Easm Review Attack Surface

by zscaler809f68d6c921No licenseListed Oct 8, 2026Updated Oct 8, 2026

Review the organization's external attack surface using Zscaler EASM. Lists organizations, retrieves findings (exposed services, vulnerabilities, misconfigurations), checks for lookalike domains, and generates a prioritized risk summary. Use when a security team asks: 'What is our external exposure?', 'Are there any critical findings?', or 'Check for lookalike domains.'

Instructions onlySecurity
AI-generated overview

Reviews an organization's external attack surface via Zscaler EASM, prioritizing findings and lookalike domains into a risk report.

What it does
This skill walks through a five-step workflow for reviewing external exposure using Zscaler EASM tools: listing monitored organizations, retrieving findings such as exposed services, vulnerabilities and misconfigurations, and checking for lookalike domains tied to phishing or brand impersonation. It groups findings into Critical, High, Medium and Low/Informational tiers and produces a prioritized external attack surface review report with assets, evidence, risk and remediation notes. It also covers edge cases such as no findings or a high volume of findings, offering filters by severity, type, asset or time range.
When to use it
Use it when a security team asks what the organization's external exposure is, whether there are critical findings, or whether lookalike domains exist. It fits periodic external posture reviews, investigation of specific findings, and phishing-indicator checks on domains resembling the organization's own.
Requirements
Requires access to Zscaler EASM tooling (organization listing, findings, finding details, evidence, scan output, and lookalike domain tools) and a monitored organization ID. It ships no scripts; it is instructions only.

EASM: Review Attack Surface

Keywords

attack surface, external exposure, easm findings, exposed services, vulnerabilities, lookalike domains, external risk, shadow IT discovery, internet-facing assets, security posture, easm audit

Overview

Review the organization's external attack surface by retrieving EASM findings, analyzing exposed services and vulnerabilities, checking for lookalike domains (phishing indicators), and generating a prioritized risk report. EASM provides visibility into internet-facing assets that may not be known to the security team.

Use this skill when: A security administrator wants to review the organization's external exposure, check for new findings, investigate specific vulnerabilities, or detect lookalike domains used for phishing.


Workflow

Follow this 5-step process to review the external attack surface.

