KNIGHTGUARD EXPOSURE VALIDATION

A small public site built to make external exposure visible.

This intentionally simple AWS workload provides safe, measurable signals for asset discovery, DNS, technology fingerprinting, TLS and public-route inventory.

IN SCOPE Public website and metadata OUT OF SCOPE Exploitation, credential testing and dark-web monitoring
01

Cloud asset

AWS EC2

Public Ubuntu web workload
02

Web stack

Nginx

HTTP response fingerprint
03

DNS

No-IP

Public A record and hostname
04

TLS

HTTPS ready

Certificate and expiry visibility
TEST MATRIX

What the scan should discover

Each item is intentionally exposed as ordinary public information—never as a real weakness.

Attack surface

Public domain, IP address and web service

01

Web technology

Nginx server and standards-based HTML

02

Subdomains

Optional portal and status DNS records

03

SSL certificate

Issuer, validity and expiry once enabled

04

Internet exposure

Only HTTP/HTTPS intended for public access

05

Public metadata

robots.txt, sitemap.xml and security.txt

06

API inventory

OpenAPI specification plus health and version endpoints

07

Software inventory

Public SBOM with declared server components

08

Security headers

CSP, HSTS, framing and MIME-sniffing protections

09

Email posture

DNS policies require a domain you own

10
PUBLIC ROUTES

Predictable paths, zero sensitive data

Useful for page discovery and inventory validation. Restricted-looking pages are static demonstrations only.

COVERAGE MAP

Website signals versus integrations

A public site supplies external evidence. Account and endpoint controls must come from their authoritative systems.

WEBSITE

Directly testable

Internet assets, DNS resolution, TLS, technologies, public APIs, exposed files, headers and software inventory.

AWS CONNECTOR

Cloud and firewall posture

IAM, EC2, VPC, security groups, logging, encryption, patching and configuration findings.

OTHER CONNECTORS

Separate evidence required

Microsoft Zero Trust, endpoint inventory, email controls, code repositories and dark-web monitoring.

SAFETY CONTROL

No real secrets. No customer data. No exploit path.

The lab uses synthetic content and read-only pages. SSH remains limited to the administrator’s IP, while only ports 80 and 443 are intended for public access.

● CONTROLLED