Skip to content
FirstSIDocs

Exposure seen from the Internet

What anyone can see of your organisation from the Internet (open ports, known vulnerabilities, names published in certificates, accounts named in breaches), from public sources and with no scanning at all.

An attacker starts by looking at what sticks out: a remote desktop open to the Internet, an old firewall with a known flaw, a forgotten subdomain. The Exposure seen from the Internet screen shows you the same thing, from public sources that already list what can be seen from the Internet.

Approve the scope

Nothing is queried until the scope is approved. Open Firewall → Internet exposure (#/firewall/exposition), Scope tab.

FirstSI suggests what it already knows, with no outside call:

SuggestionWhere it comes from
Agents' outbound addresses seen over the last 30 dayshigh confidence if at least 2 agents go out through it; those seen from a single computer are collapsed
Addresses of declared firewallsFirewall module
WAN link addressesNetworkMonitor module
Verified Microsoft 365 domainsMicrosoft 365 connector, if leak collection is enabled

For each suggestion, click Approve or Reject; Approve all approves every high-confidence suggestion in one go. Add lets you enter an address or a domain by hand, Remove takes an approved entry out. Only public IPv4 addresses and public domains are accepted, up to 256 addresses and 50 domains.

All these actions are reserved for administrators. They are recorded in the tab's Decision log and in the audit log.

The sources

SourceWhat it tells youFor
Shodan InternetDBopen ports already listed, host names, known flaws (CVEs)each approved address
Certificate transparency logs (crt.sh)names published in certificateseach approved domain
Have I Been Pwned (optional)domain accounts named in public breaches, with no passwordeach approved domain, if a key is entered

The survey runs once a day. An administrator can restart it with Refresh now, at most once an hour, the daily survey included. A source that does not answer is marked unavailable, and the screen keeps its latest data.

For Have I Been Pwned, enter your key in the Scope tab, Have I Been Pwned key (optional) block, then Save the key. It is encrypted and never shown again. The domain must be verified at Have I Been Pwned for this key.

Reading the exposure

The Exposure tab gives the counters (addresses tracked, ports listed, sensitive ports, CVEs reported, published names, accounts named), the Open alerts, then the details:

  • Public IP addresses: ports, CVEs with their CVSS score and a flag on actively exploited flaws, host names. Clicking an address adds the inbound connections accepted by your firewalls over 7 days, from the Firewall module logs.
  • Names published for each domain: names whose certificate has expired are struck through.
  • Accounts named in public breaches, if a Have I Been Pwned key is entered.

The History tab shows the trend survey by survey over 30 to 400 days.

Alerts

RuleTriggerSeverity
EXPO-PORT-SENSIBLEadministration or file-sharing port listed as open, one incident per address and per porthigh
EXPO-CVEknown flaw reported on an addresshigh if a CVSS score of 9 or more is known, otherwise medium
EXPO-NOUVEAUport or host name that appeared since the previous surveymedium
EXPO-FUITEdomain account named in a new breachmedium

The ports considered sensitive are: 21, 22, 23, 69, 111, 135, 137, 138, 139, 161, 389, 445, 623, 636, 873, 1433, 1434, 1521, 2049, 2375, 2376, 3306, 3389, 4117, 5432, 5900, 5901, 5902, 5985, 5986, 6379, 8291, 9200, 11211 and 27017.

On an address's first survey, only sensitive ports and CVEs open an incident. These two alerts close on their own when the port is no longer listed or the address is removed from the scope. EXPO-NOUVEAU and EXPO-FUITE are handled in the SIEM.

Frequently asked questions

The screen stays empty. The scope has not been approved yet: nothing is queried before that.

A port closed a week ago is still shown. Public sources update their data at their own pace, not yours. The alert closes when the port drops out of their listing.

Microsoft 365 domains are not suggested. They are only suggested if leak collection is enabled on the Microsoft 365 connector. You can also add them by hand.

Source: · FirstSI Docs · updated 2026-10-11