# Attack surface: include the forgotten paths

https://thiago.limaesilvatecnologia.com.br/en/artigos/attack-surface/

Published: 2026-09-12

Reviewing only the main application misses integrations.

Content produced with AI assistance for Thiago Silva’s website. Independent editorial analysis; it does not represent clients or employers.

Reading-path month: January 2026

Collection published on September 12, 2026. Months organize the reading path; they are not earlier publication dates.

A short architecture article. The technical reference supports the topic; hypothetical scenarios and assessment proposals are editorial analysis, not accounts of personal implementations.

## The architecture decision

A portal may be well protected while an old export endpoint remains accessible. The architectural problem is the gap between the system the team describes and the paths still operating.

## Practical application

Editorial proposal: compare the diagram with actual routes, DNS, integrations and administrative interfaces. Include monthly jobs and supplier access. Assign each entry an owner and purpose; infrequent use does not imply low risk.

## How to verify

As an exercise, select a supposedly retired integration and verify its removal with operations. An ownerless record should trigger investigation. The review should deliver an evidenced decision to retain, restrict or remove each path.

## Sources

- [OWASP — Attack Surface Analysis Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/Attack_Surface_Analysis_Cheat_Sheet.html). Accessed: 2026-09-12.

[Profile: Thiago Silva | Cyber Architect](https://thiago.limaesilvatecnologia.com.br/en/perfil/)
