What is an exposed service?¶
An exposed service is a network or application service reachable from a wider or less trusted environment than intended. Exposure can be deliberate and secure, so an internet-facing service is not automatically vulnerable or compromised.
Web applications, VPN gateways, remote desktop, file transfer, email, databases, APIs and administrative panels may all be exposed to different populations.
Define reachability at the relevant time¶
Identify the address, port, service, version and authentication controls. Establish where connections could originate, who controlled the configuration and when the exposure began and ended.
Current scans may miss temporary exposure created by cloud changes, port forwarding, emergency maintenance or automated deployment. Firewall, gateway, cloud and configuration history can show the earlier state. A service described as internal may still have been reachable through a VPN, relay or compromised device.
Connect exposure to incident activity¶
Exposure creates an opportunity for scanning, password attacks or exploitation. Authentication, application, firewall and endpoint records are needed to show what requests occurred and whether access followed.
Automated traffic may come through distributed or compromised infrastructure, so source addresses do not automatically identify a controller. Report the reachable route, controls and observed activity separately. This makes clear whether evidence proves public availability, an attempted access or a successful foothold.
Key takeaway
Establish what was reachable, from where, under which controls and during which period; exposure alone does not prove successful access.