Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Attack surface management (ASM) is the continuous process of discovering, inventorying, monitoring, assessing, prioritizing and reducing the points where an attacker could enter an organization’s systems, cause an effect or extract data. NIST defines an attack surface as those boundary points, a concept that is broader than open ports or internet-facing servers (NIST glossary).

In product marketing, “ASM” often means external attack surface management (EASM): outside-in discovery of domains, subdomains, IP addresses, cloud services, APIs, certificates, web applications and third-party infrastructure. EASM is valuable, but it is only one part of a mature program. Discovery that is not attributed to an owner, prioritized, fixed and rechecked does not reduce exposure.

What counts as an attack surface?

An attack surface is every boundary through which an attacker might gain access, influence a system or obtain information. Depending on the organization’s scope, it includes both digital and physical assets.

  • Internet-facing domains, subdomains, IP addresses and autonomous-system ranges
  • Web applications, APIs, API gateways and remote-access services
  • Cloud workloads, storage, load balancers and management interfaces
  • VPNs, firewalls, email systems, TLS certificates and authentication records
  • SaaS applications, endpoints, identities and internal services
  • Development, staging and test systems accidentally exposed to the internet
  • Forgotten, abandoned or unsupported infrastructure
  • Supplier, partner, acquired-company and other supply-chain assets
  • Physical facilities or devices where the organization includes them in ASM

An exposed database is an obvious example. A dangling DNS record, an expired certificate, a forgotten staging host or an unowned cloud endpoint can be just as important even when no CVE is involved.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ASM, EASM and related disciplines

Terminology is inconsistent, so define the boundary before comparing products. The UK National Cyber Security Centre describes EASM as the internet-accessible subset of ASM (NCSC buyer’s guide, reviewed September 18, 2025).

Capability Main question Typical starting data
ASM What can an attacker reach or influence across our environment? External, internal, cloud, identity and, where applicable, physical assets
EASM What can the public internet see about us? Domains, IPs, certificates, services, applications and related infrastructure
CAASM What do our internal IT and security systems say we own? CMDB, EDR, cloud, identity, scanners, SIEM and network tools
Vulnerability management Which known vulnerabilities affect identified assets? Asset lists, authenticated scans and vulnerability intelligence
Penetration testing Can a skilled tester exploit a defined scope to achieve a defined objective? Authorized test scope and manual validation
Attack-path analysis How could an attacker move from an exposure to a valuable resource? Identity, network, control and business-context relationships
Exposure management Which combination of weaknesses and business context creates the greatest risk? ASM, CAASM, vulnerabilities, identity, cloud, attack paths and impact

EASM helps discover what should be in a vulnerability-management scope. CAASM reconciles internal records. Exposure management combines these views and adds prioritization context. A product can support several capabilities, but the terms should not be treated as interchangeable.

Why attack surfaces keep expanding

Cloud and ephemeral infrastructure

Cloud resources can be created outside central IT inventory, changed by automation and deleted before a traditional register is updated. IPv4 addresses, cloud endpoints and services can change faster than ownership records.

Acquisitions and business growth

Mergers introduce domains, networks, brands, suppliers and certificates that may never have been mapped by the acquiring security team.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

DevOps and shadow IT

CI/CD pipelines can publish temporary services; marketing teams can launch microsites with agencies; and business units can purchase SaaS without security involvement. Development and test environments then remain reachable after a project ends.

DNS, certificates and remote work

DNS records can outlive the services they reference. Certificate records can reveal forgotten hosts, while remote work increases the number of externally reachable services and administrative interfaces.

Third-party dependencies

Suppliers, hosted services and integrations create exposure outside direct administrative control. Monitoring those relationships can be useful, but active testing may require written authorization and contractual permission.

Microsoft says Defender EASM continuously discovers and maps online infrastructure from known “discovery seeds” such as domains, IP blocks, ASNs, WHOIS organizations and contacts (Microsoft Learn, updated April 24, 2026). No method finds everything: unrelated domains, private services, restrictive controls, recent infrastructure and third-party ownership can all create blind spots or false attribution.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How an ASM program works

ASM is an operating loop, not a dashboard. Use the following sequence and assign an accountable owner at each handoff.

