EASMRcortex Elixir

มองโดเมนของคุณผ่าน
สายตาของผู้โจมตี

RedSocs ทำการตรวดิจิทัลสาธารณะของคุณ ภายใต้สมมติฐานเดียวกับผู้โจมตีทางไซเบอร์ โดยไม่พึ่งพาเอเย่นต์หรือข้อมูลประจำตัวใดๆ นำเสนอข้อมูลตามความเป็นจริง ไม่มีการตกแต่งหรือบิดเบือน เพื่อสะท้อนภาพรวมที่แท้จริงของการเปิดเผยข้อมูลของคุณบนอินเทอร์เน็ต

✓ ไม่มีการติดตั้ง✓ ข้อมูลช่องโหว่อัพเดตทุกๆ 3 ชม.✓ การสแกนอย่างต่อเนื่อง 24/7

การจัดการพื้นผิวการโจมตีภายนอกคืออะไร?

การสแกนจากภายนอกหมายความว่า RedSocs จะค้นพบและตรวจสอบรอยเท้าอินเทอร์เน็ตสาธารณะของคุณเหมือนกับที่ผู้โจมตีที่แท้จริงทำ — จากภายนอก โดยไม่มีการเข้าถึงพิเศษใดๆ เอเจนต์ภายใน หรือข้อมูลประจำตัวที่กำหนดค่าไว้ล่วงหน้า

วิธีการนี้จะบันทึกการเปิดเผยจากภายนอกที่แท้จริงของคุณ: ทรัพย์สินที่คุณอาจลืมไป บริการที่เปิดเผยต่ออินเทอร์เน็ตโดยไม่ได้ตั้งใจ โครงสร้างพื้นฐานด้านไอทีที่ซ่อนอยู่โดยไม่มีการตรวจสอบความปลอดภัย และสิ่งประดิษฐ์ดิจิทัลในอดีตที่ยังคงจัดทำดัชนีและเข้าถึงได้

EASM เป็นก้าวแรกในโปรแกรมรักษาความปลอดภัยที่น่ารังเกียจ คุณไม่สามารถปกป้องสิ่งที่คุณไม่รู้ว่ามีอยู่จริง RedSocs แมปพื้นผิวการโจมตีของคุณอย่างต่อเนื่อง เพื่อให้ทีมรักษาความปลอดภัยของคุณมีสินค้าคงคลังที่ครบถ้วนและเป็นปัจจุบันอยู่เสมอ

  • ค้นพบสินทรัพย์เงา: โดเมนย่อยที่ถูกลืม บริการที่เลิกใช้งาน สภาพแวดล้อมชั่วคราว
  • ระบุพอร์ตเปิดที่ไม่คาดคิดและบริการที่ไม่ได้มาตรฐาน
  • รวบรวมข้อมูล SPA และเว็บแอปแบบไดนามิกสำหรับจุดสิ้นสุด API ที่ซ่อนอยู่
  • เส้นทางไดเร็กทอรี Brute-forces สำหรับแผงผู้ดูแลระบบที่เปิดเผยและไฟล์สำรอง
  • เชื่อมโยงการค้นพบทั้งหมดกับฐานข้อมูล CVE และข้อมูลภัยคุกคาม

มุมมองของผู้โจมตี

1

การลาดตระเวนแบบพาสซีฟ

การแจงนับ DNS ความโปร่งใสของใบรับรอง WHOIS

2

การสแกนที่ใช้งานอยู่

การสแกนพอร์ต บริการพิมพ์ลายนิ้วมือ การดึงแบนเนอร์

3

การรวบรวมข้อมูลเว็บ

การนำทาง SPA, การค้นพบจุดสิ้นสุด API, เส้นทางเดรัจฉาน

4

ความสัมพันธ์ของช่องโหว่

การจับคู่ CVE, ความสัมพันธ์ของ Intel ภัยคุกคาม, การให้คะแนนความเสี่ยง

การค้นพบรอยเท้าเครือข่าย

ก่อนที่การสแกนเลเยอร์แอปพลิเคชันจะเริ่มต้น RedSocs จะแมปรอยเท้าเครือข่ายทั้งหมดของคุณ — ทุกที่อยู่ IP, ทุกพอร์ตที่เปิดอยู่, ทุกบริการที่ทำงานอยู่ซึ่งมองเห็นได้จากอินเทอร์เน็ตสาธารณะ

