How security testing works
What a test can and cannot tell you, how work is scoped and authorised, and how findings turn into fixes.
Continuous discovery of what you expose, triage of what is actually reachable, and remediation that holds.
External attack surface management is an operational discipline, not a product: discover continuously, work out what is genuinely exposed, route it to an owner, and prove it was closed.
This course covers building the discovery pipeline, triaging findings honestly, handling shadow IT and acquisitions, and setting remediation expectations that engineering teams can meet.
4 lessons · 54 min
DNS, certificate transparency, cloud APIs, registrars and acquisitions — run on a schedule, not a project.
Reachability, authentication and consequence — in that order, before scanner severity.
Why unmanaged systems appear, how to find them, and how to bring them in without driving them underground.
Windows by severity and exposure, routing to owners, exceptions that expire, and proof of closure.
Sign in and enrol to leave a review.
No reviews yet — be the first once you have worked through it.
2 min read
2 min read
2 min read
2 min read
What a test can and cannot tell you, how work is scoped and authorised, and how findings turn into fixes.
A methodical way through an application: mapping, authentication flows, access control and business logic.
Discovery, service enumeration, configuration weaknesses and proving that segmentation exists outside the diagram.