Attack Surface

Attack surface is the aggregate of reachable, exposure-relevant entry points—interfaces, services, identities, and paths—an organization must reason about when prioritizing reduction.

Attack Surface

Definition

Attack surface is the aggregate of reachable, exposure-relevant entry points an organization must reason about when understanding and reducing security exposure.

It includes interfaces, services, identities, network paths, and configuration states that could be reached or abused—not a raw count of open ports or a scanner inventory alone. Attack surface is a decision lens: which entry points matter now, given exposure context, relationships, and operational significance.

Attack surface differs from a vulnerability list by emphasizing where adversaries could interact with the environment, not merely what weaknesses exist in isolation.

SentriScope Usage

SentriScope relates attack surface to canonical assets, applications, exposures, and attack paths (KID-ARC-0001) so teams can explain which reachable entry points drive prioritization—not just how many findings exist. This entry defines the term only.

Related terms

Related Knowledge


Related Articles