Research note ·
How to read a public exposure snapshot
Introductory note based on existing public WitnessOps product boundaries. No new target was checked for this article.
What did the check establish?
A public hostname can return useful evidence without supporting a conclusion about the security of the whole company. The free External Exposure Snapshot covers ten defined observations against one submitted hostname at a recorded time.
Start with the named results: what needs attention, what was observed as expected, and what could not be determined. Collection completeness describes how much was observed. It is not a security grade.
Read the observation before the conclusion
A missing response header is an observation under a bounded method, not evidence that an application is exploitable. A timeout leaves an unknown; it does not establish a vulnerability. An expected response does not establish that the hostname is secure.
Needs-attention findings have no assigned security severity in the free snapshot. Informational observations remain visible without being promoted to vulnerabilities.
Method and evidence
The application server performs bounded DNS, TLS and HTTP observations. TCP connections are restricted to public addresses on ports 80 and 443. The checks cover public resolution, certificate state, legacy TLS, the HTTP-to-HTTPS transition, HSTS, browser headers, security.txt, SPF, DMARC and CAA.
Use the report to read the methods, evidence references and limitations together. The source JSON records the observations and request ledger. A request attempt is not a collected response. File hashes support integrity comparisons; they do not authenticate the observations or establish source-system truth. The free snapshot is unsigned.
Limitations and unknowns
This is not a penetration test, complete attack-surface assessment, certification, compliance assessment or assurance opinion. It does not test authenticated functions, exploit vulnerabilities, inspect internal infrastructure or discover every subdomain. Public conditions can change after collection.
A deeper human-reviewed investigation requires an agreed scope and authorization. It is separate from simply running more automated checks.
Sources and next steps
- External Exposure Snapshot: the ten-check workflow and its scope
- External Attack Surface Review synthetic worked example — illustrative material, not a live customer assessment.
- External Attack Surface Review: authorized human-reviewed work
To inspect your own hostname, open the free check. Only check a hostname you own or are authorized to check.