🔍

เปิดการค้นพบพอร์ต

การสแกนพอร์ต TCP/UDP เต็มรูปแบบตลอดช่วง IP ทั้งหมดที่เกี่ยวข้องกับองค์กรของคุณ รวมถึงช่วงของผู้ให้บริการคลาวด์ โหนด CDN Edge และการจัดสรรในอดีต ระบุบริการที่ไม่ควรเชื่อมต่อกับอินเทอร์เน็ต

  • กวาดล้างสินทรัพย์ที่สำคัญได้เต็มพอร์ต 65,535 พอร์ต
  • พอร์ต 1,000 อันดับแรกกวาดล้างสินทรัพย์ทั้งหมด
  • การพิมพ์ลายนิ้วมือเวอร์ชันบริการ (Nginx, Apache, OpenSSH, MySQL…)
  • การแจงนับและการตรวจสอบใบรับรอง SSL/TLS
👻

การตรวจจับโปรโตคอลเงา

ค้นหาบริการที่ทำงานโดยตั้งใจหรือโดยไม่ได้ตั้งใจบนพอร์ตที่ไม่ได้มาตรฐาน ซึ่งเป็นเคล็ดลับทั่วไปของผู้โจมตีในการหลบเลี่ยงการตรวจสอบขอบเขตขั้นพื้นฐาน บริการลายนิ้วมือ RedSocs โดยไม่คำนึงถึงหมายเลขพอร์ต

  • SSH บนพอร์ต 2222, 2200 หรือ 22222
  • MySQL หรือ PostgreSQL บนพอร์ตที่ไม่ใช่ค่าเริ่มต้น
  • Redis, Memcached, Elasticsearch เปิดเผยต่อสาธารณะ
  • RDP, VNC และโปรโตคอลการจัดการระยะไกล
🗺️

การทำแผนที่ความเป็นเจ้าของ IP

แมปที่อยู่ IP และ ASN ทั้งหมดที่เกี่ยวข้องกับองค์กรของคุณ รวมถึงที่คุณอาจไม่ทราบจากการจัดสรรแบบเดิม บริษัทสาขา และการจัดการโฮสติ้งของบุคคลที่สาม

  • การแจงนับ ASN และการค้นพบช่วง CIDR
  • การระบุสินทรัพย์บนคลาวด์ (AWS, GCP, Azure, Alibaba Cloud)
  • การตรวจจับสถานะ CDN และ WAF (Cloudflare, Akamai, Fastly)
  • ตำแหน่งทางภูมิศาสตร์และการระบุแหล่งที่มาของผู้ให้บริการโฮสติ้ง

โปรแกรมรวบรวมข้อมูล Spatolas SPA

เว็บแอปพลิเคชันสมัยใหม่สร้างขึ้นด้วยเฟรมเวิร์ก JavaScript ที่เครื่องสแกน HTTP แบบดั้งเดิมไม่สามารถสำรวจได้ Spitolas คือกลไกการรวบรวมข้อมูลบนเบราว์เซอร์แบบไม่มีส่วนหัวของ RedSocs โดยจะนำทางแอปพลิเคชันของคุณเหมือนกับที่ผู้ใช้มนุษย์ทำ

🖱️

การนำทางที่เหมือนมนุษย์

คลิกปุ่ม กรอกแบบฟอร์ม เลื่อนดูหน้าเลื่อนแบบไม่มีที่สิ้นสุด รอการโหลดข้อมูลแบบอะซิงก์ และจัดการการกำหนดเส้นทางฝั่งไคลเอ็นต์ที่ซับซ้อนในเฟรมเวิร์ก CMS ของ React, Vue, Angular

