Multi-CloudHow-To & HardeningRetrospectives

How to Inventory Internet-Facing File Transfer and Integration Services

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from June 2023, written in 2026 with the benefit of hindsight.

Attackers repeatedly target internet-facing file transfer, integration and remote access services. Here is how to inventory them so you can patch, restrict or retire them quickly.

Step 1: Discover from the outside

Use an external attack surface management tool (such as Microsoft Defender External Attack Surface Management) or scheduled external scans to list internet-facing hosts, open ports, software and certificates across your domains and cloud IP ranges.

Step 2: Discover from the inside

  • Azure: Azure Resource Graph for public IPs, App Services, Application Gateways and Front Door endpoints.
  • AWS: list Elastic IPs, internet-facing load balancers, API Gateways, CloudFront distributions and EC2 instances with public IPs (AWS Config advanced queries help).
  • Network team: firewall NAT rules and published services.

Step 3: Categorize

Tag each service: file transfer (MOVEit, GoAnywhere, SFTP servers), VPN and remote access, email, web applications, APIs, admin interfaces, integration platforms.

Step 4: Assign owners and data sensitivity

Each service needs a technical owner and a data classification.

Step 5: Reduce

  • Retire unused services.
  • Restrict access by IP or put services behind identity-aware access.
  • Shorten data retention on file transfer platforms.

Step 6: Link to vulnerability response

Subscribe owners to vendor advisories. Add these systems to your emergency patching process.

Step 7: Monitor

WAF in front of web-based services; logs to your SIEM; alerts on new internet-facing services appearing.

Verify

Reconcile the external scan with your inventory monthly. Anything not on the list is shadow IT to investigate.

inventory internet facing servicesMOVEit2023

More on this story