ATTACK SURFACE INTELLIGENCE

See what is actually exposed.

Fray discovers, validates and explains your attack surface — then gives your AI the evidence to reason about it.

Non-destructiveNo account requiredAuthorized domains only
Discover → Validate → Understand
example.com
Ready to scan
FRAY ENGINE
VERIFYING TARGET
example.com
example.com IDLE
NEW ASSETapi.example.comNext.js · HTTP 200
UNEXPECTED EXPOSUREadmin.example.comLogin surface detected
CORRELATING INFRASTRUCTURE93.184.xxx.xxx3 related assets · 2 shared signals · evidence linked
FRAY BROWSERISOLATED
example.com
Entering the page…
FRAY · INTERNET INVESTIGATION The surface awakens

Fray is searching the invisible paths around the target.

Attack Surface Investigation
Discover → Validate → Understand
Example result · gitlab.com
27assets
14technologies
6Security Findings
HIGHrisk level

Enter your domain above and hit "Investigate" to see your own results here.

ATTACK SURFACE

How this surface connects

Discovered assets converge on shared infrastructure, backed by evidence. Click any step to see why Fray connected it.

3 discovered assets
EVIDENCE TIMELINE

What Fray found, in order

The real sequence this investigation followed — not a mockup, the actual pipeline that just ran.

📡
Step 1 · 1.2s into the scan — DNS resolution confirmed for the target
Domain resolves and is reachable
🔎
Step 2 · 4.6s into the scan — 3 assets discovered
api, admin, and staging subdomains found
⚙️
Step 3 · 6.7s into the scan — Technology fingerprint captured
Next.js identified on the API surface
🔒
Step 4 · 7.5s into the scan — TLS certificate inspected
Certificate and transport configuration checked
⚠️
Step 5 · 8.6s into the scan — Unexpected exposure detected
Admin login surface + WAF boundary gap identified
🖥️
Step 6 · 13.3s into the scan — Origin correlation + browser verification
93.184.xxx.xxx identified as shared infrastructure
Step 7 · 16.5s into the scan — Findings independently validated
6 findings confirmed against multiple evidence sources
What Fray looks at 6 categories
Attack SurfaceSubdomains, ports, exposed services
Infrastructure IntelligenceDNS, hosting, WAF/CDN
DNS & TLSCertificates, DNSSEC, mail security
TechnologyFrameworks, servers, versions
Web ExposureAdmin panels, staging environments
Browser EvidenceIsolated rendering, screenshots
Ask Fray
Why is this risky? What should I fix first? What changed?
Attack Surface Assessment

gitlab.com

Scanned just now · Quick Scan · Cloudflare WAF detected · Detection does not imply full attack-surface protection.
6 findings
0Critical
3High
2Medium
1Low

27 assets discovered · 6 security signals

3 need deeper verification — see Findings tab →

3VERIFIED
2LIKELY
1INSUFFICIENT EVIDENCE
Attack Surface Risk56/100
How Fray verifies findings: discovery signals are checked against independent HTTP, browser, transport, and infrastructure evidence. Fray separates verified findings from leads that still need confirmation.
Investigation
Quick Scan
Browser Verification
Isolated Browser

This report distinguishes Verified (independently confirmed), Likely (strong signal, confirmation pending), and Insufficient Evidence (not enough to classify either way) — Fray would rather under-claim than overstate what it found.

13Subdomains
6security findings
8Admin Panels Exposed
60Admin Paths Checked
78/100Headers Score
TLS 1.2via Cloudflare
Use with your AI
Fray sees. Your AI reasons.
Connect this attack surface to Claude, ChatGPT, or any MCP client — ask follow-up questions, re-investigate assets, correlate findings across scans.
fray mcp install
TL;DR — 30-Second Read

Some security issues were found — address the high-severity ones within the next week.

The investigation identified 6 Security Findings: 1 Critical, 3 High, 1 Medium, and 1 Low. Cloudflare WAF detected.

  • 8 admin login page(s) confirmed publicly accessible (of 60 paths checked) — restrict access by IP
  • Your staging/dev site is publicly accessible — it may have weaker security

What Matters

6 security signals · 1 critical · 3 high
3 verified 2 likely 1 insufficient evidence
CRITICAL

Origin Outside Expected WAF Boundary

4 assets appear reachable outside the expected security boundary.

