Attack surface management (ASM) is the continuous process of discovering, inventorying, monitoring, assessing, prioritizing and reducing the points where an attacker could enter an organization’s systems, cause an effect or extract data. NIST defines an attack surface as those boundary points, a concept that is broader than open ports or internet-facing servers (NIST glossary).
In product marketing, “ASM” often means external attack surface management (EASM): outside-in discovery of domains, subdomains, IP addresses, cloud services, APIs, certificates, web applications and third-party infrastructure. EASM is valuable, but it is only one part of a mature program. Discovery that is not attributed to an owner, prioritized, fixed and rechecked does not reduce exposure.
What counts as an attack surface?
An attack surface is every boundary through which an attacker might gain access, influence a system or obtain information. Depending on the organization’s scope, it includes both digital and physical assets.
- Internet-facing domains, subdomains, IP addresses and autonomous-system ranges
- Web applications, APIs, API gateways and remote-access services
- Cloud workloads, storage, load balancers and management interfaces
- VPNs, firewalls, email systems, TLS certificates and authentication records
- SaaS applications, endpoints, identities and internal services
- Development, staging and test systems accidentally exposed to the internet
- Forgotten, abandoned or unsupported infrastructure
- Supplier, partner, acquired-company and other supply-chain assets
- Physical facilities or devices where the organization includes them in ASM
An exposed database is an obvious example. A dangling DNS record, an expired certificate, a forgotten staging host or an unowned cloud endpoint can be just as important even when no CVE is involved.
#1 Best Overall
ASM, EASM and related disciplines
Terminology is inconsistent, so define the boundary before comparing products. The UK National Cyber Security Centre describes EASM as the internet-accessible subset of ASM (NCSC buyer’s guide, reviewed September 18, 2025).
| Capability | Main question | Typical starting data |
|---|---|---|
| ASM | What can an attacker reach or influence across our environment? | External, internal, cloud, identity and, where applicable, physical assets |
| EASM | What can the public internet see about us? | Domains, IPs, certificates, services, applications and related infrastructure |
| CAASM | What do our internal IT and security systems say we own? | CMDB, EDR, cloud, identity, scanners, SIEM and network tools |
| Vulnerability management | Which known vulnerabilities affect identified assets? | Asset lists, authenticated scans and vulnerability intelligence |
| Penetration testing | Can a skilled tester exploit a defined scope to achieve a defined objective? | Authorized test scope and manual validation |
| Attack-path analysis | How could an attacker move from an exposure to a valuable resource? | Identity, network, control and business-context relationships |
| Exposure management | Which combination of weaknesses and business context creates the greatest risk? | ASM, CAASM, vulnerabilities, identity, cloud, attack paths and impact |
EASM helps discover what should be in a vulnerability-management scope. CAASM reconciles internal records. Exposure management combines these views and adds prioritization context. A product can support several capabilities, but the terms should not be treated as interchangeable.
Why attack surfaces keep expanding
Cloud and ephemeral infrastructure
Cloud resources can be created outside central IT inventory, changed by automation and deleted before a traditional register is updated. IPv4 addresses, cloud endpoints and services can change faster than ownership records.
Acquisitions and business growth
Mergers introduce domains, networks, brands, suppliers and certificates that may never have been mapped by the acquiring security team.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsDevOps and shadow IT
CI/CD pipelines can publish temporary services; marketing teams can launch microsites with agencies; and business units can purchase SaaS without security involvement. Development and test environments then remain reachable after a project ends.
DNS, certificates and remote work
DNS records can outlive the services they reference. Certificate records can reveal forgotten hosts, while remote work increases the number of externally reachable services and administrative interfaces.
Third-party dependencies
Suppliers, hosted services and integrations create exposure outside direct administrative control. Monitoring those relationships can be useful, but active testing may require written authorization and contractual permission.
Microsoft says Defender EASM continuously discovers and maps online infrastructure from known “discovery seeds” such as domains, IP blocks, ASNs, WHOIS organizations and contacts (Microsoft Learn, updated April 24, 2026). No method finds everything: unrelated domains, private services, restrictive controls, recent infrastructure and third-party ownership can all create blind spots or false attribution.
Free tools Windows power users keep installed
One-click scans. No signup required.
How an ASM program works
ASM is an operating loop, not a dashboard. Use the following sequence and assign an accountable owner at each handoff.
- Discover: Find assets through DNS and passive DNS, certificate-transparency records, WHOIS, IP and ASN relationships, web crawling, technology fingerprinting, scanning, cloud integrations, threat intelligence and seed-based recursive discovery.
