sodejm/attack-surface-planner
Offline authorized-scope reconciliation and passive attack surface test planning.
Build a passive offline attack surface review plan from signed-off scope and pinned local exports.
Execute bounded active port, protocol, and TLS assessment with explicit scan vantage, rate limits, resumable checkpoints, and visible fingerprint uncertainty.
Assess databases (MySQL, Postgres, MSSQL, Oracle), NoSQL/document stores (MongoDB, CouchDB, Cassandra), caches (Redis, Memcached), and search/analytics engines (Elasticsearch, InfluxDB, Kibana, Splunk) with bounded query budgets, synthetic canary verification, cleanup receipts, and data privilege candidate routing.
Assess developer and runtime interfaces (Docker, Docker Registry, RMI, JDWP, Erlang EPMD, ADB, distcc, SVN, AJP, FastCGI) with execution effect classification, canary verification, cleanup receipts, and developer privilege candidate routing.
Assess DNS/mDNS, SNMP, NTP, discovery utilities, RPC, LDAP, and Kerberos service exposure with protocol-specific collectors, explicit authentication prerequisites, canary verification, and Active Directory attack-path handoff.
Assess legacy enterprise storage, hardware out-of-band management, network appliance interfaces, VPN tunneling, and proxy egress services (NDMP, iSCSI, IPMI, Cisco Smart Install, TACACS+, IKE, PPTP, SOCKS, Squid) with proxy egress restriction testing, non-destructive canary verification, cleanup receipts, and legacy privilege candidate routing.
Assess email services (SMTP, POP3, IMAP), chat (IRC), and message brokers/queues (AMQP/RabbitMQ, NATS, IBM MQ, Kafka, MQTT) with bounded message budgets, synthetic canary verification, cleanup receipts, and messaging privilege candidate routing.
Normalize passive asset telemetry, preserve multi-source evidence provenance, and reconcile scope quarantine.
Assess remote administration (SSH, Telnet, RDP, VNC, WinRM, X11), file sharing (SMB, NFS, FTP/TFTP, rsync, AFP), and printing services (LPD, IPP, Raw/JetDirect) with canary verification, cleanup receipts, legacy version tracking, and host privilege candidate routing.