📡

การสกัดกั้น API ที่ซ่อนอยู่

บันทึกคำขอเครือข่ายทั้งหมดที่ทำระหว่างการนำทาง — การเรียก XHR, คำขอ Fetch API, การเชื่อมต่อ WebSocket — เปิดเผยจุดสิ้นสุด API ที่ไม่เคยจัดทำเป็นเอกสาร แต่สามารถเข้าถึงได้อย่างสมบูรณ์จากอินเทอร์เน็ตสาธารณะ

🔑

การค้นพบจุดความเสี่ยงที่ข้ามตามนุษย์

ระบุจุดสิ้นสุด API ภายใน เส้นทางเฉพาะผู้ดูแลระบบเท่านั้นที่เข้าถึงได้โดยไม่ได้ตั้งใจโดยไม่มีการตรวจสอบสิทธิ์ และจุดสิ้นสุดข้อมูลที่ส่งคืนข้อมูลที่ละเอียดอ่อนไปยังผู้ใช้ที่ไม่ผ่านการตรวจสอบสิทธิ์

🇹🇭

รองรับภาษาไทยและ JS ที่ซับซ้อน

จัดการ Thai Unicode อย่างถูกต้องในการป้อนแบบฟอร์มและพารามิเตอร์ URL รองรับเฟรมเวิร์ก JavaScript ที่ซับซ้อน รวมถึงพอร์ทัลบริการอิเล็กทรอนิกส์ของรัฐบาลไทยที่สร้างขึ้นบนแพลตฟอร์ม CMS ที่เป็นกรรมสิทธิ์

โปรแกรมรวบรวมข้อมูล spitolas v2.4.1
[10:24:01] [INIT] เปิดตัวเบราว์เซอร์ headless สำหรับ Portal.example.go.th
[10:24:03] [NAV] กำลังโหลด / → ตรวจพบการตอบสนอง SPA (Next.js 14.2)
[10:24:05] [NAV] คลิกลิงก์การนำทาง → ค้นพบ 12 เส้นทาง
[10:24:08] [XHR] GET /api/v1/products?page=1 → 200 (รหัสผู้ใช้รั่วไหลในการตอบสนอง)
[10:24:09] [XHR] POST /api/internal/admin/stats → 401 (มีจุดสิ้นสุด ไม่มีการป้องกัน)
[10:24:11] [XHR] GET /api/v2/user/profile → 200 (PII ในส่วนเนื้อหาการตอบสนอง)
[10:24:14] [SCROLL] เรียกใช้การเลื่อนแบบไม่มีที่สิ้นสุด → จับการเรียก API เพิ่มเติม 3 ครั้ง
[10:24:16] [ALERT] จุดสิ้นสุดที่ไม่มีเอกสาร /api/internal/admin/export — ไม่มีการตรวจสอบสิทธิ์
[10:24:18] [DONE] ค้นพบจุดสิ้นสุด 47 จุด | ผลการวิจัยที่มีความรุนแรงสูง 3 รายการ | 12 เส้นทางที่แมป

เครื่องยนต์ค้นพบเส้นทาง

เป็นไดเร็กทอรีของ RedSocs และเอ็นจิ้นการบังคับเดรัจฉานของพาธ โดยจะตรวจสอบทรัพย์สินบนเว็บของคุณอย่างเป็นระบบเพื่อหาแผงผู้ดูแลระบบที่ซ่อนอยู่ ไฟล์สำรอง ไฟล์การกำหนดค่าที่ถูกเปิดเผย และเส้นทางที่ละเอียดอ่อนโดยใช้รายการคำศัพท์เส้นทางมากกว่า 35,000 รายการที่ได้รับการดูแลจัดการอย่างระมัดระวัง

