Internet published Web Applications and services are subject to constant change due to the addition of new workflows, features, functions, and patches that occur quite often. The external attack surface is dynamically evolving with exposures through ephemeral assets, VM sprawling, agile development practices and no real control over change management practice. Waiting for the next scheduled penetration testing to validate the external attack surface observations give ample chances for the attackers.