Skip to main content
For Security & Infra Teams

Attack Surface Discovery & Infrastructure Mapping

Map domains resolving to your IPs & cloud assets to find shadow IT and exposed infra. DNS-enriched A/MX/NS/TXT for your external perimeter. Daily updates.

Map domains pointing to your IP ranges or cloud accounts to uncover shadow IT, third-party assets, and external exposure that silently expand your attack surface. Combine DNS data with domain records to see your full perimeter from the outside.

Your attack surface isn't what your CMDB says — it's what the internet sees. Forgotten marketing sites on old IPs, dev buckets with dangling DNS, vendor subdomains pointing to your ranges, and shadow IT spun up in a branch cloud account never make it into the asset inventory. Primitive Host maps domains that resolve to your IP ranges and cloud accounts using 276M+ DNS-enriched records. You see every externally reachable name tied to your infrastructure, with NS, MX, A, CNAME and TXT to prioritize. Track drift daily, prove perimeter reduction to auditors, and stop attackers finding what you forgot.

What you can do

External Perimeter Inventory

Enumerate every domain pointing at your ranges from an attacker's perspective — not your CMDB.

Shadow IT & Dangling DNS

Find forgotten dev, staging and marketing hosts that expand exposure and enable takeover.

Third-Party Risk Mapping

Map vendor and subsidiary domains sharing your infrastructure for supply-chain reviews.

Key features

  • Discover all domains resolving to your IP ranges and cloud accounts
  • Identify shadow IT, forgotten subdomains and dangling DNS
  • Map third-party assets and vendor dependencies by DNS footprint
  • DNS-enriched records: NS, MX, A, CNAME, and TXT with daily refresh
  • Track infrastructure changes over time for drift detection and audit proof
Example: Find domains pointing to your range primitive.host
GET /v1/domains?ip_range=198.51.100.0/24 Authorization: Bearer <token>
Response
{ "ip": "198.51.100.42", "domains": ["legacy-app.example.com", "old-marketing.example.com"], "total": 17 }
ASM DNS Records Infrastructure Mapping

Frequently asked questions

What is attack surface mapping for domains?

It inventories all domains that resolve to your infrastructure via A records — including unknown subdomains, vendor assets and shadow IT — so you can see your external perimeter as an attacker does.

How does this find shadow IT?

We reverse-map from IP to domain using daily DNS enrichment across 276M+ names. Any domain pointing to your ranges, even if unrecorded in your CMDB, surfaces in the results.

What DNS data is included?

Enriched A, NS, MX, CNAME and TXT records with daily refresh, plus TLD and registration context for prioritization.

Can I track changes over time?

Yes. Compare daily snapshots to detect drift — new domains appearing on your IPs, DNS changes, or vendor additions — for continuous perimeter monitoring.

Ready to try Attack Surface Discovery & Infrastructure Mapping?

Start free with previews and the blacklist checker — no sales call required.