Ανάπτυξη ολοκληρωμένου μηχανισμού απογραφής και διαχείρισης επιφάνειας απειλών
Development of an integrated mechanism for automated inventorying and Attack Surface Management (ASM)

View/ Open
Keywords
Κυβερνοασφάλεια ; Εξωτερική επιθετική επιφάνειαAbstract
This thesis addresses the development of an integrated mechanism and procedures for the
automated inventory of an organisation's attack surface (Attack Surface Management — ASM)
and the timely alerting on known vulnerabilities. The tool, named WebSocRates ASM, is
implemented as an orchestrated Python pipeline that combines well-established open-source
utilities from the ProjectDiscovery ecosystem (subfinder, httpx, naabu, nuclei).
The approach is structured in three phases: discovery (subdomains, live endpoints and open
ports), validation (targeted vulnerability scanning with nuclei) and reporting (generation of an
interactive HTML dashboard enriched with the CISA Known Exploited Vulnerabilities feed, with
optional email delivery). The architecture, the functional and non-functional requirements, and
a comparative positioning against existing solutions are presented.