  1. Discover: Find assets through DNS and passive DNS, certificate-transparency records, WHOIS, IP and ASN relationships, web crawling, technology fingerprinting, scanning, cloud integrations, threat intelligence and seed-based recursive discovery.
  2. Validate attribution: Determine whether each asset is owned, supplier-owned, shared, acquired, historical or incorrectly associated. Require evidence such as DNS, certificate, registration or hosting relationships.
  3. Inventory and classify: Record the business owner, technical owner, security contact, environment, criticality, lifecycle status and remediation route.
  4. Identify exposures: Detect services, technologies, configurations, unsupported software, certificates, DNS relationships, email controls, cloud settings and possible vulnerabilities.
  5. Prioritize: Combine internet exposure, asset criticality, exploitability, known exploitation, authentication, data sensitivity, exposure duration, attack-path relevance, regulatory impact, confidence and remediation effort.
  6. Assign: Route work to the team empowered to fix it, using tickets, workflow integrations and due dates.
  7. Remediate, remove, restrict or accept: Patch or reconfigure the service, close access, decommission the asset, or document a time-bound risk acceptance.
  8. Verify: Recheck externally that the service, vulnerable version, DNS pointer or access path is actually gone or mitigated.
  9. Monitor: Continue watching for new assets, configuration drift, reappearing services and changed ownership.

What ASM tools can find

  • Unknown or unmanaged assets and shadow IT
  • Internet-accessible databases, management interfaces and remote-access services
  • Unsupported software, missing patches and likely vulnerable versions
  • Weak TLS settings, expired certificates and possible certificate misuse
  • Dangling DNS records and subdomain-takeover risk
  • SPF, DMARC and MTA-STS email-security weaknesses
  • Exposed development, staging and test environments
  • Cloud storage, administrative services and other configuration errors
  • Newly exposed assets, asset drift and historical infrastructure
  • Supplier, acquired-company and third-party exposure

EASM findings are often called “issues” or “risks,” not just vulnerabilities, because many concern configuration, lifecycle or ownership rather than a CVE (NCSC buyer’s guide).

Discovery methods and their limits

Passive sources are generally lower risk: DNS, certificate transparency, registration data, search indexes and public threat intelligence. Active methods such as port scans, service probes and technology fingerprinting can improve accuracy but may trigger intrusion-prevention systems or affect fragile systems. More intrusive validation can require authenticated access and explicit authorization.

Technology fingerprinting may infer a version associated with a CVE; it does not prove that the instance is exploitable. Confirm with authenticated scanning, configuration evidence, vendor confirmation or safe validation. Ask providers for scan source addresses, user-agent identifiers, schedules, rate controls, payload descriptions, suppression features and an emergency stop.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Building an ASM program

Define an authorized scope

List legal entities, subsidiaries, brands, domains, IP ranges, ASNs, cloud accounts, SaaS providers, acquisitions, critical suppliers and internet-facing services. Document what may be observed, scanned or tested. Separate passive monitoring from active testing of third parties.

Create an ownership model

Every asset needs a business owner, technical owner, security contact, classification, criticality, lifecycle status and remediation path. Security teams often discover assets owned by marketing, contractors or suppliers; escalation rules are essential when the security team cannot make the change itself.

Baseline the inventory

  • Known and authorized
  • Known but unauthorized
  • Unknown but likely owned
  • Supplier- or partner-owned
  • Historical or inactive
  • False positive or incorrectly attributed

Do not automatically treat every discovered host as company property.

Connect existing workflows

Useful integrations include ticketing, SIEM/SOAR, vulnerability-management platforms, CMDB and asset management, cloud inventories, DNS and certificate management, and collaboration tools. The goal is accountable action rather than another isolated console.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Verify closure

A ticket marked complete is not proof. Recheck that the service is no longer exposed, the vulnerable version or misconfiguration is resolved, DNS no longer points to an abandoned resource, access controls work as intended and the issue has not reappeared under another hostname or cloud endpoint.

How to evaluate an ASM platform

Coverage and attribution

  • Can it discover subsidiaries, acquisitions, brands, unrelated domains, IPv4 and IPv6, cloud resources, APIs, certificates, SaaS and suppliers?
  • Does it explain why an asset was attributed to you?
  • Can analysts correct, reject or suppress an attribution?

Freshness

“Continuous” is not a sufficient specification. Ask how often each data type is refreshed, whether on-demand verification is available and when alerts are generated. Domains, services, certificates and findings may have different schedules (NCSC guidance).

Risk and workflow

Test prioritization by asset criticality, exploitability, known exploitation, authentication, data sensitivity, threat intelligence, confidence, attack-path context and remediation effort. Look for ticket creation, assignment, comments, exceptions, evidence, APIs, integrations, verification scans and historical trends.

