ATTACK SURFACE INTELLIGENCE

See what is actually exposed.

Fray discovers, validates and explains your attack surface — then gives your AI the evidence to reason about it.

Non-destructiveNo account requiredAuthorized domains only
Discover → Validate → Understand
example.com
Ready to scan
FRAY ENGINE
VERIFYING TARGET
example.com
example.com IDLE
NEW ASSETapi.example.comNext.js · HTTP 200
UNEXPECTED EXPOSUREadmin.example.comLogin surface detected
CORRELATING INFRASTRUCTURE93.184.xxx.xxx3 related assets · 2 shared signals · evidence linked
FRAY BROWSERISOLATED
example.com
Entering the page…
FRAY · INTERNET INVESTIGATION The surface awakens

Fray is searching the invisible paths around the target.

Attack Surface Investigation
Discover → Validate → Understand
Example result · gitlab.com
27assets
14technologies
6Security Findings
HIGHrisk level

Enter your domain above and hit "Investigate" to see your own results here.

QUICK SCAN COMPLETE
Attack surface understood.
6 findings
0Critical
3High
2Medium
1Low

27 assets discovered · 6 security signals

3 verified 2 likely 1 insufficient evidence

Investigate →
ATTACK SURFACE GRAPH

How the surface connects

Fray connects assets, infrastructure and evidence into one investigation path.

Asset Infrastructure Evidence
example.com TARGET api.example.com Next.js · HTTP 200 admin.example.com Login surface staging.example.com Public surface 93.184.xxx.xxx 3 related assets Evidence DNS · HTTP · TLS
INVESTIGATION PATH 3 assets converge on shared infrastructure. Select a node to see what evidence connects it to the rest of the surface.

What Matters

6 security signals · 1 critical · 3 high
View full example report →
CRITICAL

WAF boundary bypass

4 assets appear reachable outside the expected security boundary.

VERIFIEDevidence-based
✓ Resolves outside Cloudflare's published IP ranges
✓ Direct connection confirmed on port 443, no WAF headers present
✓ Confirmed independently across 4 separate assets
HIGH

Public staging environment

staging.example.com is externally reachable and exposes the production stack.

LIKELYneeds confirmation
✓ Publicly reachable, resolves and responds over HTTPS
✓ Shares technology fingerprint with production
○ Login interface not yet confirmed by browser isolation
HIGH

Administrative surfaces exposed

3 administrative interfaces are publicly discoverable.

VERIFIEDevidence-based
✓ Publicly reachable, no IP restriction detected
✓ Login interface detected by browser isolation
✓ Browser snapshot captured as visual evidence
✓ Origin correlation confirmed against known infrastructure
WHAT FRAY LOOKS AT
Attack SurfaceSubdomains, ports, exposed services
Infrastructure IntelligenceDNS, hosting, WAF/CDN
DNS & TLSCertificates, DNSSEC, mail security
TechnologyFrameworks, servers, versions
Web ExposureAdmin panels, staging environments
Browser EvidenceIsolated rendering, screenshots
Ask Fray
Why is this risky? What should I fix first? What changed?
Attack Surface Assessment
Investigation
How Fray verifies findings: discovery signals are checked against independent HTTP, browser, transport, and infrastructure evidence. Fray separates verified findings from leads that still need confirmation.
Quick Scan
Browser Verification
Isolated Browser
Evidence
5 independent signals

gitlab.com

Scanned just now · Profile: Standard · Cloudflare WAF detected · Detection does not imply full attack-surface protection.
56HIGH RISK
13Subdomains
6security findings
8Admin Panels Exposed
60Admin Paths Checked
78/100Headers Score
TLS 1.2via Cloudflare
TL;DR — 30-Second Read

Some security issues were found — address the high-severity ones within the next week.

The investigation identified 6 Security Findings: 1 Critical, 3 High, 1 Medium, and 1 Low. Cloudflare WAF detected.

  • 8 admin login page(s) confirmed publicly accessible (of 60 paths checked) — restrict access by IP
  • Your staging/dev site is publicly accessible — it may have weaker security

What Matters

6 security signals · 1 critical · 3 high
CRITICAL

Origin Outside Expected WAF Boundary

4 assets appear reachable outside the expected security boundary.