📖 รายการคำรู้ไทย

เส้นทางมากกว่า 35,000 เส้นทาง รวมถึงรูปแบบ CMS ของรัฐบาลไทย เส้นทางผู้ดูแลระบบอีคอมเมิร์ซไทยทั่วไป โมดูล Drupal ภาษาไทย การติดตั้ง WordPress ที่พบได้ทั่วไปในตลาดไทย และการกำหนดค่าเริ่มต้นของผู้ให้บริการโฮสติ้งในพื้นที่

🚪 การตรวจจับแผงผู้ดูแลระบบ

ระบุอินเทอร์เฟซผู้ดูแลระบบที่ถูกเปิดเผย — /admin, /phpmyadmin, /cPanel, /wp-admin, /administrator, /manager และเส้นทางเฉพาะแอปพลิเคชันหลายร้อยเส้นทางสำหรับซอฟต์แวร์ยอดนิยมในตลาดไทย

💾 การค้นพบไฟล์สำรอง

แจ้งไฟล์สำรองที่สามารถเข้าถึงได้ซึ่งมีดัมพ์ฐานข้อมูลหรือซอร์สโค้ด: .sql, .bak, .tar.gz, .zip, db_backup.sql, website_backup_2024.zip — ข้อผิดพลาดทั่วไปที่ทำให้เนื้อหาฐานข้อมูลเต็มรูปแบบ

🤖 robots.txt รับทราบ

ในโหมดพาสซีฟ ให้คำนึงถึง robots.txt และสแกนเฉพาะเส้นทางที่ไม่ได้รับอนุญาตอย่างชัดแจ้ง ในโหมดแอคทีฟ (ต้องได้รับอนุญาตอย่างชัดเจน) มันจะสแกนรายการคำทั้งหมดโดยไม่คำนึงถึง robots.txt — เผยให้เห็นสิ่งที่เจ้าของไซต์พยายามซ่อนจากเครื่องมือค้นหา

ผลลัพธ์การค้นพบ — Portal.example.go.th

สแกนเสร็จภายใน 4 นาที 23 วินาที | ทดสอบแล้ว 35,241 เส้นทาง

PathStatusSizeSeverity
/wp-admin/200 โอเค12.4 กิโลไบต์วิกฤต
/phpmyadmin/200 โอเค8.1 กิโลไบต์วิกฤต
/backup_2023.sql/200 โอเค142 MBวิกฤต
/api/swagger.json200 โอเค44 กิโลไบต์สูง
/.env403 สิ่งต้องห้ามปานกลาง
/robots.txt200 โอเค310 บข้อมูล
/xmlrpc.php200 โอเค418 บสูง
/wp-config.php.bak200 โอเค6.2 กิโลไบต์วิกฤต

ขับเคลื่อนด้วยเครื่องยนต์ rcortex Elixir

การค้นพบ EASM ทั้งหมดตั้งแต่พอร์ตเครือข่ายไปจนถึงจุดสิ้นสุด API ที่รวบรวมข้อมูลไปจนถึงเส้นทางที่ค้นพบ สตรีมแบบเรียลไทม์ไปยังแบ็กเอนด์ rcortex Elixir ซึ่งขับเคลื่อนแดชบอร์ดสดที่ app.redsocs.com

🔎

การค้นพบ

การสแกนเครือข่าย การรวบรวมข้อมูล Spitolas เส้นทางที่ดุร้ายวิ่งกับทรัพย์สินของคุณ

สตรีมแบบเรียลไทม์

การค้นพบที่สตรีมไปยังโปรแกรม rcortex Elixir ผ่านทางไปป์ไลน์ GenServer ที่ปลอดภัย

🧠

ความสัมพันธ์แบบซีวีอี

ทุกเวอร์ชันบริการที่ค้นพบจะจับคู่กับฟีดภัยคุกคาม NVD, CISA KEV และ RedSocs

📊

แดชบอร์ด

การค้นพบที่ได้รับการจัดลำดับความสำคัญจะปรากฏใน app.redsocs.com ภายในไม่กี่วินาทีหลังจากค้นพบ

