Map your entire external footprint — passively.
Subdomains, exposed services, open doors an attacker would walk through — we map your external footprint passively, silently, without touching your network, so you can close gaps before someone else finds them.
External Attack Surface Report
Velocity Cyber
Acme Corporation (Sample)
acme-corp-sample.com
Elevated
Risk score: 68 / 100
Passive reconnaissance identified 14 subdomains, 3 exposed services, and 5 attack surface findings. Several legacy systems remain internet-facing and should be reviewed for removal or hardening.
Subdomains (8 of 14 shown)
• www.acme-corp-sample.com
• mail.acme-corp-sample.com
• vpn.acme-corp-sample.com
• api.acme-corp-sample.com
• staging.acme-corp-sample.com
• dev.acme-corp-sample.com
• portal.acme-corp-sample.com
• remote.acme-corp-sample.com
Exposed services
SSL certificates
• acme-corp-sample.com — Let's Encrypt · expires 2026-11-15
• vpn.acme-corp-sample.com — DigiCert · expires 2026-09-02
Cloud & hosting
• AWS (us-east-1), Cloudflare (CDN/DNS), Google Workspace (MX)
Technologies
• Microsoft IIS, nginx, WordPress, jQuery, PHP
Findings
Recommendations
- 1. Replace exposed RDP with Zscaler Privileged Access (PRA) to eliminate direct internet exposure.
- 2. Migrate SSL VPN to Zscaler Private Access (ZPA) for zero-trust application access.
- 3. Restrict the staging environment to authenticated internal users only.
- 4. Enable automatic patching for all internet-facing CMS and server software.
- 5. Review and reduce DNS exposure of internal hostnames.
Generated by Velocity Cyber. Passive, non-intrusive analysis based on publicly available data. For informational purposes only — not a penetration test or active scan. This is a SAMPLE report with fictional data for demonstration purposes only.
Disclaimer & Limitations
These tools perform passive, non-intrusive analysis using publicly available data sources and AI-assisted research. They are provided as a complimentary pre-sales resource for informational purposes only and do not constitute a comprehensive security assessment, penetration test, audit, or professional advice. Results may not identify all subdomains, exposed services, credentials, breaches, or dark web exposures associated with your domain. Findings should be validated through a paid engagement before acting on them. Velocity Cyber and its partners assume no liability for decisions made or actions taken based on these reports. By using these tools you confirm you are authorized to analyze the submitted domain and accept these terms.