SHODAN, Rapid7, Censys and others have made vast swaths of raw data scan data available to researchers over the last 10 years, but enumerating the exposed attack surface of a given organization remains an open challenge. Database leaks, application layer misconfigurations and default creds still pose significant risk to security teams. We are left living the unpleasant reality: “You can’t fix what you can’t find”. In this session, the speaker will dig into the open source Intrigue Core engine, a framework to iteratively enumerate attack surface, walking through lessons learned and exposures found while scaling the engine to discover the attack surface of tens of thousands of organizations.