Step 1: List EASM Organizations

text
zeasm_list_organizations()```text
EASM can monitor multiple organizations or business units. Note:
- Organization ID and name- Monitored domains/assets- Last scan date
If multiple organizations exist, confirm which one to review.
---
### Step 2: Retrieve Findings
```textzeasm_list_findings(organization_id="<org_id>")```text
This returns all findings across the attack surface. Each finding includes:
- Finding type (exposed service, vulnerability, misconfiguration, certificate issue)- Severity (Critical, High, Medium, Low, Informational)- Asset affected (domain, IP, subdomain)- Discovery date- Current status
**For detailed information on a specific finding:**
```textzeasm_get_finding_details(organization_id="<org_id>", finding_id="<finding_id>")```text
**For scan evidence:**
```textzeasm_get_finding_evidence(organization_id="<org_id>", finding_id="<finding_id>")```text
**For complete scan output:**
```textzeasm_get_finding_scan_output(organization_id="<org_id>", finding_id="<finding_id>")```text
---
### Step 3: Check for Lookalike Domains
```textzeasm_list_lookalike_domains(organization_id="<org_id>")```text
Lookalike domains are domains registered by third parties that resemble your organization's domains. They are commonly used for:
- Phishing campaigns- Brand impersonation- Credential harvesting
**For details on a specific lookalike domain:**
```textzeasm_get_lookalike_domain(organization_id="<org_id>", domain_id="<domain_id>")```text
Check:
- Similarity score to your actual domain- Registration date (recent registrations are higher risk)- Whether the domain is actively hosting content- DNS records (MX records suggest email phishing)
---
### Step 4: Categorize and Prioritize
Group findings by severity and type:
**CRITICAL:**
- Exposed databases (MongoDB, Elasticsearch, Redis without auth)- Known CVEs with active exploitation (CISA KEV)- Exposed admin panels (phpMyAdmin, Jenkins, Kubernetes dashboard)- Default credentials detected
**HIGH:**
- SSL/TLS misconfigurations (expired certs, weak ciphers)- Exposed development/staging environments- Open mail relays- Unpatched services with known CVEs
**MEDIUM:**
- Missing security headers (HSTS, CSP, X-Frame-Options)- Directory listing enabled- CORS misconfigurations- Subdomains pointing to unclaimed resources (subdomain takeover risk)
**LOW/INFORMATIONAL:**
- Technology fingerprinting (web server versions)- DNS zone transfer possible- Informational banners exposed
---
### Step 5: Generate Report
```textExternal Attack Surface Review================================Date: <current_date>Organization: <org_name>
## Executive Summary
- Total findings: X- Critical: X | High: X | Medium: X | Low: X- Lookalike domains detected: X- New findings (last 7 days): X
---
## Critical Findings (Immediate Action Required)
### 1. Exposed MongoDB Instance- **Asset:** db-backup.company.com:27017- **Type:** Exposed Database- **Discovered:** 3 days ago- **Risk:** Unauthenticated access to database. Data exfiltration possible.- **Evidence:** Port 27017 open, MongoDB banner detected, no auth required- **Remediation:** Restrict access via firewall rules. Enable authentication.
### 2. CVE-2024-XXXXX on api.company.com- **Asset:** api.company.com- **Type:** Known Vulnerability- **CVSS:** 9.8- **Discovered:** 1 week ago- **Risk:** Remote code execution. Actively exploited in the wild.- **Evidence:** Service version detected: Apache/2.4.49 (vulnerable)- **Remediation:** Patch immediately to version 2.4.54+.
---
## High Findings
### 3. Expired SSL Certificate- **Asset:** portal.company.com- **Type:** Certificate Issue- **Discovered:** 2 days ago- **Risk:** Users see browser warnings. MITM attack possible.- **Remediation:** Renew certificate immediately.
---
## Lookalike Domains (X detected)
| Domain              | Similarity | Registered | Active | MX Records | Risk  ||--------------------|-----------|-----------|--------|-----------|-------|| companny.com       | 95%       | 2 days ago | Yes    | Yes       | HIGH  || company-login.net  | 87%       | 1 week ago | Yes    | No        | HIGH  || c0mpany.com        | 82%       | 3 months  | No     | No        | MEDIUM|
**companny.com** is actively hosting content and has MX records configured,suggesting an active phishing campaign. Recommend:1. Submit to Zscaler URL category as "Phishing"2. Report to domain registrar for takedown3. Alert users via security awareness notification
---
## Recommendations (Priority Order)
1. [CRITICAL] Secure exposed MongoDB instance immediately2. [CRITICAL] Patch Apache on api.company.com3. [HIGH] Renew SSL certificate for portal.company.com4. [HIGH] Investigate and report lookalike domain companny.com5. [MEDIUM] Add security headers to all web applications6. [LOW] Remove server version banners```text
---
## Edge Cases
### No Findings
```textNo findings detected for organization "<org_name>".
This means:- The external attack surface appears clean as of the last scan- OR EASM monitoring scope may need to be expanded
Recommendation: Verify all known domains and IP ranges are includedin the EASM monitoring scope.```text
### High Volume of Findings
If there are hundreds of findings:
```textLarge number of findings detected (X total). Showing top 10 by severity.
For a focused review, I can filter by:1. Severity level (Critical/High only)2. Finding type (e.g., only exposed services)3. Specific asset or subdomain4. Time range (e.g., last 7 days only)
Which filter would you like to apply?```text
---
## Quick Reference
**Primary workflow:** List Orgs → Retrieve Findings → Check Lookalikes → Categorize → Report
**Tools used:**
- `zeasm_list_organizations()` -- list monitored organizations- `zeasm_list_findings(organization_id)` -- all findings- `zeasm_get_finding_details(organization_id, finding_id)` -- finding details- `zeasm_get_finding_evidence(organization_id, finding_id)` -- scan evidence- `zeasm_get_finding_scan_output(organization_id, finding_id)` -- full scan output- `zeasm_list_lookalike_domains(organization_id)` -- lookalike domains- `zeasm_get_lookalike_domain(organization_id, domain_id)` -- domain details
**Severity classification:**
- CRITICAL: Exposed databases, active CVEs, admin panels- HIGH: SSL issues, exposed dev environments, unpatched services- MEDIUM: Missing headers, CORS issues, subdomain takeover risk- LOW: Version banners, informational findings

Source and attribution

Source:zscaler/zscaler-mcp-serverinskills/easm/review-attack-surfaceat commit809f68d

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

More from zscaler/zscaler-mcp-server

Zpa Troubleshoot App Connector

zscaler

Troubleshoot ZPA App Connector issues including enrollment failures, upgrade problems, Public Service Edge connectivity, and high CPU/memory/disk utilization. Uses MCP tools to inspect connector groups, provisioning keys, server groups, and application segments, then provides runbook-guided remediation steps. Use when an administrator reports 'connector is down', 'connector not enrolling', 'connector upgrade failed', or 'connector high CPU.'

Awaiting classificationOct 8, 2026

Zpa Create Timeout Policy Rule

zscaler

Create ZPA timeout policy rules that control session re-authentication and idle timeout behavior. Configures how long a user session remains active (reauth_timeout) and how long an idle session persists (reauth_idle_timeout) before requiring re-authentication. Supports conditions: APP, APP_GROUP, CLIENT_TYPE, SAML, SCIM, SCIM_GROUP, PLATFORM, and POSTURE. Use when an administrator asks: 'Set session timeout', 'Configure idle timeout', 'Require re-authentication after X hours', or 'Set different timeouts per app or user group.'

Awaiting classificationOct 8, 2026

Zpa Create Session Duration Rule

zscaler

Create a ZPA Timeout Policy rule that enforces session duration — i.e. forces re-authentication after N minutes/hours/days, optionally with an idle-timeout. Use this skill when an admin asks for 'session duration', 'auto-revoke', 're-authentication interval', 'force re-auth after X hours', or 'session must expire after a workday' for ZPA. Scopes by SCIM group, SAML attribute, application segment, platform, and posture. ZPA Timeout Policy is a separate resource type from Access Policy; this skill creates timeout rules only and does not modify or pair with access rules.

Awaiting classificationOct 8, 2026

Zpa Create Server Group

zscaler

Create a ZPA server group with all required dependencies. Server groups require app connector groups to exist first. This skill walks through the dependency chain: (1) Check for existing app connector groups, (2) Create an app connector group if none exist, (3) Create the server group referencing the connector group IDs, (4) Verify the server group was created correctly. Use when an administrator needs to set up a new server group for application access.

Awaiting classificationOct 8, 2026

Zpa Create Forwarding Policy Rule

zscaler

Creates ZPA client forwarding policy rules that control how Zscaler Client Connector traffic is routed.

DevOps & CloudOct 8, 2026

Zpa Create Conditional Access Rule

zscaler

Builds a ZPA conditional access policy rule combining identity, posture, platform, country and risk checks.

SecurityOct 8, 2026