Weekly external attack surface drift report in Slack

By General Input

Check your public IPs against an approved baseline every Monday and get one grouped Slack alert covering only what actually changed.

Integrations

  • Shodan
  • Google Sheets
  • Slack

Type

Agentic Task

Categories

  • Engineering
  • Operations

Every Monday at 7am, review my company's external attack surface for drift and report it to my security channel in Slack.

Start by reading my watched asset list from Google Sheets with Get Values. Each row holds one public IP address or hostname, plus a column listing the ports that are approved to be open on that asset. Treat that column as the approved baseline. When a row holds a hostname rather than an IP, use the Shodan Resolve Hostnames operation to turn it into an IP address first, and carry the hostname through so I can still tell which asset a finding belongs to.

For each IP, call Shodan Get Host Information to pull the services, open ports, banners, and product versions Shodan currently observes, along with anything in the host's vulns list. Pace these lookups at roughly one request per second, because the Shodan API allows about one request per second and will return a rate limit error above that. If a single host lookup fails or Shodan has no record for that address, note it and keep going rather than aborting the whole run.

Also read back the history rows this workflow has appended on previous runs, using Get Values on the history tab, so you know what was last seen on each asset. Compare what Shodan sees now against both the approved baseline and the most recent history entry, and surface only the drift: ports that are open now but are not in the approved column, services whose product or version changed since the previous run, and any CVEs Shodan flags in vulns. Ports that are open and approved with no version change are not findings and should not be reported.

Post one grouped Slack message with Send a Message to my security channel. Group the findings by IP address rather than sending one alert per port, and lead with the highest risk items: exposed remote access on port 3389 or 22, databases reachable from the internet or without authentication, and admin panels or management interfaces. Everything else follows underneath. For each finding give me the asset (IP and hostname), the port, what Shodan sees running there including product and version, and one short line on why it matters.

Append every finding back into the Google Sheet with Append Values, one dated row per finding, capturing the run date, IP, hostname, port, the service and version observed, the finding type (newly open port, changed service or version, or flagged vulnerability), and a severity, so there is a running history I can look back through.

If nothing has drifted, stay quiet: post a single short all-clear message naming how many assets were checked and that everything matches the approved baseline, and do not append any finding rows that week.

Related prompts

Explore more prompts
Call overdue Xero customers with an AI collections agentLocal listing health board for every location you manageWin back LiveChat visitors whose chats went unansweredLet support send one-off Loops emails without an engineerStop cold emails to anyone with a live deal in PipedriveiMessage campaign console with pre-flight checks and delivery boardChat quality review board for LiveChat support leadsLinkedIn Ads budget pacing dashboard for every client accountFront desk appointment confirmation board for the next 3 daysGive your team Looker numbers without buying more seats