Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Zscaler: How Attackers Find Your Network Attack Surface

Zscaler
06/21/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


My name is Brian Dietsch and welcome to my TED Talk. It turns out this is not a TED Talk, they haven't invited me yet. This is actually going to be a three-part mini-series called, If It's Reachable, It's Breachable. And we'll be looking at this through the lens of like the bad guy, the bad girl, the adversary that's trying to come in here and take advantage of your network. We'll be talking about how they find you, how they classify you, and how they exploit you, but how they leverage AI to help accelerate this. And yeah, you guessed it, we're also going to be talking about how ZStore can help prevent all this from happening. So follow along with me, I think you'll have a good time. Just about every breach kind of starts off the exact same way, which is you have some type of asset that's connected to the internet that you forgot about. It could be like standard like this, like you know, the cloud, whether you have an east or west, same thing with the data centers, HQ, factory, branch office, maybe you did like a merger or acquisition, we have some assets that are out there, maybe even like a developer environment that's coming through. And at the end of the day, the bad guy, the bad girl, the adversary is trying to come in here and find that attack surface, and they're using a bunch of different tools to do so. Now, some of the tools that they can be using, like maybe even Nmap, Snowden, Census, ZoomEye, what they're doing is they're looking for IP addresses, host names, admin portals, production environments, test environments, other domains that are out there. Now, the unfortunate fact is like you can use all these tools, be a little bit time consuming, but from an adversary perspective, there actually is a better way. Now, let's be real, the attackers, they can come out, use these different scripting tools that are out there, there could be a little bit of a learning curve. So it could be a little bit challenging, and sometimes even those apps, they just get so old, they just break. And so AI is helping, unfortunately, the adversary kind of do their evil deeds as well. So when it comes time to finding your attack surface, the attacker can just go out there and be like, hey, I'm interested in Acme, and I want to kind of know everything about it. And then in a series of prompts, get a good idea of like where all of your locations are, where all of your ASNs, things like that, and be able to map out your network externally, that external attack surface. And what they're going to get at the end of the day is your IP addresses. And again, if it's reachable, it's reachable, that's inbound traffic that's sitting there. And then last but not least, to be able to maybe find out some of the domains that you're using, not even your, not just your production domains, but even like your test dev environments as well. And where AI really helps accelerate this is it kind of diminishes that learning curve. But then too, let's say it scans your entire network, finds all this stuff, and you have like 100,000 IP addresses, these endpoints that are externally facing. Normally, you'd have to sit there and try to figure out like how to prioritize it. Or you can just ask AI to prioritize the top 100, 200, and then set your target on that. It's a whole nother world to find the IP address or the domain. It's a whole nother world to come back through there and figure out what is the service that's running behind that IP address, which is in our next video.

TL;DR

  • Breaches typically start with forgotten internet-connected assets across cloud, data centers, branches, and M&A environments that attackers discover through reconnaissance
  • Traditional scanning tools like Nmap, Shodan, and Censys help attackers identify IP addresses, domains, and admin portals, but require technical expertise
  • AI has transformed attack surface discovery by eliminating the learning curve and automatically prioritizing the most vulnerable targets from thousands of exposed endpoints

Summary

This educational video examines how adversaries discover and map external attack surfaces from the attacker's perspective. Brian Dietsch explains that most breaches begin with forgotten internet-connected assets across cloud environments, data centers, branch offices, and merger acquisitions. Attackers traditionally use reconnaissance tools like Nmap, Shodan, Censys, and ZoomEye to identify IP addresses, hostnames, admin portals, and test environments. However, the presentation reveals how AI has dramatically accelerated this discovery process by eliminating the learning curve associated with traditional scanning tools and enabling attackers to automatically prioritize the most vulnerable targets from thousands of exposed endpoints. The video sets up a three-part series exploring how attackers find, classify, and exploit reachable assets, while positioning Zscaler's Zero Trust approach as a defensive strategy against these reconnaissance techniques.