Internal visibility and data governance

If the primary problem is unmanaged laptops, servers, identities, workloads or OT, a pure EASM product may be the wrong starting point. Internal visibility usually requires agents or integrations with EDR, cloud, identity and other systems. Confirm data residency, retention, access controls and whether customer data is separated from global internet datasets. Microsoft states that Defender EASM customer data is stored in the selected region, while underlying internet data is global Microsoft data (Microsoft Learn).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Pricing models

Common models include asset-per-day, monitored-asset or IP/domain counts, subsidiary counts, enterprise licenses and bundled exposure-management subscriptions. Microsoft publishes an asset-per-day model, but its pricing page does not display a stable fixed amount and directs buyers to estimates, the Azure calculator or a quote (Microsoft pricing). Tenable, Palo Alto Networks and Rapid7 primarily use demo or quote-led sales paths (Tenable; Palo Alto Networks; Rapid7).

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Product landscape by fit

Product Potential fit Pricing signal Important caution
Microsoft Defender EASM Azure and Microsoft security environments Asset-per-day; fixed public amount not displayed Azure dependence and attribution scope
Cortex Xpanse Large enterprises needing broad external and supply-chain discovery Demo or sales Enterprise complexity and investigation workload
Tenable One ASM EASM connected to vulnerability and exposure management Quote or demo May be excessive for EASM-only needs
Rapid7 Surface Command Internal and external visibility in Rapid7 environments Quote-based Evaluate the broader platform, not just ASM
CrowdStrike Falcon Surface CrowdStrike customers wanting adversary-intelligence and endpoint context Stable public price not established Value may depend on an existing Falcon footprint

Vendor pages establish intended capabilities and commercial positioning, not comparative accuracy or guaranteed return on investment. Palo Alto Networks’ claim that Xpanse scans the entire IPv4 space up to several times daily is a vendor claim, not an independently verified measurement (Palo Alto Networks).

Failure modes and safeguards

False attribution

Certificates, DNS, hosting relationships or historical links can associate another organization’s asset with yours. Require evidence and an exclusion process.

Stale or misleading “continuous” data

A dashboard can look current while a particular check updates daily or weekly. Evaluate refresh intervals per feature.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Scanning friction and legal exposure

Active probes can trigger defenses or affect fragile systems. Make scanner traffic identifiable, coordinate with SOC and network teams, and obtain permission before testing supplier assets.

Asset explosion and alert fatigue

Broad discovery can reveal duplicates, shared hosting and historical records. Classification and prioritization must come before mass ticket creation.

Remediation without service context

Deleting a DNS record or closing a port can break a business service. Require owner validation before destructive changes.

Tool overlap

Compare the incremental value against cloud-security posture management, vulnerability scanners, EDR/XDR, CMDB, certificate management, security ratings, penetration testing and digital-risk tools. A “single pane” is not automatically better coverage.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Metrics and operating cadence

Track measures that show ownership and risk reduction, not just asset volume:

  • Percentage of discovered assets with an owner and authorization status
  • Unknown-asset discovery rate
  • Coverage across domains, cloud accounts, subsidiaries and suppliers
  • Time from exposure to discovery, owner assignment and remediation
  • Internet-facing services lacking required authentication
  • Unsupported or high-risk technologies and critical-exposure age
  • False-positive and recurrence rates
  • Percentage of findings verified closed
  • Risk accepted versus risk remediated

Review new assets and critical exposures weekly, ownership and aging monthly, and scope, supplier coverage, exceptions and product value quarterly. A rising asset count can indicate improved visibility rather than worsening security.

Choosing the right starting point

  1. Choose EASM when the main uncertainty is what the public internet can see, especially across domains, acquisitions, suppliers or cloud accounts.
  2. Choose CAASM when internal records disagree about laptops, servers, identities, cloud workloads or OT.
  3. Prioritize vulnerability management when asset ownership and scope are already reliable but patch and configuration risk is not.
  4. Consider exposure management when you need one risk model combining external and internal assets, vulnerabilities, identities, attack paths and business impact.

Whatever the product category, insist on attribution evidence, feature-level freshness, safe-scan controls, owner-based workflow and verified closure. ASM improves the organization’s ability to find and act on unknown exposure; it does not replace secure design, patching, identity controls, segmentation, application security, incident response or authorized penetration testing.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.