Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Zscaler: How Attackers Find Your Network Attack Surface

Zscaler
06/21/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


My name is Brian Dietsch and welcome to my TED Talk. It turns out this is not a TED Talk, they haven't invited me yet. This is actually going to be a three-part mini-series called, If It's Reachable, It's Breachable. And we'll be looking at this through the lens of like the bad guy, the bad girl, the adversary that's trying to come in here and take advantage of your network. We'll be talking about how they find you, how they classify you, and how they exploit you, but how they leverage AI to help accelerate this. And yeah, you guessed it, we're also going to be talking about how ZStore can help prevent all this from happening. So follow along with me, I think you'll have a good time. Just about every breach kind of starts off the exact same way, which is you have some type of asset that's connected to the internet that you forgot about. It could be like standard like this, like you know, the cloud, whether you have an east or west, same thing with the data centers, HQ, factory, branch office, maybe you did like a merger or acquisition, we have some assets that are out there, maybe even like a developer environment that's coming through. And at the end of the day, the bad guy, the bad girl, the adversary is trying to come in here and find that attack surface, and they're using a bunch of different tools to do so. Now, some of the tools that they can be using, like maybe even Nmap, Snowden, Census, ZoomEye, what they're doing is they're looking for IP addresses, host names, admin portals, production environments, test environments, other domains that are out there. Now, the unfortunate fact is like you can use all these tools, be a little bit time consuming, but from an adversary perspective, there actually is a better way. Now, let's be real, the attackers, they can come out, use these different scripting tools that are out there, there could be a little bit of a learning curve. So it could be a little bit challenging, and sometimes even those apps, they just get so old, they just break. And so AI is helping, unfortunately, the adversary kind of do their evil deeds as well. So when it comes time to finding your attack surface, the attacker can just go out there and be like, hey, I'm interested in Acme, and I want to kind of know everything about it. And then in a series of prompts, get a good idea of like where all of your locations are, where all of your ASNs, things like that, and be able to map out your network externally, that external attack surface. And what they're going to get at the end of the day is your IP addresses. And again, if it's reachable, it's reachable, that's inbound traffic that's sitting there. And then last but not least, to be able to maybe find out some of the domains that you're using, not even your, not just your production domains, but even like your test dev environments as well. And where AI really helps accelerate this is it kind of diminishes that learning curve. But then too, let's say it scans your entire network, finds all this stuff, and you have like 100,000 IP addresses, these endpoints that are externally facing. Normally, you'd have to sit there and try to figure out like how to prioritize it. Or you can just ask AI to prioritize the top 100, 200, and then set your target on that. It's a whole nother world to find the IP address or the domain. It's a whole nother world to come back through there and figure out what is the service that's running behind that IP address, which is in our next video.

TL;DR

  • Breaches typically start with forgotten internet-connected assets across cloud, data centers, branches, and M&A environments that attackers discover through reconnaissance
  • Traditional scanning tools like Nmap, Shodan, and Censys help attackers identify IP addresses, domains, and admin portals, but require technical expertise
  • AI has transformed attack surface discovery by eliminating the learning curve and automatically prioritizing the most vulnerable targets from thousands of exposed endpoints

Summary

This educational video examines how adversaries discover and map external attack surfaces from the attacker's perspective. Brian Dietsch explains that most breaches begin with forgotten internet-connected assets across cloud environments, data centers, branch offices, and merger acquisitions. Attackers traditionally use reconnaissance tools like Nmap, Shodan, Censys, and ZoomEye to identify IP addresses, hostnames, admin portals, and test environments. However, the presentation reveals how AI has dramatically accelerated this discovery process by eliminating the learning curve associated with traditional scanning tools and enabling attackers to automatically prioritize the most vulnerable targets from thousands of exposed endpoints. The video sets up a three-part series exploring how attackers find, classify, and exploit reachable assets, while positioning Zscaler's Zero Trust approach as a defensive strategy against these reconnaissance techniques.

Chapters

0:00 - Series Introduction
0:43 - How Breaches Begin
1:12 - Traditional Reconnaissance Tools
1:45 - AI-Powered Attack Surface Discovery

Key Quotes

0:43 "Just about every breach kind of starts off the exact same way, which is you have some type of asset that's connected to the internet that you forgot about."
2:31 "And again, if it's reachable, it's reachable, that's inbound traffic that's sitting there."
2:47 "And where AI really helps accelerate this is it kind of diminishes that learning curve."

FAQ

What tools do attackers use to discover external attack surfaces?

Attackers use reconnaissance tools like Nmap, Shodan, Censys, and ZoomEye to scan for IP addresses, hostnames, admin portals, production environments, test environments, and domains. Increasingly, they're leveraging AI to automate and accelerate this discovery process without requiring deep technical expertise.

How has AI changed the way attackers find vulnerable assets?

AI has eliminated the learning curve associated with traditional scanning tools and can automatically prioritize the most vulnerable targets. Attackers can now use simple prompts to map entire networks, discover all locations and ASNs, and have AI prioritize the top 100-200 most promising targets from potentially 100,000 exposed endpoints.


Categories:
  • » Webinar Library » Zscaler
  • » Cybersecurity » Zero Trust
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Threat Intelligence
  • Zero Trust
  • AI & Machine Learning
  • Security Operations
  • Getting Started
  • Attack Surface Management
  • Reconnaissance Techniques
  • AI-Enabled Threats
  • Zero Trust Security
  • External Attack Surface
  • Network Scanning
  • Security Awareness
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Zscaler: How Attackers Find Your Network Attack Surface

              Industry Events (Sponsor Hosted)

              • Aug
                06

                Safeguarding Sensitive Data in the Age of AI Platforms

                08/06/202604:00 AM ET
                • Aug
                  06

                  AI Agents Transforming Identity Attack Tactics and Speed

                  08/06/202602:00 PM ET
                  • Aug
                    13

                    Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada

                    08/13/202612:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 08/06/2026
                      04:00 AM
                      08/06/2026
                      Safeguarding Sensitive Data in the Age of AI Platforms
                      https://www.truthinit.com/index.php/channel/2058/safeguarding-sensitive-data-in-the-age-of-ai-platforms/
                    • 08/06/2026
                      02:00 PM
                      08/06/2026
                      AI Agents Transforming Identity Attack Tactics and Speed
                      https://www.truthinit.com/index.php/channel/2064/ai-agents-transforming-identity-attack-tactics-and-speed/
                    • 08/13/2026
                      12:00 PM
                      08/13/2026
                      Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                      https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                    • 08/19/2026
                      12:00 PM
                      08/19/2026
                      Becoming Agent Ready with Cyera: Essential Strategies and Insights
                      https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                    • 09/02/2026
                      12:00 PM
                      09/02/2026
                      Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                      https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Optimizing Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version