Skip to main content
OSINT platform

YekIntel

A company's externally visible attack surface, gathered from public sources and rated.

One organisation and the assets visible from outside Names and certificates, reachable services, cloud storage and code, remote access, with the links between them. Six carry a finding: an API with a published CVE, a VPN whose vulnerability is in the known-exploited catalogue, a public bucket, an exposed administration interface, a database reachable without authentication, a forgotten test host. WEBSHOP API CVE SUBDOMAINS TESTSYSTEM FORGOTTEN CODE REPO MOBILE APP CLOUD STORE PUBLIC ADMIN UI EXPOSED DATABASE NO AUTH RDP VPN KEV LISTED MAIL TLS CERT DNS ORG NAME · CERT SERVICE CLOUD · CODE REMOTE FINDING YEKINTEL · EXTERNAL ASSETS FROM PUBLIC SOURCES, RATED

Domains, subdomains, cloud services, repositories, forgotten test systems, remote access into the plant: what can be seen of a company from outside has grown over years. All of it is public, little of it is ever put together.

The attacker side

An attack starts with a query

The attacker side: a query, not a target An attacker filters an index of the reachable internet by port, banner and missing authentication. No company name is part of the query. Every host that fits the pattern comes back, and one of them belongs to the reader. QUERY RUNS CONTINUOUSLY PORT 8080 · BANNER CONTAINS <VERSION> AUTH = NONE · ORG = ANY MATCHES YOUR HOST ONE QUERY · EVERY HOST THAT FITS THE PATTERN

A service goes online, an access stays open, a storage area is readable by anyone. Nobody decided any of it; it happened all the same. And it gets found: the reachable internet is indexed continuously, and whoever looks for a weakness does not look at one company but searches an index for everyone a pattern fits. That part of an attack is automated, and it costs the attacker minutes.

That same surface never stands still. A team puts a test environment online, a certificate expires, a supplier creates a subdomain. None of it appears in a report that is six months old. The gap between accidentally exposed and findable from outside is therefore shorter than the gap between two audits, which makes an analysis that repeats with the same procedure worth more than a thorough one that runs once.

YekIntel turns the direction of view around. The platform works out that same external surface automatically, from the same publicly available information, and rates it: one domain is enough as input. Every run follows the same procedure, so two states can be compared.

Threat picture

What is visible gets found

Four findings that come up regularly.

Systems nobody has on a list any more

A test environment from an old project, a subdomain from a supplier, a legacy system that stayed online after the migration. They are not patched, because they are in no inventory; they are reachable all the same.

Certificates and configurations that have run out

An expired certificate is rarely just a browser error; usually it means nobody owns the service any more. The same goes for weak signature algorithms and mail records that leave a sender address unprotected.

Credentials from somebody else's breach

Company addresses turn up in collections from third-party breaches, often with a password. Where the same password was used twice, a login leads into the network without any exploit.

Access sitting in the open

A VPN portal, an administration interface, a remote maintenance entry: what is meant for internal use regularly sits in the open network, through rules drawn too wide. Whoever finds it often needs no exploit, only a password.

Scope

What the analysis collects

One domain is enough as input. What comes out of it sorts into four groups:

  • Names and networks. Subdomains, assigned address and network ranges, mail and DNS configuration.
  • Services and systems. Open standard ports, HTTP headers, TLS certificates with validity and signature algorithm, services meant for internal networks.
  • Cloud and code. Publicly readable storage, public repositories along with the projects attached to them, published apps in the app stores.
  • Addresses and breaches. Publicly findable company addresses and their match against known breaches.

The difference is not any single place a thing is found but that the results meet at one object instead of in four exports.

Next step

One domain is enough.

Enter the domain whose external surface you want to see. The second step asks for the address the results go to. We check the details and come back to you before anything runs.

Eine Domain genügt, zum Beispiel ihre-firma.de. Ohne https:// und ohne Pfad.
Trusted by