Skip to main content
Use case · Discovery and attribution

Nobody registered it, and it is still answering.

“Marketing stood up a subdomain three years ago and pointed it at a service that no longer exists.”

Shadow IT is rarely a rogue software purchase. It is the subdomain marketing spun up for a campaign, the staging host that outlived the project it was built for, the cloud account somebody opened on a personal card at a company you later acquired. ShadowMap starts from the apex domains you already know you own and works inwards from outside, so what comes back is the estate as an attacker enumerates it rather than the estate as it was last written down.

One apex domain
The only input a first scan needs
Two business days
From that input to a written snapshot of what was found
30–60%

More external assets found than were internally inventoried

A band, not a promise — where an organisation lands inside it is driven by how much has been acquired, how long the estate has existed and how centralised its DNS is. Read it as a statement about how registers work, not as a criticism of yours. An internal inventory records what somebody remembered to add; an outside-in scan simply does not carry that constraint.

The honest framing

This is not a failure of the CMDB

The register is accurate about everything in it. The gap is structural: an internal inventory can only ever contain what someone remembered to add to it.

Every asset in a register got there because a person decided it belonged there — a ticket was raised, a build pipeline registered it, an onboarding form was filled in. That is a reasonable system and it fails in exactly one predictable way: it has no entry for the things nobody thought to file. A campaign subdomain delegated to an agency. A staging host whose project closed while the machine kept running. A cloud account opened on a personal card by an engineer who has since left. An apex domain that arrived with a subsidiary and never reached the parent. None of these were hidden. They were never written down, and from outside that is not a meaningful distinction — somebody enumerating your certificate transparency history does not consult your register first.

The contrast

What a register records, and what the internet answers

The same estate read two ways. The left column is what an internal inventory can know by construction; the right is what outside-in observation returns without asking anybody inside the organisation.

Asset classWhat the internal inventory hasWhat an outside-in view observesWhere it turns up first
Campaign and microsite subdomains Only the ones somebody raised a ticket for. DNS delegated to an agency leaves no internal record at all. Every name issued a publicly-trusted certificate, whether or not it still resolves to infrastructure you control. Attack Surface Management
Certificate transparency logs are public and append-only. A name issued for a six-week campaign in 2019 is still enumerable today — your register is allowed to forget it, the log is not. That asymmetry is the whole use case.
Staging, UAT and demo hosts Marked decommissioned when the project closed, which is a statement about the ticket rather than about the machine. A live host, its technology stack, the services it exposes and whatever authentication it was never given. Attack Surface Management
Origin-server and virtual-host detection matters here: a pre-production host sitting behind the same edge as production is often reachable directly, which is precisely what makes it interesting to somebody else.
Domains registered outside procurement The corporate registrar account. Not the name a departing employee bought on a personal card for a launch. Registration, nameserver and hosting records for names carrying your brand, including ones you are no longer renewing. Domain Monitoring
A lapsed name that once served your content is a different problem from a typosquat: it inherits your backlinks, and sometimes your old DNS records are still pointing at it.
Repositories, buckets and indexed documents The organisation-owned repositories. Not the personal account a contractor pushed a working copy to. Public code, exposed storage and indexed files attributed back to you by what is inside them rather than by who owns the account. Data Exposure Monitoring
Credentials for a system you had not listed Nothing. A register cannot hold an account for an application it has no entry for. Stealer-log credentials naming a host, at which point the host itself becomes the discovery. Dark Web Monitoring
This is the direction people do not expect — the exposure finds the asset. A credential for an internal tool nobody had registered is simultaneously an incident and an inventory update.

Campaign and microsite subdomains

What the internal inventory has
Only the ones somebody raised a ticket for. DNS delegated to an agency leaves no internal record at all.
What an outside-in view observes
Every name issued a publicly-trusted certificate, whether or not it still resolves to infrastructure you control.
Where it turns up first
Attack Surface Management

Certificate transparency logs are public and append-only. A name issued for a six-week campaign in 2019 is still enumerable today — your register is allowed to forget it, the log is not. That asymmetry is the whole use case.