เริ่มการสแกน EASM ของคุณวันนี้

รู้จักพื้นผิวการโจมตีภายนอกของคุณก่อนที่ผู้โจมตีจะรู้ ขอการประเมิน EASM และรับรายงานฉบับสมบูรณ์เกี่ยวกับทรัพย์สิน บริการ และช่องโหว่ที่เปิดเผยต่อสาธารณะของคุณ

EASMPowered by rcortex Elixir Engine

See Your Domain Through
an Attacker's Eyes

RedSocs performs outside-in internet scanning of your public digital footprint — exactly as an attacker would. No agents. No credentials. Just the raw, unfiltered view of your exposure.

✓ No agent installation✓ No credentials required✓ Thai domain expertise✓ Continuous scanning

What Is External Attack Surface Management?

Outside-in scanning means RedSocs discovers and probes your public internet footprint exactly as a real attacker would — from the outside, without any privileged access, internal agents, or pre-configured credentials.

This approach captures your true external exposure: assets you may have forgotten about, services accidentally exposed to the internet, shadow IT infrastructure provisioned without security review, and historical digital artifacts still indexed and reachable.

EASM is the first step in any offensive security program. You cannot defend what you don't know exists. RedSocs continuously maps your attack surface so your security team always has a complete, current inventory.

  • Discovers shadow assets: forgotten subdomains, decommissioned services, staging environments
  • Identifies unexpected open ports and non-standard services
  • Crawls SPAs and dynamic web apps for hidden API endpoints
  • Brute-forces directory paths for exposed admin panels and backup files
  • Correlates all findings with CVE databases and threat intelligence

Attacker's Perspective

1

Passive Recon

DNS enumeration, certificate transparency, WHOIS

2

Active Scanning

Port scanning, service fingerprinting, banner grabbing

3

Web Crawling

SPA navigation, API endpoint discovery, path brute-force

4

Vulnerability Correlation

CVE matching, threat intel correlation, risk scoring

Network Footprint Discovery

Before any application-layer scanning begins, RedSocs maps your complete network footprint — every IP address, every open port, every running service that is visible from the public internet.

🔍

Open Port Discovery

Full TCP/UDP port scanning across all IP ranges associated with your organisation — including cloud provider ranges, CDN edge nodes, and historical allocations. Identifies services that should not be internet-facing.

  • Full 65,535-port sweep on critical assets
  • Top-1000 port sweep across all assets
  • Service version fingerprinting (Nginx, Apache, OpenSSH, MySQL…)
  • SSL/TLS certificate enumeration and validation
👻

Shadow Protocol Detection

Find services deliberately or accidentally running on non-standard ports — a common attacker trick to evade basic perimeter monitoring. RedSocs fingerprints services regardless of port number.

  • SSH on port 2222, 2200, or 22222
  • MySQL or PostgreSQL on non-default ports
  • Redis, Memcached, Elasticsearch exposed publicly
  • RDP, VNC, and remote management protocols
🗺️

IP Ownership Mapping

Map all IP addresses and ASNs associated with your organisation — including those you may not know about from legacy allocations, subsidiary companies, and third-party hosting arrangements.

  • ASN enumeration and CIDR range discovery
  • Cloud asset identification (AWS, GCP, Azure, Alibaba Cloud)
  • CDN and WAF presence detection (Cloudflare, Akamai, Fastly)
  • Geolocation and hosting provider attribution

Spitolas SPA Crawler

Modern web applications are built with JavaScript frameworks that traditional HTTP scanners cannot explore. Spitolas is RedSocs' headless browser-based crawling engine — it navigates your application exactly as a human user would.

🖱️

Human-Like Navigation

Clicks buttons, fills forms, scrolls through infinite-scroll pages, waits for async data loads, and handles complex client-side routing in React, Vue, Angular, and Thai-language CMS frameworks.