Chapters

0:00 - Series Introduction
0:43 - How Breaches Begin
1:12 - Traditional Reconnaissance Tools
1:45 - AI-Powered Attack Surface Discovery

Key Quotes

0:43 "Just about every breach kind of starts off the exact same way, which is you have some type of asset that's connected to the internet that you forgot about."
2:31 "And again, if it's reachable, it's reachable, that's inbound traffic that's sitting there."
2:47 "And where AI really helps accelerate this is it kind of diminishes that learning curve."

FAQ

What tools do attackers use to discover external attack surfaces?

Attackers use reconnaissance tools like Nmap, Shodan, Censys, and ZoomEye to scan for IP addresses, hostnames, admin portals, production environments, test environments, and domains. Increasingly, they're leveraging AI to automate and accelerate this discovery process without requiring deep technical expertise.

How has AI changed the way attackers find vulnerable assets?

AI has eliminated the learning curve associated with traditional scanning tools and can automatically prioritize the most vulnerable targets. Attackers can now use simple prompts to map entire networks, discover all locations and ASNs, and have AI prioritize the top 100-200 most promising targets from potentially 100,000 exposed endpoints.


Categories:
  • » Webinar Library » Zscaler
  • » Cybersecurity » Zero Trust
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Threat Intelligence
  • Zero Trust
  • AI & Machine Learning
  • Security Operations
  • Getting Started
  • Attack Surface Management
  • Reconnaissance Techniques
  • AI-Enabled Threats
  • Zero Trust Security
  • External Attack Surface
  • Network Scanning
  • Security Awareness
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Zscaler: How Attackers Find Your Network Attack Surface

              Upcoming Webinar Calendar

              • 07/14/2026
                01:00 PM
                07/14/2026
                Crafting a Championship-Worthy Security Team for Unmatched Defense
                https://www.truthinit.com/index.php/channel/2025/crafting-a-championship-worthy-security-team-for-unmatched-defense/
              • 07/14/2026
                02:00 PM
                07/14/2026
                Understanding the Crucial Role of Context in Safeguarding AI-Accessible Data
                https://www.truthinit.com/index.php/channel/2037/understanding-the-crucial-role-of-context-in-safeguarding-ai-accessible-data/
              • 07/21/2026
                04:00 AM
                07/21/2026
                Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
              • 07/22/2026
                06:30 AM
                07/22/2026
                Insights and Strategies in Data Protection and Privacy Management
                https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-in-data-protection-and-privacy-management/
              • 07/22/2026
                01:00 PM
                07/22/2026
                Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue
                https://www.truthinit.com/index.php/channel/2029/insights-from-attackers-during-the-fifa-world-cup-a-human-dialogue/
              • 07/28/2026
                01:00 PM
                07/28/2026
                Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
              • 07/29/2026
                04:00 AM
                07/29/2026
                Real-Time Strategies for Safeguarding Against Prompt Injections
                https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
              • 07/29/2026
                12:00 PM
                07/29/2026
                Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
              • 07/29/2026
                01:00 PM
                07/29/2026
                Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
              • 08/19/2026
                12:00 PM
                08/19/2026
                Becoming Agent Ready: Insights from Cyera's Expertise
                https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-from-cyeras-expertise/
              • 09/30/2026
                04:00 AM
                09/30/2026
                AI Command Center: Optimizing Visibility and Control in Your Operations
                https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/

              Upcoming Events

              • Jul
                14

                Crafting a Championship-Worthy Security Team for Unmatched Defense

                07/14/202601:00 PM ET
                • Jul
                  14

                  Understanding the Crucial Role of Context in Safeguarding AI-Accessible Data

                  07/14/202602:00 PM ET
                  • Jul
                    21

                    Strategies for Managing AI Governance and Securing App-to-LLM API Traffic

                    07/21/202604:00 AM ET
                    • Jul
                      22

                      Insights and Strategies in Data Protection and Privacy Management

                      07/22/202606:30 AM ET
                      • Jul
                        22

                        Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue

                        07/22/202601:00 PM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version