Skip to main content
Use case · Discovery and attribution

Nobody registered it, and it is still answering.

“Marketing stood up a subdomain three years ago and pointed it at a service that no longer exists.”

Shadow IT is usually mundane: the subdomain marketing spun up for a campaign, the staging host that outlived the project it was built for, the cloud account somebody opened on a personal card at a company you later acquired. ShadowMap starts from the apex domains you already know you own and works inwards from outside, so what comes back is the estate as an attacker enumerates it, not the estate as it was last written down.

One apex domain
The only input a first scan needs
Two business days
From that input to a written snapshot of what was found
30–60%

More external assets found than were internally inventoried

Where an organisation lands inside the band is driven by how much has been acquired, how long the estate has existed and how centralised its DNS is. An internal inventory records what somebody remembered to add; an outside-in scan does not carry that constraint.

The structural gap

Why the register cannot see it

The register is accurate about everything in it. The gap is structural: an internal inventory can only ever contain what someone remembered to add to it.

Every asset in a register got there because a person decided it belonged there: a ticket was raised, a build pipeline registered it, an onboarding form was filled in. That is a reasonable system, and it fails in one predictable way: it has no entry for the things nobody thought to file. A campaign subdomain delegated to an agency. A staging host whose project closed while the machine kept running. A cloud account opened on a personal card by an engineer who has since left. An apex domain that arrived with a subsidiary and never reached the parent. None of these were hidden; they were never written down. From outside, that distinction does not matter: somebody enumerating your certificate transparency history does not consult your register first.

The contrast

What a register records, and what the internet answers

The same estate read two ways. The left column is what an internal inventory can know by construction; the right is what outside-in observation returns without asking anybody inside the organisation.

Asset classWhat the internal inventory hasWhat an outside-in view observesWhere it turns up first
Campaign and microsite subdomains Only the ones somebody raised a ticket for. DNS delegated to an agency leaves no internal record at all. Every name issued a publicly-trusted certificate, whether or not it still resolves to infrastructure you control. Attack Surface Management
Certificate transparency logs are public and append-only. A name issued for a six-week campaign in 2019 is still enumerable today. Your register is allowed to forget it; the log is not.
Staging, UAT and demo hosts Marked decommissioned when the project closed, which is a statement about the ticket, not about the machine. A live host, its technology stack, the services it exposes and whatever authentication it was never given. Attack Surface Management
Origin-server and virtual-host detection matters here: a pre-production host sitting behind the same edge as production is often reachable directly, and that is what makes it interesting to somebody else.
Domains registered outside procurement The corporate registrar account. Not the name a departing employee bought on a personal card for a launch. Registration, nameserver and hosting records for names carrying your brand, including ones you are no longer renewing. Domain Monitoring
A lapsed name that once served your content carries a risk a typosquat does not: it inherits your backlinks, and sometimes your old DNS records are still pointing at it.
Repositories, buckets and indexed documents The organisation-owned repositories. Not the personal account a contractor pushed a working copy to. Public code, exposed storage and indexed files attributed back to you by what is inside them, not by who owns the account. Data Exposure Monitoring
Credentials for a system you had not listed Nothing. A register cannot hold an account for an application it has no entry for. Stealer-log credentials naming a host, at which point the host itself becomes the discovery. Dark Web Monitoring
Here the exposure finds the asset. A credential for an internal tool nobody had registered is both an incident and an inventory update.

Campaign and microsite subdomains

What the internal inventory has
Only the ones somebody raised a ticket for. DNS delegated to an agency leaves no internal record at all.
What an outside-in view observes
Every name issued a publicly-trusted certificate, whether or not it still resolves to infrastructure you control.
Where it turns up first
Attack Surface Management

Certificate transparency logs are public and append-only. A name issued for a six-week campaign in 2019 is still enumerable today. Your register is allowed to forget it; the log is not.

Staging, UAT and demo hosts

What the internal inventory has
Marked decommissioned when the project closed, which is a statement about the ticket, not about the machine.
What an outside-in view observes
A live host, its technology stack, the services it exposes and whatever authentication it was never given.
Where it turns up first
Attack Surface Management

Origin-server and virtual-host detection matters here: a pre-production host sitting behind the same edge as production is often reachable directly, and that is what makes it interesting to somebody else.

Domains registered outside procurement

What the internal inventory has
The corporate registrar account. Not the name a departing employee bought on a personal card for a launch.
What an outside-in view observes
Registration, nameserver and hosting records for names carrying your brand, including ones you are no longer renewing.
Where it turns up first
Domain Monitoring

A lapsed name that once served your content carries a risk a typosquat does not: it inherits your backlinks, and sometimes your old DNS records are still pointing at it.

Repositories, buckets and indexed documents

What the internal inventory has
The organisation-owned repositories. Not the personal account a contractor pushed a working copy to.
What an outside-in view observes
Public code, exposed storage and indexed files attributed back to you by what is inside them, not by who owns the account.
Where it turns up first
Data Exposure Monitoring

Credentials for a system you had not listed

What the internal inventory has
Nothing. A register cannot hold an account for an application it has no entry for.
What an outside-in view observes
Stealer-log credentials naming a host, at which point the host itself becomes the discovery.
Where it turns up first
Dark Web Monitoring

Here the exposure finds the asset. A credential for an internal tool nobody had registered is both an incident and an inventory update.

The number

Where 30–60% comes from, and what it leaves out

A first-scan comparison, not a running statistic. Here is what was counted on each side of it, so you know what you are quoting if the figure reaches a board.

