# Attack Surface

> Maps every entry point, component, and trust boundary of a target before testing begins prevents missed coverage and prioritizes the highest-value attack paths. Trigger when the user provides a target and wants to know where to start, says "map the attack surface", "what should I test", or "where do I begin", or is starting any engagement after scope-grill is complete.

- Skill: `rifteo/attack-surface` (Agent Skill, multi-file: 3 files)
- Install (CLI): `npx skillmds@latest add rifteo/attack-surface`
- Raw SKILL.md: https://api.skillmd.com/api/skills/rifteo/attack-surface/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Web & Frontend
- License: MIT
- Author: Rifteo (https://skillmd.com/u/rifteo)
- Updated: 2026-09-22
- Page: https://skillmd.com/skills/rifteo/attack-surface

---


# Attack Surface Mapper

Before testing individual vulnerabilities, map the full attack surface. Untested components are unfound vulnerabilities. This skill produces a structured map that drives testing coverage.

## Process

### Phase 1 — Enumerate Entry Points

Systematically identify every place an attacker could interact with the target:

- **Web** — domains, subdomains, ports 80/443, login pages, API endpoints, file upload, search, export
- **APIs** — REST, GraphQL, SOAP, WebSocket, mobile API backends
- **Auth flows** — login, registration, password reset, OAuth/SSO, MFA bypass paths
- **Network** — open ports, admin interfaces (SSH, RDP, Telnet), VPNs, exposed management panels
- **Cloud** — S3 buckets, blob storage, exposed functions/lambdas, public AMIs, metadata endpoints
- **Third-party integrations** — webhooks, OAuth providers, embedded iframes, CDN-served content
- **Client-side** — JavaScript source, local storage, service workers, postMessage handlers

### Phase 2 — Identify Trust Boundaries

Mark where the system transitions between trust levels:
- Unauthenticated → authenticated
- User role → admin role
- External network → internal network
- Client-controlled input → server-side processing

### Phase 3 — Tech Stack Fingerprint

For each component, note:
- Language / framework
- Version (if visible)
- Authentication mechanism
- Known CVEs for the version (run `check-exploit` skill on identified versions)

### Phase 4 — Prioritize

Rank attack paths by value. See `references/priority-matrix.md`.

## Output Format

Produce a **Surface Map** table:

| Component | Type | Auth Required | Tech Stack | Priority | Notes |
|---|---|---|---|---|---|
| `/api/v2/users` | REST API | Bearer token | Node.js/Express | High | Returns PII |
| `admin.target.com` | Web app | Basic auth | Apache/PHP | Critical | Exposed to internet |

Follow with a **Recommended Testing Order** — ordered list of highest-value targets first.

## Rules

- Do not start testing until Phase 1 is complete — partial maps lead to missed coverage
- If the scope is large, timebox Phase 1 and note what was not mapped
- Reference `check-exploit` for every identified technology version

