GlossaryAttack surface and pentesting

ASM

Short answer

ASM (Attack Surface Management) is the continuous discovery, inventory and monitoring of an organisation's assets that an attacker could target, such as domains, servers, cloud services and applications exposed to the internet. Its goal is to find exposures before attackers do.

What ASM looks for

ASM tools scan for internet facing assets: domains and subdomains, IP addresses, open ports, exposed services, expired certificates, cloud storage and forgotten test environments. Many of these assets are created outside IT's control, which is why they go unnoticed.

External and internal attack surface

External attack surface management (EASM) covers what is visible from the internet. The internal attack surface covers what an attacker could reach once inside the network, such as misconfigured servers or excessive permissions.

ASM vs pentesting

ASM is continuous and broad: it tells you what is exposed and changes as your infrastructure changes. A pentest is a deeper test at a point in time that shows what can be exploited. They work best together.

Why it matters

Attackers scan the internet constantly for exposed services and known vulnerabilities. ASM helps find and close those openings first, prioritising them by real risk.

Related terms

Keep reading on this topic

External and internal attack surface management, cloud configuration and application security: finding exposures and prioritising them by real risk.

Go to the topic hub