- Validate attribution: Determine whether each asset is owned, supplier-owned, shared, acquired, historical or incorrectly associated. Require evidence such as DNS, certificate, registration or hosting relationships.
- Inventory and classify: Record the business owner, technical owner, security contact, environment, criticality, lifecycle status and remediation route.
- Identify exposures: Detect services, technologies, configurations, unsupported software, certificates, DNS relationships, email controls, cloud settings and possible vulnerabilities.
- Prioritize: Combine internet exposure, asset criticality, exploitability, known exploitation, authentication, data sensitivity, exposure duration, attack-path relevance, regulatory impact, confidence and remediation effort.
- Assign: Route work to the team empowered to fix it, using tickets, workflow integrations and due dates.
- Remediate, remove, restrict or accept: Patch or reconfigure the service, close access, decommission the asset, or document a time-bound risk acceptance.
- Verify: Recheck externally that the service, vulnerable version, DNS pointer or access path is actually gone or mitigated.
- Monitor: Continue watching for new assets, configuration drift, reappearing services and changed ownership.
What ASM tools can find
- Unknown or unmanaged assets and shadow IT
- Internet-accessible databases, management interfaces and remote-access services
- Unsupported software, missing patches and likely vulnerable versions
- Weak TLS settings, expired certificates and possible certificate misuse
- Dangling DNS records and subdomain-takeover risk
- SPF, DMARC and MTA-STS email-security weaknesses
- Exposed development, staging and test environments
- Cloud storage, administrative services and other configuration errors
- Newly exposed assets, asset drift and historical infrastructure
- Supplier, acquired-company and third-party exposure
EASM findings are often called “issues” or “risks,” not just vulnerabilities, because many concern configuration, lifecycle or ownership rather than a CVE (NCSC buyer’s guide).
Discovery methods and their limits
Passive sources are generally lower risk: DNS, certificate transparency, registration data, search indexes and public threat intelligence. Active methods such as port scans, service probes and technology fingerprinting can improve accuracy but may trigger intrusion-prevention systems or affect fragile systems. More intrusive validation can require authenticated access and explicit authorization.
Technology fingerprinting may infer a version associated with a CVE; it does not prove that the instance is exploitable. Confirm with authenticated scanning, configuration evidence, vendor confirmation or safe validation. Ask providers for scan source addresses, user-agent identifiers, schedules, rate controls, payload descriptions, suppression features and an emergency stop.
Rank #3
Building an ASM program
Define an authorized scope
List legal entities, subsidiaries, brands, domains, IP ranges, ASNs, cloud accounts, SaaS providers, acquisitions, critical suppliers and internet-facing services. Document what may be observed, scanned or tested. Separate passive monitoring from active testing of third parties.
Create an ownership model
Every asset needs a business owner, technical owner, security contact, classification, criticality, lifecycle status and remediation path. Security teams often discover assets owned by marketing, contractors or suppliers; escalation rules are essential when the security team cannot make the change itself.
Baseline the inventory
- Known and authorized
- Known but unauthorized
- Unknown but likely owned
- Supplier- or partner-owned
- Historical or inactive
- False positive or incorrectly attributed
Do not automatically treat every discovered host as company property.
Connect existing workflows
Useful integrations include ticketing, SIEM/SOAR, vulnerability-management platforms, CMDB and asset management, cloud inventories, DNS and certificate management, and collaboration tools. The goal is accountable action rather than another isolated console.
Verify closure
A ticket marked complete is not proof. Recheck that the service is no longer exposed, the vulnerable version or misconfiguration is resolved, DNS no longer points to an abandoned resource, access controls work as intended and the issue has not reappeared under another hostname or cloud endpoint.
How to evaluate an ASM platform
Coverage and attribution
- Can it discover subsidiaries, acquisitions, brands, unrelated domains, IPv4 and IPv6, cloud resources, APIs, certificates, SaaS and suppliers?
- Does it explain why an asset was attributed to you?
- Can analysts correct, reject or suppress an attribution?
Freshness
“Continuous” is not a sufficient specification. Ask how often each data type is refreshed, whether on-demand verification is available and when alerts are generated. Domains, services, certificates and findings may have different schedules (NCSC guidance).
Rank #4
Risk and workflow
Test prioritization by asset criticality, exploitability, known exploitation, authentication, data sensitivity, threat intelligence, confidence, attack-path context and remediation effort. Look for ticket creation, assignment, comments, exceptions, evidence, APIs, integrations, verification scans and historical trends.
