Skip to Content

Insights

The Insights view provides a high-level understanding of your external attack surface based on everything Surface Monitoring has discovered. Use Insights to assess the breadth and composition of your infrastructure, identify trends, and prioritize security efforts.

Asset Overview

The asset overview shows the total count and breakdown of discovered assets across your monitored root domains. Assets are categorized by type:

  • Domains and subdomains — All discovered DNS names associated with your root domains
  • IP addresses — IPv4 and IPv6 addresses resolved from your domains or imported via cloud connectors
  • Ports and services — Open ports detected on your IP addresses, with service identification where possible

Each asset type links to a detailed view where you can inspect individual assets, their relationships, and their assessment history.

Domain Intelligence

The domain view provides details about each discovered domain and subdomain, including:

  • DNS records: A, AAAA, CNAME, MX, NS, TXT, and SRV records associated with the domain
  • Resolution history: How the domain’s DNS records have changed over time
  • Associated IP addresses: Current and historical IP resolutions
  • SSL/TLS certificates: Certificate details, expiration dates, and chain validity
  • Hosting information: Where the domain is hosted based on IP address and WHOIS data

Domain Status

Domains can be in one of several states:

  • Monitored: Actively scanned and assessed on regular schedules
  • Unmonitored: Discovered but not actively assessed (typically subdomains outside your primary scope)
  • Inactive: Previously discovered but no longer resolving in DNS

Technology Inventory

Surface Monitoring maintains a technology inventory based on fingerprinting results across all your assets. The technology view shows:

  • All detected technologies grouped by category (web servers, frameworks, CMS, libraries, analytics)
  • Version information where detectable, helping you identify outdated or vulnerable versions
  • Asset count showing how many of your assets run each technology
  • First and last seen dates indicating when a technology was detected and whether it is still in use

Using Technology Data

Technology insights help you answer questions like:

  • How many assets are running an end-of-life version of a framework?
  • Which assets use a library affected by a recently disclosed CVE?
  • Are teams following approved technology standards?
  • What is the most common web server across your infrastructure?

IP Address Intelligence

The IP address view shows all discovered IP addresses with enrichment data:

  • Geolocation: Country and region where the IP is hosted
  • ASN and hosting provider: The network operator and cloud provider
  • Associated domains: Which of your domains resolve to this IP
  • Open ports: Services detected on the IP address
  • Cloud provider mapping: Whether the IP belongs to a connected cloud account

Insights views support filtering to help you focus on specific segments of your attack surface:

  • Filter by root domain to scope results to a specific domain tree
  • Filter by technology to see all assets running a specific framework or library
  • Filter by hosting provider to view assets across a specific cloud environment
  • Filter by discovery date to focus on recently discovered assets

Exporting Data

Insights data can be exported for use in other tools and reporting workflows. Export options are available from each view and include CSV format for spreadsheet analysis and integration with asset management systems.

Next Steps

  • Policies — Create automated rules based on your insights
  • Results — Review vulnerability findings for your assets
  • Discovery — Understand how assets enter your inventory
Last updated on