An attack surface map describes relationships, not only addresses. It connects observable assets to services, identities, providers and controls that may change risk.
Map layers
Separate what is confirmed, inferred and pending. Record the source, observation date and confidence level for each asset.
Trust boundaries
The most interesting points often appear where responsibility changes: public and internal access, organisation and provider, user and service, or production and administration.
Preserve context
The map is temporal. Avoid treating an old observation as a permanent property and retain the history of relevant changes.