Cloud asset
A small public site built to make external exposure visible.
This intentionally simple AWS workload provides safe, measurable signals for asset discovery, DNS, technology fingerprinting, TLS and public-route inventory.
Web stack
Nginx
HTTP response fingerprintDNS
No-IP
Public A record and hostnameTLS
HTTPS ready
Certificate and expiry visibilityWhat the scan should discover
Each item is intentionally exposed as ordinary public information—never as a real weakness.
Attack surface
Public domain, IP address and web service
Web technology
Nginx server and standards-based HTML
Subdomains
Optional portal and status DNS records
SSL certificate
Issuer, validity and expiry once enabled
Internet exposure
Only HTTP/HTTPS intended for public access
Public metadata
robots.txt, sitemap.xml and security.txt
API inventory
OpenAPI specification plus health and version endpoints
Software inventory
Public SBOM with declared server components
Security headers
CSP, HSTS, framing and MIME-sniffing protections
Email posture
DNS policies require a domain you own
Predictable paths, zero sensitive data
Useful for page discovery and inventory validation. Restricted-looking pages are static demonstrations only.
/loginDemo sign-in pageSTATIC →/adminAccess-denied demonstration403 DEMO →/robots.txtCrawler directivesTEXT →/sitemap.xmlPublic route inventoryXML →/openapi.jsonMachine-readable API inventoryJSON →/sbom.jsonSoftware bill of materialsJSON →/api/health.jsonNon-sensitive service statusJSON →/manifest.webmanifestApplication metadataJSON →Website signals versus integrations
A public site supplies external evidence. Account and endpoint controls must come from their authoritative systems.
Directly testable
Internet assets, DNS resolution, TLS, technologies, public APIs, exposed files, headers and software inventory.
Cloud and firewall posture
IAM, EC2, VPC, security groups, logging, encryption, patching and configuration findings.
Separate evidence required
Microsoft Zero Trust, endpoint inventory, email controls, code repositories and dark-web monitoring.
No real secrets. No customer data. No exploit path.
The lab uses synthetic content and read-only pages. SSH remains limited to the administrator’s IP, while only ports 80 and 443 are intended for public access.
● CONTROLLED