Easm Review Attack Surface

作者 zscaler809f68d6c921无许可证收录于 2026年10月8日更新于 2026年10月8日

Review the organization's external attack surface using Zscaler EASM. Lists organizations, retrieves findings (exposed services, vulnerabilities, misconfigurations), checks for lookalike domains, and generates a prioritized risk summary. Use when a security team asks: 'What is our external exposure?', 'Are there any critical findings?', or 'Check for lookalike domains.'

仅含说明Security
AI 生成的概览

通过 Zscaler EASM 审查组织的外部攻击面,将发现项与仿冒域名整理为按优先级排序的风险报告。

功能
该技能给出一个五步工作流,使用 Zscaler EASM 工具审查外部暴露情况:列出受监控的组织、获取暴露服务、漏洞与错误配置等发现项,并检查与钓鱼或品牌仿冒相关的仿冒域名。它把发现项划分为严重、高、中、低/信息四个等级,并生成按优先级排序的外部攻击面审查报告,包含资产、证据、风险与修复建议。它还处理无发现项或发现项数量过多等边界情况,可按严重程度、类型、资产或时间范围筛选。
适用场景
当安全团队询问组织的外部暴露情况、是否存在严重发现项,或是否存在仿冒域名时使用。适用于定期的外部安全态势审查、针对特定发现项的调查,以及针对与组织域名相似域名的钓鱼指标检查。
运行要求
需要访问 Zscaler EASM 工具(组织列表、发现项、发现项详情、证据、扫描输出以及仿冒域名工具)以及受监控的组织 ID。该技能不附带脚本,仅为说明文档。

EASM: Review Attack Surface

Keywords

attack surface, external exposure, easm findings, exposed services, vulnerabilities, lookalike domains, external risk, shadow IT discovery, internet-facing assets, security posture, easm audit

Overview

Review the organization's external attack surface by retrieving EASM findings, analyzing exposed services and vulnerabilities, checking for lookalike domains (phishing indicators), and generating a prioritized risk report. EASM provides visibility into internet-facing assets that may not be known to the security team.

Use this skill when: A security administrator wants to review the organization's external exposure, check for new findings, investigate specific vulnerabilities, or detect lookalike domains used for phishing.


Workflow

Follow this 5-step process to review the external attack surface.

