Exposure seen from the Internet
What anyone can see of your organisation from the Internet (open ports, known vulnerabilities, names published in certificates, accounts named in breaches), from public sources and with no scanning at all.
An attacker starts by looking at what sticks out: a remote desktop open to the Internet, an old firewall with a known flaw, a forgotten subdomain. The Exposure seen from the Internet screen shows you the same thing, from public sources that already list what can be seen from the Internet.
Approve the scope
Nothing is queried until the scope is approved. Open Firewall → Internet exposure (#/firewall/exposition), Scope tab.
FirstSI suggests what it already knows, with no outside call:
| Suggestion | Where it comes from |
|---|---|
| Agents' outbound addresses seen over the last 30 days | high confidence if at least 2 agents go out through it; those seen from a single computer are collapsed |
| Addresses of declared firewalls | Firewall module |
| WAN link addresses | NetworkMonitor module |
| Verified Microsoft 365 domains | Microsoft 365 connector, if leak collection is enabled |
For each suggestion, click Approve or Reject; Approve all approves every high-confidence suggestion in one go. Add lets you enter an address or a domain by hand, Remove takes an approved entry out. Only public IPv4 addresses and public domains are accepted, up to 256 addresses and 50 domains.
All these actions are reserved for administrators. They are recorded in the tab's Decision log and in the audit log.
The sources
| Source | What it tells you | For |
|---|---|---|
| Shodan InternetDB | open ports already listed, host names, known flaws (CVEs) | each approved address |
| Certificate transparency logs (crt.sh) | names published in certificates | each approved domain |
| Have I Been Pwned (optional) | domain accounts named in public breaches, with no password | each approved domain, if a key is entered |
The survey runs once a day. An administrator can restart it with Refresh now, at most once an hour, the daily survey included. A source that does not answer is marked unavailable, and the screen keeps its latest data.
For Have I Been Pwned, enter your key in the Scope tab, Have I Been Pwned key (optional) block, then Save the key. It is encrypted and never shown again. The domain must be verified at Have I Been Pwned for this key.
Reading the exposure
The Exposure tab gives the counters (addresses tracked, ports listed, sensitive ports, CVEs reported, published names, accounts named), the Open alerts, then the details:
- Public IP addresses: ports, CVEs with their CVSS score and a flag on actively exploited flaws, host names. Clicking an address adds the inbound connections accepted by your firewalls over 7 days, from the Firewall module logs.
- Names published for each domain: names whose certificate has expired are struck through.
- Accounts named in public breaches, if a Have I Been Pwned key is entered.
The History tab shows the trend survey by survey over 30 to 400 days.
Alerts
| Rule | Trigger | Severity |
|---|---|---|
| EXPO-PORT-SENSIBLE | administration or file-sharing port listed as open, one incident per address and per port | high |
| EXPO-CVE | known flaw reported on an address | high if a CVSS score of 9 or more is known, otherwise medium |
| EXPO-NOUVEAU | port or host name that appeared since the previous survey | medium |
| EXPO-FUITE | domain account named in a new breach | medium |
The ports considered sensitive are: 21, 22, 23, 69, 111, 135, 137, 138, 139, 161, 389, 445, 623, 636, 873, 1433, 1434, 1521, 2049, 2375, 2376, 3306, 3389, 4117, 5432, 5900, 5901, 5902, 5985, 5986, 6379, 8291, 9200, 11211 and 27017.
On an address's first survey, only sensitive ports and CVEs open an incident. These two alerts close on their own when the port is no longer listed or the address is removed from the scope. EXPO-NOUVEAU and EXPO-FUITE are handled in the SIEM.
Frequently asked questions
The screen stays empty. The scope has not been approved yet: nothing is queried before that.
A port closed a week ago is still shown. Public sources update their data at their own pace, not yours. The alert closes when the port drops out of their listing.
Microsoft 365 domains are not suggested. They are only suggested if leak collection is enabled on the Microsoft 365 connector. You can also add them by hand.
Source: · FirstSI Docs · updated 2026-10-11