Internet-Facing IP Addresses

Attack Surface Discovery scans your external attack surface to discover public IP addresses.

IP-related risks are identified based on the following factors:


Example of risk


Unexpected service exposure


Unexpected port exposure


Application vulnerability detected on a device

The following table outlines the actions you can perform on the Public IPs tab:



View an overview of internet-facing IPs.

The widget provides the following information:

  • Number of discovered IPs per month

  • Discovery trend for the last 12 months

  • Distribution by geographic location

View the list of internet-facing IPs.

The list provides key information about each IP, including latest risk score, number of related hosts, and number of highly-exploitable CVEs.

You can filter list entries based on criteria such as criticality and host provider.


Assets marked with the star icon are highly critical to your organization's operations. For more information, see Asset Criticality.

View the asset details screen for each listed IP.

The asset details screen includes the following tabs:

  • Risk Assessment: Displays the risk score and list of risk indicators, including descriptions of risk events and recommended remediation actions

  • Related Hosts: Lists the related domains and subdomains with information such as host provider, services, and ports

  • Open Services and Ports: Lists internet-facing ports, the related services, and their status

  • Asset Profile: Displays criticality-related information, including the criticality level and list of profile tags

Export information about internet-facing IPs discovered in the last 7 days.

  1. Click Manage Reports.

  2. Select Internet-Facing Assets.

    The Report Management › Internet-Facing Assets Template screen appears.

  3. Configure the report settings.


    To view the list of data fields for each asset type, click View CSV Fields.

  4. Click Create.

Each CSV file contains a maximum of 100,000 records.