Step 1: List EASM Organizations

text
zeasm_list_organizations()```text
EASM can monitor multiple organizations or business units. Note:
- Organization ID and name- Monitored domains/assets- Last scan date
If multiple organizations exist, confirm which one to review.
---
### Step 2: Retrieve Findings
```textzeasm_list_findings(organization_id="<org_id>")```text
This returns all findings across the attack surface. Each finding includes:
- Finding type (exposed service, vulnerability, misconfiguration, certificate issue)- Severity (Critical, High, Medium, Low, Informational)- Asset affected (domain, IP, subdomain)- Discovery date- Current status
**For detailed information on a specific finding:**
```textzeasm_get_finding_details(organization_id="<org_id>", finding_id="<finding_id>")```text
**For scan evidence:**
```textzeasm_get_finding_evidence(organization_id="<org_id>", finding_id="<finding_id>")```text
**For complete scan output:**
```textzeasm_get_finding_scan_output(organization_id="<org_id>", finding_id="<finding_id>")```text
---
### Step 3: Check for Lookalike Domains
```textzeasm_list_lookalike_domains(organization_id="<org_id>")```text
Lookalike domains are domains registered by third parties that resemble your organization's domains. They are commonly used for:
- Phishing campaigns- Brand impersonation- Credential harvesting
**For details on a specific lookalike domain:**
```textzeasm_get_lookalike_domain(organization_id="<org_id>", domain_id="<domain_id>")```text
Check:
- Similarity score to your actual domain- Registration date (recent registrations are higher risk)- Whether the domain is actively hosting content- DNS records (MX records suggest email phishing)
---
### Step 4: Categorize and Prioritize
Group findings by severity and type:
**CRITICAL:**
- Exposed databases (MongoDB, Elasticsearch, Redis without auth)- Known CVEs with active exploitation (CISA KEV)- Exposed admin panels (phpMyAdmin, Jenkins, Kubernetes dashboard)- Default credentials detected
**HIGH:**
- SSL/TLS misconfigurations (expired certs, weak ciphers)- Exposed development/staging environments- Open mail relays- Unpatched services with known CVEs
**MEDIUM:**
- Missing security headers (HSTS, CSP, X-Frame-Options)- Directory listing enabled- CORS misconfigurations- Subdomains pointing to unclaimed resources (subdomain takeover risk)
**LOW/INFORMATIONAL:**
- Technology fingerprinting (web server versions)- DNS zone transfer possible- Informational banners exposed
---
### Step 5: Generate Report
```textExternal Attack Surface Review================================Date: <current_date>Organization: <org_name>
## Executive Summary
- Total findings: X- Critical: X | High: X | Medium: X | Low: X- Lookalike domains detected: X- New findings (last 7 days): X
---
## Critical Findings (Immediate Action Required)
### 1. Exposed MongoDB Instance- **Asset:** db-backup.company.com:27017- **Type:** Exposed Database- **Discovered:** 3 days ago- **Risk:** Unauthenticated access to database. Data exfiltration possible.- **Evidence:** Port 27017 open, MongoDB banner detected, no auth required- **Remediation:** Restrict access via firewall rules. Enable authentication.
### 2. CVE-2024-XXXXX on api.company.com- **Asset:** api.company.com- **Type:** Known Vulnerability- **CVSS:** 9.8- **Discovered:** 1 week ago- **Risk:** Remote code execution. Actively exploited in the wild.- **Evidence:** Service version detected: Apache/2.4.49 (vulnerable)- **Remediation:** Patch immediately to version 2.4.54+.
---
## High Findings
### 3. Expired SSL Certificate- **Asset:** portal.company.com- **Type:** Certificate Issue- **Discovered:** 2 days ago- **Risk:** Users see browser warnings. MITM attack possible.- **Remediation:** Renew certificate immediately.
---
## Lookalike Domains (X detected)
| Domain              | Similarity | Registered | Active | MX Records | Risk  ||--------------------|-----------|-----------|--------|-----------|-------|| companny.com       | 95%       | 2 days ago | Yes    | Yes       | HIGH  || company-login.net  | 87%       | 1 week ago | Yes    | No        | HIGH  || c0mpany.com        | 82%       | 3 months  | No     | No        | MEDIUM|
**companny.com** is actively hosting content and has MX records configured,suggesting an active phishing campaign. Recommend:1. Submit to Zscaler URL category as "Phishing"2. Report to domain registrar for takedown3. Alert users via security awareness notification
---
## Recommendations (Priority Order)
1. [CRITICAL] Secure exposed MongoDB instance immediately2. [CRITICAL] Patch Apache on api.company.com3. [HIGH] Renew SSL certificate for portal.company.com4. [HIGH] Investigate and report lookalike domain companny.com5. [MEDIUM] Add security headers to all web applications6. [LOW] Remove server version banners```text
---
## Edge Cases
### No Findings
```textNo findings detected for organization "<org_name>".
This means:- The external attack surface appears clean as of the last scan- OR EASM monitoring scope may need to be expanded
Recommendation: Verify all known domains and IP ranges are includedin the EASM monitoring scope.```text
### High Volume of Findings
If there are hundreds of findings:
```textLarge number of findings detected (X total). Showing top 10 by severity.
For a focused review, I can filter by:1. Severity level (Critical/High only)2. Finding type (e.g., only exposed services)3. Specific asset or subdomain4. Time range (e.g., last 7 days only)
Which filter would you like to apply?```text
---
## Quick Reference
**Primary workflow:** List Orgs → Retrieve Findings → Check Lookalikes → Categorize → Report
**Tools used:**
- `zeasm_list_organizations()` -- list monitored organizations- `zeasm_list_findings(organization_id)` -- all findings- `zeasm_get_finding_details(organization_id, finding_id)` -- finding details- `zeasm_get_finding_evidence(organization_id, finding_id)` -- scan evidence- `zeasm_get_finding_scan_output(organization_id, finding_id)` -- full scan output- `zeasm_list_lookalike_domains(organization_id)` -- lookalike domains- `zeasm_get_lookalike_domain(organization_id, domain_id)` -- domain details
**Severity classification:**
- CRITICAL: Exposed databases, active CVEs, admin panels- HIGH: SSL issues, exposed dev environments, unpatched services- MEDIUM: Missing headers, CORS issues, subdomain takeover risk- LOW: Version banners, informational findings

来源与署名

来源:zscaler/zscaler-mcp-server位于skills/easm/review-attack-surface提交809f68d

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架