Evidence
✓ Resolves outside Cloudflare's published IP ranges
✓ Direct HTTPS connection confirmed on port 443
✓ No expected WAF headers observed
✓ Confirmed independently across 4 separate assets
VERIFIED
Evidence-based
HIGH

Admin Panels Publicly Accessible

8 admin login pages confirmed exposed, out of 60 paths checked.

VERIFIED
Evidence-based
HIGH

GraphQL Introspection Enabled

Full schema is exposed at /api/graphql to any caller — no auth required to query it.

VERIFIED
Evidence-based
MEDIUM

Public Staging / Internal Environment

admin.demo.fray.info ↗ and staging.demo.fray.info ↗ are publicly reachable. Their security posture may differ from production.

Evidence
✓ DNS resolution
✓ HTTP response
✓ Publicly reachable
⚠ Production-equivalent controls not verified
LIKELY
Evidence-based
LOW

2 subdomains behind a different CDN

registry.gitlab.com (Google CDN) and status.gitlab.com (CloudFront) — not a WAF bypass, just a different provider than Cloudflare.

VERIFIED
evidence-based
HIGH

136 origin IP candidates found

Sourced from MX/SPF records — most trace to third-party mail (Google) and billing (Zuora) infrastructure, not gitlab's own origin.

INSUFFICIENT EVIDENCE
0 of 136 candidates confirmed

Attack surface

13 subdomains · 63 high-value targets
Staging / Dev2 environment(s)
admin.demo.fray.infostaging.demo.fray.info
Payment / E-Commerce1 environment(s)
shop.gitlab.com
Admin Panels60 path(s) checked · 8 confirmed exposed
Show admin paths
/admin ⚠ exposed/wp-admin ⚠ exposed /administrator ⚠ exposed/cpanel ⚠ exposed /manage/console/panel… 52 more

Remediation plan

5 action items
1

Block direct-to-origin access CRITICAL

Why — admin.demo.fray.info and api.demo.fray.info resolve directly to origin, bypassing Cloudflare WAF entirely.
How — Restrict the origin firewall to Cloudflare's published IP ranges; route both subdomains through the CDN/WAF.
2

Restrict exposed admin panels HIGH

Why — 8 admin login pages confirmed publicly accessible (of 60 paths checked).
How — IP-allowlist or VPN-gate admin paths; enforce MFA; rename or remove default paths.
3

Disable GraphQL introspection HIGH

Why — Introspection confirmed enabled at /api/graphql, exposing the full schema to any caller.
How — Disable introspection in production; add query depth/complexity limits.
4

Remove exposed sensitive file CRITICAL

Why — /.env is publicly accessible.
How — Block access via web server config, remove from webroot, or add authentication.
5

Enable DNSSEC MEDIUM

Why — DNS responses are not signed — vulnerable to spoofing/cache poisoning.
How — Enable DNSSEC signing at your DNS provider (Cloudflare, Route53, etc.).
Ask FrayWhy is this risky? What should I fix first? What changed since the last scan?

Technical details

For engineers — full evidence below
DNS & Email DNSSEC not enabled · SPF/DMARC missing
NSdiva.ns.cloudflare.com, jermaine.ns.cloudflare.com
MX1 aspmx.l.google.com, 10 alt3.aspmx.l.google.com
DNSSEC✗ Not enabled
SPF✗ Missing
DMARC✗ Missing
Security Headers 78/100
MissingCOOP (low), CORP (low)
Technologies 0 detected this scan

No technologies detected — re-run with --deep for subdomain-level fingerprinting.

Rate Limits fixed-window · 500 req
ratelimit-limit500
ratelimit-remaining458
Suggested validation tests 4 categories

csp_bypass · modern_bypasses · prototype_pollution · ssti — run fray test https://gitlab.com -c <category> --smart for details on each.

← Scan another domain
Fray — DALI Security Reconnaissance Engine
CONFIDENTIAL — this report contains sensitive security information. Share only with authorized personnel.
Fray is intended for authorized security testing only.
Report abuse · Acceptable Use Policy · Privacy