Attack Surface Monitoring Checklist for SMB IT Teams

An attack surface monitoring checklist turns continuous security into a fixed routine: a 15-minute weekly check for new subdomains, open ports, expiring certificates, and DNS changes; a 30-minute monthly review of your full asset inventory and technology stack; and a quarterly look at scope, vendors, and compliance evidence. Consistency matters more than depth.

You don't need a 20-person security team to monitor your attack surface. You need a checklist, a cadence, and the discipline to follow it. This guide gives you all three — built for IT teams of one to five people who are already stretched thin.

What You'll Learn
  • A 15-minute weekly attack surface check (7 items)
  • A 30-minute monthly deep review (4 items)
  • A quarterly strategic review (3 items)
  • Which open-source tools cover each step
  • How to automate 90% of this checklist
  • Three actions you can take in the next 10 minutes

12 min read

Who This Checklist Is For

This checklist is designed for the IT generalist who wears too many hats. You manage the network, handle help desk tickets, run backups, keep the website up, and somewhere in there you're also supposed to be doing "security." Sound familiar?

If your organization has between 10 and 500 employees, no dedicated security hire, and at least a few internet-facing assets (a website, a mail server, maybe a VPN), this checklist is for you. It's tool-agnostic — you can do most of this with free tools and a browser. But we'll also show you how to automate the boring parts so you can focus on what actually needs your attention.

The Goal Is Consistency, Not Perfection

A 15-minute weekly check you actually do is infinitely more valuable than a 4-hour monthly audit you keep pushing to next week. This checklist is designed to be short enough that you'll actually complete it every time.

What makes attack surface monitoring different from vulnerability scanning? Vulnerability scanners check known assets for known CVEs. Attack surface monitoring answers a more fundamental question: what assets do you actually have exposed to the internet right now? New subdomains, new open ports, DNS changes, expired certificates — these are the gaps that attackers exploit before your vulnerability scanner ever sees them.

The 15-Minute Weekly Attack Surface Check

Block 15 minutes every Monday morning. Put it on your calendar. Treat it like a standup meeting — quick, focused, non-negotiable. Here are the seven items to check every single week.

Item 1Review New Subdomains Discovered
  • Check for any new subdomains that appeared since last week
  • Verify each new subdomain is authorized and expected
  • Flag unknown subdomains for immediate investigation
  • Look for patterns: staging servers, test environments, shadow IT
Item 2Check for New Open Ports
  • Compare this week's port scan results against last week's baseline
  • Investigate any new ports that weren't open before
  • Pay special attention to management ports (22, 3389, 8080, 8443)
  • Confirm any new services have proper authorization
Item 3Verify SSL Certificate Status
  • Check certificates expiring within 30 days
  • Verify no certificates have already expired
  • Confirm certificate chains are valid and trusted
  • Initiate renewal for anything expiring within 14 days
Item 4Review DNS Record Changes
  • Check for any DNS records added, modified, or deleted
  • Look for dangling CNAME records pointing to decommissioned services
  • Verify MX records haven't been tampered with
  • Confirm SPF/DKIM/DMARC records are intact
Item 5Check for Exposed Admin Panels
  • Scan for common admin paths (/admin, /wp-admin, /login, /phpmyadmin)
  • Verify all admin interfaces require MFA
  • Confirm admin panels are not accessible from the public internet
  • Check for any new management interfaces that appeared
Item 6Review Vulnerability Scan Results
  • Check for any new critical or high-severity vulnerabilities
  • Verify that previously identified vulns are being remediated
  • Look for newly published CVEs affecting your tech stack
  • Prioritize anything internet-facing with a public exploit
Item 7Check Drift Alerts
  • Review any configuration drift alerts from the past week
  • Investigate unexpected changes to running services
  • Check for technology version changes (upgrades or downgrades)
  • Verify that all changes correspond to approved change requests

That's the entire weekly check. Seven items, fifteen minutes. If you find something concerning during the check, don't try to fix it on the spot — log it, assign it a priority, and schedule the remediation. The weekly check is for detection, not resolution.

Automate This Entire Checklist

DriftAlarm runs all seven weekly checks automatically — subdomain discovery, port monitoring, SSL tracking, DNS change detection, admin panel scanning, vulnerability assessment, and drift alerting. Instead of spending 15 minutes checking manually, you spend 2 minutes reviewing what DriftAlarm already found.

Start your 30-day trial →

Monthly Deep Review (30 Minutes)

Once a month, block 30 minutes for a deeper look. This is where you catch the slow-moving risks that don't trigger weekly alerts — the gradual drift, the forgotten assets, the trends that only become visible over time.

Monthly 1Full Asset Inventory Audit
  • Compare your asset register against discovery scan results
  • Identify any assets in scans that aren't in your register (shadow IT)
  • Remove decommissioned assets that no longer resolve
  • Confirm asset ownership is current — people leave, roles change
  • Update criticality ratings if business context has changed
Monthly 2Technology Stack Review
  • Review all detected technologies across your assets
  • Check for end-of-life (EOL) software approaching or past end of support
  • Look for technology version inconsistencies across environments
  • Verify all web frameworks and CMS platforms are on supported versions
  • Flag any technology that requires an upgrade plan
Monthly 3WHOIS and Registration Verification
  • Check domain expiration dates — renew anything within 90 days
  • Verify registrar lock is enabled on critical domains
  • Confirm WHOIS contact info is accurate and monitored
  • Check for unauthorized domain transfers or NS record changes
Monthly 4Risk Score Trend Analysis
  • Review your overall risk score trend over the past 30 days
  • Identify which assets are driving risk score increases
  • Check if remediation efforts are actually reducing your score
  • Compare against your target risk posture
  • Adjust priorities if certain assets are chronically risky

Quarterly Strategic Review

Every quarter, step back and look at the bigger picture. This isn't about individual vulnerabilities — it's about whether your monitoring program is keeping pace with how your organization is growing and changing.

