SecurityBoat

Case Study

The attack surface nobody was watching — mapped, secured, taken down.

A regulated Indian BFSI enterprise knew its inventory spreadsheet was fiction. TriNetra ASM mapped the subdomains nobody had recorded, surfaced a pre-production admin portal facing the open internet, and DRP caught the credentials — and the phishing clone — circulating outside the walls.

Representative engagement — details anonymized

01

Challenge

Years of growth had outrun the asset register. Vendor-built microsites, campaign landing pages, dev and test environments stood up for release cycles and never torn down — the organization's real internet footprint had drifted far from the spreadsheet the security team inherited. For a BFSI enterprise answering to Indian regulators, “we don't know what we expose” isn't just a security gap; asset inventory and continuous monitoring are baseline expectations under the RBI cybersecurity framework.

And the risk didn't stop at their own infrastructure. Customers were reporting convincing phishing messages, and the fraud team had no systematic way to find look-alike domains or leaked staff credentials before they were used. Two blind spots, one consequence: the first person to find an exposure would be an attacker.

02

Solution

SecurityBoat onboarded the enterprise onto two TriNetra modules that watch in opposite directions — ASM at everything the organization exposes, DRP at everything the threat landscape aims back at it.

Scope, gated. Primary domains and IP ranges went into ASM through the client-request → staff-approval flow — no scan runs until scope is confirmed as theirs.

Continuous discovery, not a one-time audit. Comprehensive-mode scans on a recurring cadence, every scan diffed against the last so new, regressed, and resolved exposures are flagged automatically.

A DRP watchlist. Brand terms, domains, and product names configured as always-on monitors across paste sites, breach data, look-alike domain registrations, and phishing infrastructure — every detection landing as one of seven severity-scored alert categories with verifiable evidence attached.

Alerts where the team works. Critical and high findings routed to Slack and Jira, so exposures became tickets, not emails.

Subdomain Inventory

24 targets+ Scan ad-hoc
SubdomainClassScanRisk
assets.netbanking.aecm-corp.comLive · 200cloudComplete20
dev.payments.aecm-corp.comLive · 200devComplete45
api.shop.aecm-corp.comLive · 200apiComplete65
mail.payments.aecm-corp.comLive · 200infraComplete30
admin.payments.aecm-corp.comLive · 200adminComplete90
staging.aecm-corp.comLive · 200webComplete40
vpn.partner.aecm-corp.comLive · 200infraComplete70

03

Methodology

ASM: the scan pipeline. Every scan advanced through TriNetra's 11-state pipeline, watchable live — Queued against approved scope; Setup with recon-toolchain pre-flight checks; Passive discovery building the subdomain and DNS inventory without touching infrastructure; Active probing of live hosts for status, ports, and technology fingerprints; Exposure checks for takeover-prone records, exposed secrets, weak TLS, exposed login portals, and CVE matches; Profiling, where the Surface Classifier tags every asset web / api / admin / dev / infra / cloud; Planning, where attack hypotheses are chained into CVSS v4.0-scored, confidence-rated paths — advisory only, never auto-exploited; and Complete, with the scan-over-scan drift diff and alert routing.

DRP: watchlist to takedown. Detections matched against the watchlist arrive as one of seven alert categories — Phishing Clone, Typosquat/New Domain, Financial Fraud, Ransomware Leak Site, Credential Leak, Fake Mobile App, Executive Impersonation — each carrying its evidence: matched domain, favicon hash, HTML-similarity score, DNS records. Actionable threats move across the takedown board — Detect → Validate → Action → Confirm — with days-in-stage visible on every card and re-emergence monitoring after closure.

04

Attack Lifecycle

This is the attack that never happened — the chain TriNetra surfaced and broke, step by step, before an adversary could assemble it.

  1. 01

    Step 1 — The unknown surface. The first Comprehensive scan expanded the live subdomain inventory well beyond the official register — vendor microsites, orphaned campaign pages, and forgotten environments, each carrying up/down status, environment classification, risk score, and first-seen tracking.

  2. 02

    Step 2 — The portal. Among them: a pre-production admin portal, tagged admin and dev by the Surface Classifier, flagged in the Exposures phase as an exposed login portal — internet-reachable, outside every hardening cycle, invisible to the team defending production.

  3. 03

    Step 3 — The credentials. A DRP Credential Leak alert surfaced staff credentials posted to a paste site. Running alongside the attack-surface scans, DRP correlated the leak with the organization's real exposed footprint — and the combination told the story plainly: leaked credentials plus an exposed pre-prod admin portal is a complete intrusion path, no exploit required. Underlying credential values stayed encrypted; the alert carried the breach evidence, not the secrets.

  4. 04

    Step 4 — The clone. A Phishing Clone alert fired on a look-alike domain serving the brand's byte-identical favicon with a high HTML-similarity score against the customer login page — evidence attached: both domains, favicon hash, similarity score, DNS records.

  5. 05

    Step 5 — Breaking the chain. The portal was pulled off the public internet and the leaked credentials rotated — the next scan's drift diff confirmed the exposure resolved, not just claimed fixed. The phishing clone entered the takedown board and moved Detect → Validate → Action → Confirm through to verified removal, with the domain added to the blocklist export and re-emergence monitoring watching for the same actor to try again.

Client Testimonial

Client quote pending approval.

A named client quote is published only after client sign-off.

On the record

A real inventory, finally.

Coverage and freshness tracked against defined scope — every asset classified, risk-scored, and on a monitoring cadence. Not a spreadsheet.

0targets
Exposure posture

Watching 10 of 12 targets · 0 open findings

2 At RiskView latest scan →

06

Key Outcomes

01

A real inventory, finally. A live, self-updating subdomain inventory replaced the spreadsheet — every asset classified, risk-scored, and on a monitoring cadence with coverage and freshness tracked against defined scope.

02

The intrusion path closed before it opened. Exposed pre-prod admin portal secured, leaked credentials rotated, and both confirmed resolved by the next scan's drift diff — not by assumption.

03

A phishing clone gone, verifiably. Detect → Validate → Action → Confirm, with evidence at every stage and re-emergence monitoring still standing watch after removal.

04

Regulator-ready posture. Continuous discovery and monitoring evidence that supports RBI cybersecurity framework expectations around asset inventory and continuous surveillance — generated by watching, not by scrambling before an audit.

05

Two directions, one picture. ASM watching what the organization exposes, DRP watching what the landscape aims back — correlated, so a leak outside the walls is read against the real footprint inside them.

Ready when you are

What does your organization expose that nobody's watching?

Give SecurityBoat your domains and brand terms. TriNetra ASM and DRP will show you the footprint you actually have — and what's already circulating outside it — within days.