What ASM looks for
ASM tools scan for internet facing assets: domains and subdomains, IP addresses, open ports, exposed services, expired certificates, cloud storage and forgotten test environments. Many of these assets are created outside IT's control, which is why they go unnoticed.
External and internal attack surface
External attack surface management (EASM) covers what is visible from the internet. The internal attack surface covers what an attacker could reach once inside the network, such as misconfigured servers or excessive permissions.
ASM vs pentesting
ASM is continuous and broad: it tells you what is exposed and changes as your infrastructure changes. A pentest is a deeper test at a point in time that shows what can be exploited. They work best together.
Why it matters
Attackers scan the internet constantly for exposed services and known vulnerabilities. ASM helps find and close those openings first, prioritising them by real risk.