Staging, UAT and demo hosts

What the internal inventory has
Marked decommissioned when the project closed, which is a statement about the ticket rather than about the machine.
What an outside-in view observes
A live host, its technology stack, the services it exposes and whatever authentication it was never given.
Where it turns up first
Attack Surface Management

Origin-server and virtual-host detection matters here: a pre-production host sitting behind the same edge as production is often reachable directly, which is precisely what makes it interesting to somebody else.

Domains registered outside procurement

What the internal inventory has
The corporate registrar account. Not the name a departing employee bought on a personal card for a launch.
What an outside-in view observes
Registration, nameserver and hosting records for names carrying your brand, including ones you are no longer renewing.
Where it turns up first
Domain Monitoring

A lapsed name that once served your content is a different problem from a typosquat: it inherits your backlinks, and sometimes your old DNS records are still pointing at it.

Repositories, buckets and indexed documents

What the internal inventory has
The organisation-owned repositories. Not the personal account a contractor pushed a working copy to.
What an outside-in view observes
Public code, exposed storage and indexed files attributed back to you by what is inside them rather than by who owns the account.
Where it turns up first
Data Exposure Monitoring

Credentials for a system you had not listed

What the internal inventory has
Nothing. A register cannot hold an account for an application it has no entry for.
What an outside-in view observes
Stealer-log credentials naming a host, at which point the host itself becomes the discovery.
Where it turns up first
Dark Web Monitoring

This is the direction people do not expect — the exposure finds the asset. A credential for an internal tool nobody had registered is simultaneously an incident and an inventory update.

The number

Where 30–60% comes from, and what it leaves out

A first-scan comparison, not a running statistic. Worth knowing exactly what was counted on each side of it before you quote the figure to a board.

How the 30–60% band is arrived at As of August 2026
  • The denominator is the asset list the customer supplied at kick-off — whatever they treat as their inventory of record, in whatever form it arrived.
  • The numerator is internet-facing assets attributed to that organisation at the end of a first scan, starting only from apex domains the customer confirmed as theirs.
  • Attribution is confirmed before an asset counts. A host that merely shares an address range with something of yours is not yours, and padding the figure with those would make it worthless in exactly the meeting where it gets used.
  • The band is wide because the driver is organisational rather than technical. Acquisitions, delegated DNS and decentralised marketing all move an organisation towards the top of it.

Deliberately excluded

  • Internal-only assets. This is an outside-in comparison, so anything unreachable from the internet is out of scope on both sides of the ratio.
  • Assets discovered after the first scan. Continuous discovery keeps adding, but folding later finds in would quietly improve the figure over time until it stopped meaning anything.
  • Vendor-hosted assets the customer does not claim. Where an asset is genuinely disowned it leaves the numerator, rather than being argued into it.

The sequence

From an unattributed host to a decision you can defend

Discovery is the first move, not the job. The order here is load-bearing: nothing can be validated before it has been attributed, and nothing should be attributed before a person has said out loud whether it is ours.

Three points of view

The same forgotten subdomain, read three ways

One host, described by the three parties who have an opinion about it. None of them is lying. They simply hold different facts.

Worked example

promo.acmecorp.com — a campaign microsite, live since 2021

What the marketing team knows
The campaign ended years ago and the agency that built the site was paid and offboarded. As far as anyone in the team is concerned it is gone, because nothing has linked to it since the quarter it ran.
What the security team knows
Nothing. The host is not in the register, so it is not in the scanning scope, so it has never appeared in a report. There is no finding to miss, because as far as the programme is concerned there is no asset.
What is actually true
The DNS record still resolves. The host still answers on 443, running a content management system three major versions behind, and its administrative login still accepts the shared credential the agency was handed in 2021.

Where this bites hardest

The same gap takes a different shape by sector

Unregistered estate is universal. What produces it is not — and knowing which pattern applies to you is what tells you where a first scan will spend its time.