📡

Hidden API Interception

Captures all network requests made during navigation — XHR calls, Fetch API requests, WebSocket connections — revealing API endpoints that are never documented but are fully accessible from the public internet.

🔑

Undocumented Endpoint Discovery

Identifies internal API endpoints, admin-only routes accidentally accessible without authentication, and data endpoints returning sensitive information to unauthenticated users.

🇹🇭

Thai-Language & Complex JS Support

Handles Thai Unicode correctly in form inputs and URL parameters. Supports complex JavaScript frameworks including Thai government e-service portals built on proprietary CMS platforms.

spitolas-crawler v2.4.1
[10:24:01] [INIT] Launching headless browser for portal.example.go.th
[10:24:03] [NAV] Loading / → React SPA detected (Next.js 14.2)
[10:24:05] [NAV] Clicking navigation links → 12 routes discovered
[10:24:08] [XHR] GET /api/v1/products?page=1 → 200 (leaked user IDs in response)
[10:24:09] [XHR] POST /api/internal/admin/stats → 401 (endpoint exists, unprotected)
[10:24:11] [XHR] GET /api/v2/user/profile → 200 (PII in response body)
[10:24:14] [SCROLL] Infinite scroll triggered → 3 additional API calls captured
[10:24:16] [ALERT] Undocumented endpoint /api/internal/admin/export — no auth check
[10:24:18] [DONE] 47 endpoints discovered | 3 high-severity findings | 12 routes mapped

Path Discovery Engine

is RedSocs' directory and path brute-forcing engine. It systematically probes your web assets for hidden admin panels, backup files, exposed configuration files, and sensitive paths using a carefully curated 35,000+ path wordlist.

📖 Thai-Aware Wordlist

35,000+ paths including Thai government CMS patterns, common Thai e-commerce admin paths, Thai-language Drupal modules, WordPress installations common in the Thai market, and local hosting provider default configurations.

🚪 Admin Panel Detection

Identifies exposed admin interfaces — /admin, /phpmyadmin, /cPanel, /wp-admin, /administrator, /manager, and hundreds of application-specific paths for popular Thai-market software.

💾 Backup File Discovery

Flags accessible backup files containing database dumps or source code: .sql, .bak, .tar.gz, .zip, db_backup.sql, website_backup_2024.zip — common mistakes that expose full database contents.

🤖 robots.txt Aware

In passive mode, respects robots.txt and only scans paths not explicitly disallowed. In active mode (requires explicit permission), it scans the full wordlist regardless of robots.txt — revealing what site owners try to hide from search engines.

Discovery Results — portal.example.go.th

Scan completed in 4m 23s | 35,241 paths tested

PathStatusSizeSeverity
/wp-admin/200 OK12.4 KBCRITICAL
/phpmyadmin/200 OK8.1 KBCRITICAL
/backup_2023.sql/200 OK142 MBCRITICAL
/api/swagger.json200 OK44 KBHIGH
/.env403 ForbiddenMEDIUM
/robots.txt200 OK310 BINFO
/xmlrpc.php200 OK418 BHIGH
/wp-config.php.bak200 OK6.2 KBCRITICAL

Powered by rcortex Elixir Engine

All EASM findings — from network ports to crawled API endpoints to discovered paths — stream in real time to the rcortex Elixir backend, which powers the live dashboard at app.redsocs.com.

🔎

Discovery

Network scan, Spitolas crawl, path brute-force run against your assets

Real-Time Stream

Findings streamed to rcortex Elixir engine via secure GenServer pipeline

🧠

CVE Correlation

Every discovered service version matched against NVD, CISA KEV, and RedSocs threat feeds

📊

Dashboard

Prioritized findings appear in app.redsocs.com within seconds of discovery

Start Your EASM Scan Today

Know your external attack surface before attackers do. Request an EASM assessment and get a full report of your publicly exposed assets, services, and vulnerabilities.