Evidence
✓ Resolves outside Cloudflare's published IP ranges
✓ Direct HTTPS connection confirmed on port 443
✓ No expected WAF headers observed
✓ Confirmed independently across 4 separate assets
VERIFIED
Evidence-based
HIGH

Admin Panels Publicly Accessible

8 admin login pages confirmed exposed, out of 60 paths checked.

VERIFIED
Evidence-based
HIGH

GraphQL Introspection Enabled

Full schema is exposed at /api/graphql to any caller — no auth required to query it.

VERIFIED
Evidence-based
MEDIUM

Public Staging / Internal Environment

admin.demo.fray.info ↗ and staging.demo.fray.info ↗ are publicly reachable. Their security posture may differ from production.

Evidence
✓ DNS resolution
✓ HTTP response
✓ Publicly reachable
⚠ Production-equivalent controls not verified
LIKELY
Evidence-based
LOW

2 subdomains behind a different CDN

registry.gitlab.com (Google CDN) and status.gitlab.com (CloudFront) — not a WAF bypass, just a different provider than Cloudflare.

VERIFIED
evidence-based
HIGH

136 origin IP candidates found

Sourced from MX/SPF records — most trace to third-party mail (Google) and billing (Zuora) infrastructure, not gitlab's own origin. Fray will not classify these as exposed origins without independent confirmation.

INSUFFICIENT EVIDENCE
0 of 136 candidates confirmed

Attack surface

13 subdomains · 63 high-value targets
Staging / Dev2 environment(s)
admin.demo.fray.infostaging.demo.fray.info
Payment / E-Commerce1 environment(s)
shop.gitlab.com
Admin Panels60 path(s) checked · 8 confirmed exposed
Show admin paths
/admin ⚠ exposed/wp-admin ⚠ exposed /administrator ⚠ exposed/cpanel ⚠ exposed /manage/console/panel… 52 more

Remediation plan

5 action items
1

Block direct-to-origin access CRITICAL

Why — admin.demo.fray.info and api.demo.fray.info resolve directly to origin, bypassing Cloudflare WAF entirely.
How — Restrict the origin firewall to Cloudflare's published IP ranges; route both subdomains through the CDN/WAF.
2

Restrict exposed admin panels HIGH

Why — 8 admin login pages confirmed publicly accessible (of 60 paths checked).
How — IP-allowlist or VPN-gate admin paths; enforce MFA; rename or remove default paths.
3

Disable GraphQL introspection HIGH

Why — Introspection confirmed enabled at /api/graphql, exposing the full schema to any caller.
How — Disable introspection in production; add query depth/complexity limits.
4

Remove exposed sensitive file CRITICAL

Why — /.env is publicly accessible.
How — Block access via web server config, remove from webroot, or add authentication.
5

Enable DNSSEC MEDIUM

Why — DNS responses are not signed — vulnerable to spoofing/cache poisoning.
How — Enable DNSSEC signing at your DNS provider (Cloudflare, Route53, etc.).
Ask FrayWhy is this risky? What should I fix first? What changed since the last scan?

Technical details

For engineers — full evidence below
DNS & Email DNSSEC not enabled · SPF/DMARC missing
NSdiva.ns.cloudflare.com, jermaine.ns.cloudflare.com
MX1 aspmx.l.google.com, 10 alt3.aspmx.l.google.com
DNSSEC✗ Not enabled
SPF✗ Missing
DMARC✗ Missing
Security Headers 78/100
MissingCOOP (low), CORP (low)
Technologies 0 detected this scan

No technologies detected — re-run with --deep for subdomain-level fingerprinting.

Rate Limits fixed-window · 500 req
ratelimit-limit500
ratelimit-remaining458
Suggested validation tests 4 categories

csp_bypass · modern_bypasses · prototype_pollution · ssti — run fray test https://gitlab.com -c <category> --smart for details on each.

🤖 Fray sees. Your AI reasons.

MCP-native

This investigation — the evidence, the correlations, the attack path graph above — isn't just for reading. Connect Fray to Claude, ChatGPT, or any MCP-compatible AI, and it can query this attack surface directly: ask follow-up questions, correlate findings across scans, re-investigate a specific asset on demand.

Most tools stop at "here's what we found." Fray gives your AI the evidence to reason about why it matters — because the AI is working from verified, structured findings, not summarizing a PDF.

fray mcp install
Works with Claude Desktop, Claude Code, and any MCP-compatible client.
← Scan another domain
Fray — DALI Security Reconnaissance Engine
CONFIDENTIAL — this report contains sensitive security information. Share only with authorized personnel.
Fray is intended for authorized security testing only.
Report abuse · Acceptable Use Policy · Privacy