Quarterly 1Scope Expansion
  • Has the company acquired new domains, IPs, or cloud accounts?
  • Are there new SaaS tools that expose branded login pages?
  • Has the company merged with or acquired another organization?
  • Add any new assets to your monitoring scope
  • Retire monitoring for assets that have been fully decommissioned
Quarterly 2Vendor and Third-Party Surface Review
  • Review vendor integrations that connect to your infrastructure
  • Check for third-party services hosting content on your domains
  • Verify that vendor-managed assets meet your security standards
  • Assess whether any vendor relationships have changed or ended
Quarterly 3Compliance Evidence Collection
  • Export scan reports and remediation evidence for audit readiness
  • Document your monitoring cadence and coverage for compliance
  • Verify that monitoring meets any regulatory requirements (SOC 2, ISO 27001, HIPAA)
  • Archive quarterly summary for board or leadership reporting

Tools You Need

You can build a monitoring program with open-source tools. It takes more manual effort, but it works. Here's what covers each checklist item — and how DriftAlarm automates each step so you don't have to stitch it together yourself.

Checklist ItemOpen-Source ToolsDriftAlarm Automation
Subdomain discoveryAmass, Subfinder, crt.shAutomated weekly discovery scans with change alerts
Port monitoringNmap, Masscan, RustScanDaily port scans with baseline comparison and drift detection
SSL certificate trackingtestssl.sh, sslyze, certbotContinuous certificate monitoring with expiry alerts
DNS change detectiondig + cron scripts, DNSdiffAutomated DNS baseline with change notifications
Admin panel scanningNuclei, httpx, ffufVulnerability scans include admin path detection
Vulnerability scanningNuclei, OpenVAS, NiktoDaily vulnerability scans with AI-assisted prioritization
Drift alertingCustom scripts + diff32 built-in drift rules with notification channels
Asset inventorySpreadsheet + manual updatesAutomatic asset register with technology fingerprinting
Tech stack reviewWhatWeb, Wappalyzer, httpxTechnology normalization with EOL tracking
Risk scoringManual spreadsheet formulasAutomated risk scores with trend tracking per asset
The DIY Tax

Stitching open-source tools together works, but it takes time — typically 2-4 hours per week to run, aggregate, compare, and investigate results manually. That's time most SMB IT teams don't have. The real question is whether your time is better spent running Nmap or investigating the one finding that actually matters.

Getting Started Today: 3 Actions in 10 Minutes

Don't wait until next Monday. Here are three things you can do in the next 10 minutes to start monitoring your attack surface.

1
List Your Assets

Open a spreadsheet. Write down every domain, IP address, and cloud service your company exposes to the internet. Don't overthink it — you can refine later. Just get the list started.

2
Schedule Your First Weekly Check

Put a 15-minute recurring calendar event on Monday mornings. Label it "Attack Surface Check." Invite yourself. Protect this time — it's the most important 15 minutes of your security week.

3
Run Your First Scan

Pick one domain from your list. Run a discovery scan with DriftAlarm (takes just minutes) or use Amass and Nmap manually. Either way, you'll immediately see what's exposed — and that's the first step.

Related Security Guides

This checklist gets you started. These guides go deeper on specific topics:

Start Your 30-Day Trial

First scan in minutes. No credit card required. See what attackers see before they see it first.

Frequently Asked Questions

How is attack surface monitoring different from vulnerability scanning?

Vulnerability scanners check assets you already know about for known CVEs. Attack surface monitoring answers a more basic question: what do you actually have exposed to the internet right now? New subdomains, new open ports, DNS changes, and expired certificates are gaps that appear before a vulnerability scanner — pointed only at your known assets — ever sees them. The checklist covers both, in that order.

How often should a small IT team check its attack surface?

Weekly for detection, monthly and quarterly for depth. Block 15 minutes every Monday to check new subdomains, open ports, certificate expiry, DNS changes, exposed admin panels, new vulnerabilities, and drift alerts. Spend 30 minutes monthly on a full inventory and tech-stack audit, and step back quarterly to review scope, vendors, and compliance evidence. A short check you always do beats a long one you skip.

Can I do attack surface monitoring with free tools, or do I need a paid platform?

You can. Open-source tools cover every step — Amass and crt.sh for subdomains, Nmap for ports, testssl.sh for certificates, Nuclei for vulnerabilities. The cost is time: stitching them together, aggregating, and comparing results runs roughly two to four hours a week. A platform trades that for money. DriftAlarm runs daily monitoring and real asset discovery at a self-serve price.

What is configuration drift and why does it matter for security?

Configuration drift is the gradual, often unnoticed change in your internet-facing setup: a new port opens, a TLS setting weakens, a DNS record points somewhere new, or a service version changes without a matching change request. Individually these look minor, but they're where exposures quietly appear between vulnerability scans. Reviewing drift alerts weekly catches the change while it's still small and easy to reverse.