How the 30–60% band is arrived at As of August 2026
  • The denominator is the asset list the customer supplied at kick-off: whatever they treat as their inventory of record, in whatever form it arrived.
  • The numerator is internet-facing assets attributed to that organisation at the end of a first scan, starting only from apex domains the customer confirmed as theirs.
  • Attribution is confirmed before an asset counts. A host that merely shares an address range with something of yours is not yours.
  • The band is wide because the driver is organisational, not technical. Acquisitions, delegated DNS and decentralised marketing all move an organisation towards the top of it.

Deliberately excluded

  • Internal-only assets. This is an outside-in comparison, so anything unreachable from the internet is out of scope on both sides of the ratio.
  • Assets discovered after the first scan. Continuous discovery keeps adding, but later finds are not folded back into this figure.
  • Vendor-hosted assets the customer does not claim. Where an asset is disowned it leaves the numerator.

The sequence

From an unattributed host to a decision you can defend

Discovery is the first move, not the job. The order here is load-bearing: nothing can be validated before it has been attributed, and nothing should be attributed before a person has said out loud whether it is ours.

Three points of view

The same forgotten subdomain, read three ways

One host, described by the three parties who have an opinion about it. Each of them is working from different facts.

Worked example

promo.acmecorp.com: a campaign microsite, live since 2021

What the marketing team knows
The campaign ended years ago and the agency that built the site was paid and offboarded. As far as anyone in the team is concerned it is gone, because nothing has linked to it since the quarter it ran.
What the security team knows
Nothing. The host is not in the register, so it is not in the scanning scope, so it has never appeared in a report. There is no finding to miss, because as far as the programme is concerned there is no asset.
What is actually true
The DNS record still resolves. The host still answers on 443, running a content management system three major versions behind, and its administrative login still accepts the shared credential the agency was handed in 2021.

Where this bites hardest

The same gap takes a different shape by sector

Unregistered estate is universal; what produces it varies by sector. Knowing which pattern applies to you tells you where a first scan will spend its time.

SectorWhat produces the unregistered estateWhere a first scan usually finds it
Banking and financial services A long tail of campaign microsites, regional portals and customer-facing applications that were superseded but never formally retired. Old customer-facing hostnames still resolving, and subdomains delegated to marketing agencies years ago.
The regulatory framing sharpens this one. An inspection asks what is exposed and by when it will be fixed, and an asset nobody recorded is the hardest possible version of that question to answer in writing.
Manufacturing and industrial groups Plants and acquired entities running their own IT, each with its own domains, its own registrar and its own view of what the centre needs to know. Whole apex domains the parent had no record of, arriving with the subsidiary that owns them.
Technology and software Velocity. Preview deployments, short-lived environments and repositories that outrun any process asking engineers to register things first. Ephemeral hosts that stopped being ephemeral, and public repositories sitting under personal accounts.

Banking and financial services

What produces the unregistered estate
A long tail of campaign microsites, regional portals and customer-facing applications that were superseded but never formally retired.
Where a first scan usually finds it
Old customer-facing hostnames still resolving, and subdomains delegated to marketing agencies years ago.

The regulatory framing sharpens this one. An inspection asks what is exposed and by when it will be fixed, and an asset nobody recorded is the hardest possible version of that question to answer in writing.

Manufacturing and industrial groups

What produces the unregistered estate
Plants and acquired entities running their own IT, each with its own domains, its own registrar and its own view of what the centre needs to know.
Where a first scan usually finds it
Whole apex domains the parent had no record of, arriving with the subsidiary that owns them.

Technology and software

What produces the unregistered estate
Velocity. Preview deployments, short-lived environments and repositories that outrun any process asking engineers to register things first.
Where a first scan usually finds it
Ephemeral hosts that stopped being ephemeral, and public repositories sitting under personal accounts.

Questions buyers ask

Before you evaluate this

We already run an asset inventory. What does this actually add?

The assets an inventory has no way to contain. A register is a record of decisions people made: a ticket raised, a pipeline registration, an onboarding form. It is accurate about every one of them. What it cannot do is hold an entry for something nobody filed. Outside-in discovery starts from your apex domains and reads what the internet answers, so it does not inherit that constraint. The two are complementary: the register tells you what you meant to be running, the scan tells you what is running. And because discovery feeds one correlated exposure model, a host found this way arrives already tied to whatever else is known about it: the leaked credential naming it, the certificate that exposed it, the domain it was registered under.

Do you need access to our network, our DNS zone or our cloud accounts?

No. The input is a list of apex domains you confirm as yours. Everything else is observed from outside using public and passively collected sources, which is also what makes the exercise a fair rehearsal of what somebody hostile can assemble about you with no access at all. Deeper testing of what discovery found is Continuous Automated Red-Teaming. It runs only where it is safe and authorised, and the scope is agreed with you in advance.

How do you avoid handing us assets that are not ours?

Attribution is a separate step from discovery, and it works from evidence: registration records, certificate subjects, hosting relationships and served content, not the fact that a host sits in a neighbouring address range. Anything that cannot be tied back stays a candidate instead of being counted. You then adjudicate each attributed asset: own it, disown it, or decommission it. A disowned asset stays on the record with your reason attached, so the same host does not come back as a fresh finding every quarter.

Is a 30–60% gap not just an argument for reporting a bigger number?

It would be, if the number were the deliverable. A discovery tool optimised for volume is easy to build: count everything adjacent, hand the customer a large first report, then lose their trust the first time somebody checks and finds most of it belongs to another company. Our figure is a first-scan comparison against the inventory you supplied, counted only after attribution is confirmed, with the denominator and the exclusions published beside it. The useful part is which specific assets sat inside it. One forgotten pre-production host running an unpatched application matters more than every correctly attributed static page in the report put together.

Find out what is answering that you never registered

One apex domain, two business days, a written snapshot of the estate we can see from outside. No call required.