Internal visibility and data governance
If the primary problem is unmanaged laptops, servers, identities, workloads or OT, a pure EASM product may be the wrong starting point. Internal visibility usually requires agents or integrations with EDR, cloud, identity and other systems. Confirm data residency, retention, access controls and whether customer data is separated from global internet datasets. Microsoft states that Defender EASM customer data is stored in the selected region, while underlying internet data is global Microsoft data (Microsoft Learn).
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Pricing models
Common models include asset-per-day, monitored-asset or IP/domain counts, subsidiary counts, enterprise licenses and bundled exposure-management subscriptions. Microsoft publishes an asset-per-day model, but its pricing page does not display a stable fixed amount and directs buyers to estimates, the Azure calculator or a quote (Microsoft pricing). Tenable, Palo Alto Networks and Rapid7 primarily use demo or quote-led sales paths (Tenable; Palo Alto Networks; Rapid7).
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Product landscape by fit
| Product | Potential fit | Pricing signal | Important caution |
|---|---|---|---|
| Microsoft Defender EASM | Azure and Microsoft security environments | Asset-per-day; fixed public amount not displayed | Azure dependence and attribution scope |
| Cortex Xpanse | Large enterprises needing broad external and supply-chain discovery | Demo or sales | Enterprise complexity and investigation workload |
| Tenable One ASM | EASM connected to vulnerability and exposure management | Quote or demo | May be excessive for EASM-only needs |
| Rapid7 Surface Command | Internal and external visibility in Rapid7 environments | Quote-based | Evaluate the broader platform, not just ASM |
| CrowdStrike Falcon Surface | CrowdStrike customers wanting adversary-intelligence and endpoint context | Stable public price not established | Value may depend on an existing Falcon footprint |
Vendor pages establish intended capabilities and commercial positioning, not comparative accuracy or guaranteed return on investment. Palo Alto Networks’ claim that Xpanse scans the entire IPv4 space up to several times daily is a vendor claim, not an independently verified measurement (Palo Alto Networks).
Failure modes and safeguards
False attribution
Certificates, DNS, hosting relationships or historical links can associate another organization’s asset with yours. Require evidence and an exclusion process.
Stale or misleading “continuous” data
A dashboard can look current while a particular check updates daily or weekly. Evaluate refresh intervals per feature.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
Scanning friction and legal exposure
Active probes can trigger defenses or affect fragile systems. Make scanner traffic identifiable, coordinate with SOC and network teams, and obtain permission before testing supplier assets.
Asset explosion and alert fatigue
Broad discovery can reveal duplicates, shared hosting and historical records. Classification and prioritization must come before mass ticket creation.
Remediation without service context
Deleting a DNS record or closing a port can break a business service. Require owner validation before destructive changes.
Tool overlap
Compare the incremental value against cloud-security posture management, vulnerability scanners, EDR/XDR, CMDB, certificate management, security ratings, penetration testing and digital-risk tools. A “single pane” is not automatically better coverage.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Metrics and operating cadence
Track measures that show ownership and risk reduction, not just asset volume:
- Percentage of discovered assets with an owner and authorization status
- Unknown-asset discovery rate
- Coverage across domains, cloud accounts, subsidiaries and suppliers
- Time from exposure to discovery, owner assignment and remediation
- Internet-facing services lacking required authentication
- Unsupported or high-risk technologies and critical-exposure age
- False-positive and recurrence rates
- Percentage of findings verified closed
- Risk accepted versus risk remediated
Review new assets and critical exposures weekly, ownership and aging monthly, and scope, supplier coverage, exceptions and product value quarterly. A rising asset count can indicate improved visibility rather than worsening security.
Choosing the right starting point
- Choose EASM when the main uncertainty is what the public internet can see, especially across domains, acquisitions, suppliers or cloud accounts.
- Choose CAASM when internal records disagree about laptops, servers, identities, cloud workloads or OT.
- Prioritize vulnerability management when asset ownership and scope are already reliable but patch and configuration risk is not.
- Consider exposure management when you need one risk model combining external and internal assets, vulnerabilities, identities, attack paths and business impact.
Whatever the product category, insist on attribution evidence, feature-level freshness, safe-scan controls, owner-based workflow and verified closure. ASM improves the organization’s ability to find and act on unknown exposure; it does not replace secure design, patching, identity controls, segmentation, application security, incident response or authorized penetration testing.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

