How to Inventory Internet-Facing File Transfer and Integration Services
Retrospective: this article looks back at events from June 2023, written in 2026 with the benefit of hindsight.
Attackers repeatedly target internet-facing file transfer, integration and remote access services. Here is how to inventory them so you can patch, restrict or retire them quickly.
Step 1: Discover from the outside
Use an external attack surface management tool (such as Microsoft Defender External Attack Surface Management) or scheduled external scans to list internet-facing hosts, open ports, software and certificates across your domains and cloud IP ranges.
Step 2: Discover from the inside
- Azure: Azure Resource Graph for public IPs, App Services, Application Gateways and Front Door endpoints.
- AWS: list Elastic IPs, internet-facing load balancers, API Gateways, CloudFront distributions and EC2 instances with public IPs (AWS Config advanced queries help).
- Network team: firewall NAT rules and published services.
Step 3: Categorize
Tag each service: file transfer (MOVEit, GoAnywhere, SFTP servers), VPN and remote access, email, web applications, APIs, admin interfaces, integration platforms.
Step 4: Assign owners and data sensitivity
Each service needs a technical owner and a data classification.
Step 5: Reduce
- Retire unused services.
- Restrict access by IP or put services behind identity-aware access.
- Shorten data retention on file transfer platforms.
Step 6: Link to vulnerability response
Subscribe owners to vendor advisories. Add these systems to your emergency patching process.
Step 7: Monitor
WAF in front of web-based services; logs to your SIEM; alerts on new internet-facing services appearing.
Verify
Reconcile the external scan with your inventory monthly. Anything not on the list is shadow IT to investigate.