Glossary › Patterns
Reference · Patterns
Patterns
The openings we find most often from outside, each with why it matters, a check anyone can run and the direction of the fix.
Patterns 14By LeakTrace
Credential exposure
Credentials in monitored breach databases reused on production login
Employee credentials appearing in monitored breach databases are still active on the corporate SSO or VPN, giving attackers a direct password-spray path.
Critical
Infrastructure
Application admin panel exposed to the public internet
A CMS or application admin login page (WordPress, Django, phpMyAdmin, GitLab, custom SaaS) is reachable from any IP without authentication gating, IP allowlisting, or VPN.
High
Public TLS certificate approaching expiry without automated renewal
A production-facing TLS certificate is within the browser warning window and shows no evidence of ACME/auto-renewal, risking a hard outage and browser trust warnings.
Medium
Subdomain takeover risk on abandoned CNAME
A DNS CNAME record points to a third-party service (Heroku, S3, GitHub Pages, Zendesk, etc.) that no longer claims the subdomain, allowing anyone to register it and impersonate the parent domain.
High
Email authentication
DKIM signing absent on the primary mail sender
A domain's outbound mail is not cryptographically signed, so receivers cannot verify integrity or authenticity beyond IP-based SPF.
Medium
SPF configured without DMARC alignment
A domain publishes an SPF record but no DMARC policy, leaving receivers with no instruction on how to handle unauthenticated mail.
High
Supply chain
Unmaintained marketing vendor with historical corporate data access
A marketing, analytics, or engagement vendor that once had customer or employee data access remains contracted (paying) or connected (integration live), despite no active use, extending the exposure surface.
Medium
Cloud misconfiguration
S3 bucket permissions allowing anonymous list
A production or backup S3 bucket is configured to allow anonymous LIST operations, exposing the object inventory (and often the object contents) to any unauthenticated caller.
High
Insider threat
Departed employee retains SSO or SaaS access post-departure
A former employee's corporate SSO, individual SaaS accounts, or personal-device-linked corporate app access remains active after their departure date.
High
Phishing infrastructure
Lookalike domain registered against the corporate brand
A recently-registered domain uses a visual or typographical variation of the corporate name (typo-squat, IDN homograph, tenant-suffix squat) and is likely being staged for wire-fraud pretext.
High
Paste site leak
Executive email addresses harvested from paste sites
Public paste-site archives contain executive email addresses paired with breached passwords, providing an off-the-shelf target list for BEC.
High
Code / repository leak
API keys committed to public GitHub repositories
Employee or contractor GitHub accounts host public repositories containing plaintext API keys, cloud credentials, or database connection strings for the corporate tenant.
Critical
Exposed .git directory on a production web server
A production web server exposes its `.git/` directory over HTTP, allowing anyone to reconstruct the full source tree, including secrets committed to history.
Critical
Third-party / vendor risk
Outside adviser with no DMARC on its sending domain
A firm’s accountant, lawyer or broker sends mail from a domain with no DMARC policy, so email in that adviser’s name can be forged to ask the firm for a payment.
Critical
See what is open from outside before anyone else does. Check my firm →