SectorWhat produces the unregistered estateWhere a first scan usually finds it
Banking and financial services A long tail of campaign microsites, regional portals and customer-facing applications that were superseded rather than formally retired. Old customer-facing hostnames still resolving, and subdomains delegated to marketing agencies years ago.
The regulatory framing sharpens this one. An inspection asks what is exposed and by when it will be fixed, and an asset nobody recorded is the hardest possible version of that question to answer in writing.
Manufacturing and industrial groups Plants and acquired entities running their own IT, each with its own domains, its own registrar and its own view of what the centre needs to know. Whole apex domains the parent had no record of, arriving with the subsidiary that owns them.
Technology and software Velocity. Preview deployments, short-lived environments and repositories that outrun any process asking engineers to register things first. Ephemeral hosts that stopped being ephemeral, and public repositories sitting under personal accounts.

Banking and financial services

What produces the unregistered estate
A long tail of campaign microsites, regional portals and customer-facing applications that were superseded rather than formally retired.
Where a first scan usually finds it
Old customer-facing hostnames still resolving, and subdomains delegated to marketing agencies years ago.

The regulatory framing sharpens this one. An inspection asks what is exposed and by when it will be fixed, and an asset nobody recorded is the hardest possible version of that question to answer in writing.

Manufacturing and industrial groups

What produces the unregistered estate
Plants and acquired entities running their own IT, each with its own domains, its own registrar and its own view of what the centre needs to know.
Where a first scan usually finds it
Whole apex domains the parent had no record of, arriving with the subsidiary that owns them.

Technology and software

What produces the unregistered estate
Velocity. Preview deployments, short-lived environments and repositories that outrun any process asking engineers to register things first.
Where a first scan usually finds it
Ephemeral hosts that stopped being ephemeral, and public repositories sitting under personal accounts.

Questions buyers actually ask

Before you evaluate this

We already run an asset inventory. What does this actually add?

The assets an inventory has no way to contain. A register is a record of decisions people made — a ticket raised, a pipeline registration, an onboarding form — and it is accurate about every one of them. What it cannot do is hold an entry for something nobody filed. Outside-in discovery starts from your apex domains and reads what the internet answers, so it does not inherit that constraint. The two are complementary: the register tells you what you meant to be running, the scan tells you what is running. And because discovery feeds one correlated exposure model, a host found this way arrives already tied to whatever else is known about it — the leaked credential naming it, the certificate that exposed it, the domain it was registered under.

Do you need access to our network, our DNS zone or our cloud accounts?

No. The input is a list of apex domains you confirm as yours. Everything else is observed from outside using public and passively collected sources, which is also what makes the exercise a fair rehearsal of what somebody hostile can assemble about you with no access at all. Where you want deeper testing of what discovery found, that is Continuous Automated Red-Teaming, it runs only where it is safe and authorised, and the scope is agreed with you in advance.

How do you avoid handing us assets that are not ours?

Attribution is a separate step from discovery and it is evidence-based rather than proximity-based: registration records, certificate subjects, hosting relationships and served content, not the fact that a host sits in a neighbouring address range. Anything that cannot be tied back stays a candidate instead of being counted. You then adjudicate each attributed asset — own it, disown it, or decommission it — and a disowned asset stays on the record with your reason attached, so the same host does not come back as a fresh finding every quarter.

Is a 30–60% gap not just an argument for reporting a bigger number?

It would be, if the number were the deliverable. A discovery tool optimised for volume is easy to build: count everything adjacent, hand the customer a large first report, and lose their trust the first time somebody checks and most of it belongs to another company. Our figure is a first-scan comparison against the inventory you supplied, counted only after attribution is confirmed, with the denominator and the exclusions published beside it. The useful part was never the size of the gap. It is which specific assets sat inside it — one forgotten pre-production host running an unpatched application matters more than every correctly attributed static page in the report put together.

Find out what is answering that you never registered

One apex domain, two business days, a written snapshot of the estate we can see from outside. No call required.