Report
Beyond the Web: Non-Web Attack Surface Report
This report examines how attackers exploit non-web protocols to evade defenses and create hidden paths for command-and-control, data theft, lateral movement, and persistence. It identifies DNS as the dominant non-web threat vector, accounting for 83.8% of activity, with abuse ranging from tunneling and dynamic records to algorithmic domains. It analyzes SSH, SMB, SMTP, RDP, FTP, NTP, LDAP, DHCP, and torrent-based activity, showing how legacy vulnerabilities, brute force, anonymizers, Cobalt Strike, Chisel, TOR, and backdoors support intrusion chains. Retail, manufacturing, healthcare, technology, and energy are key targets. The report recommends DNS security, cloud IPS, AI-powered detection, least-privilege firewall policy, threat intelligence, and Zero Trust controls to close blind spots.
