- Job title
- Technical service technician
- Sector
- Packaging
- Organization type
- a company within a holding
- Joined
- Jul 2025
- Message
- 263
We are an 18-person automotive spare parts exporter based in Frankfurt. Our company has been operating for 9 years, and over that time we've accumulated 42 subdomains, 12 static IP addresses, and forgotten test servers spun up for various past projects. When looking into commercial attack surface management services to secure our infrastructure, we received quotes ranging from 6,000 to 9,000 EUR per year. That budget is tough to justify for an SME of our size, so we decided to map out our own inventory using open source attack surface discovery tools.
Using open source asset discovery and DNS scanning scripts deployed on our Linux server, we managed to list our externally exposed systems. However, we're struggling to define where the line is. Querying public DNS and certificate transparency logs poses no legal or technical issues, but how safe is it to run active port scans against these IPs, query open service versions, and run automated vulnerability checks? How far can we take this on our own without running afoul of our German data center or ISP, and at what point does hiring a professional penetration testing service become unavoidable?