oolak / Features / Attack surface
Attack surface

See your organisation the way an attacker does.

oolak finds the domains, host names, IP addresses, certificates and services that anyone on the internet can reach. Each one is linked to its owner, so a forgotten test server becomes a task for someone instead of an open door.

Everything visible from the internet, with its owner.

Find what was forgotten

Old subdomains, test servers and shadow IT come to light before an attacker finds them.

Catch risky mistakes

Dangling DNS records, internal addresses in public DNS and missing e-mail protection are reported as findings.

Never miss an expiry

Certificates and domains trigger a warning 30, 15 and 7 days before they expire.

Attack surface

What's included

  • You confirm the root domains and IP ranges that belong to you, and oolak keeps third parties apart.
  • Discovery uses certificate transparency logs, DNS, RDAP, subfinder, dnsx and httpx.
  • Shodan and Censys show which of your services are visible on the internet.
  • Cloudflare and Route53 DNS zones are read directly.
  • Active checks such as subdomain guessing and zone transfer tests run only after approval.
  • Subdomain takeover risks are verified, not just guessed.
  • Leaked e-mail accounts are watched through breach and threat intelligence feeds.
  • Tenable ASM and Microsoft Defender EASM results come into the same view.
  • Every record keeps evidence of where it was found.
  • Exposures follow the same life cycle as vulnerabilities, from open to verified.

See oolak on your own data in 14 days.

We install oolak in your environment, connect your tools and show you your real risk picture. You keep everything it finds.

Start a free 14-day trial → Try the live demo
For engineers

Technical details

What counts as an exposure?
Examples are dangling CNAME records, internal IP addresses published in DNS, missing SPF or DMARC records, expiring certificates and domains, and risky services that are open to the internet on assets you own.
How is scope decided?
Confirmed root domains and public IP ranges define what is yours. Suggested seeds come from the names your own scanners resolved. A more specific rejected domain can carve a name out of a broader confirmed one, and vendor names on factory certificates are kept as third party.
Does active discovery run on its own?
No. Brute-force subdomain discovery and zone transfer checks are requested, approved by someone other than the requester and only then run by a worker. They are never part of a routine sync.