdated SSL VPN portalThe VPN portal at vpn.acme-corp-sample.com appears to run an older firmware version.Medium
Staging environment publicly accessiblestaging.acme-corp-sample.com is indexed and exposes internal-style content.Medium
DNS zone exposes internal hostnamesSubdomain enumeration revealed internal naming conventions.Low
CMS version detectedWordPress detected on www.acme-corp-sample.com.Info

Recommendations

  1. 1. Replace exposed RDP with Zscaler Privileged Access (PRA) to eliminate direct internet exposure.
  2. 2. Migrate SSL VPN to Zscaler Private Access (ZPA) for zero-trust application access.
  3. 3. Restrict the staging environment to authenticated internal users only.
  4. 4. Enable automatic patching for all internet-facing CMS and server software.
  5. 5. Review and reduce DNS exposure of internal hostnames.

Generated by Velocity Cyber. Passive, non-intrusive analysis based on publicly available data. For informational purposes only — not a penetration test or active scan. This is a SAMPLE report with fictional data for demonstration purposes only.

Disclaimer & Limitations

These tools perform passive, non-intrusive analysis using publicly available data sources and AI-assisted research. They are provided as a complimentary pre-sales resource for informational purposes only and do not constitute a comprehensive security assessment, penetration test, audit, or professional advice. Results may not identify all subdomains, exposed services, credentials, breaches, or dark web exposures associated with your domain. Findings should be validated through a paid engagement before acting on them. Velocity Cyber and its partners assume no liability for decisions made or actions taken based on these reports. By using these tools you confirm you are authorized to analyze the submitted domain and accept these terms.