What is attack surface management? A practical guide

HebeSec TechnologiesUpdated 6 min read

Attack surface management (ASM) is the continuous process of finding everything your organization exposes to the internet, such as domains, servers, cloud services, open ports and leaked credentials, and fixing the riskiest exposures first. External attack surface management (EASM) does this from the outside, the way an attacker would.

On this page

What attack surface management means

Your attack surface is every point where an attacker could try to get in or take data out. Attack surface management keeps an up-to-date inventory of those points, checks each one for weaknesses, ranks what it finds by risk, and repeats the process, because the attack surface changes whenever someone launches a website, opens a port or signs up for a cloud service.

You will see three related terms:

  • EASM (external attack surface management) covers what is reachable from the internet. It starts from your domain names and discovers assets the way an attacker would, with no access to your network.
  • CAASM (cyber asset attack surface management) pulls asset data from the tools you already run, such as endpoint, cloud and identity systems, into one internal inventory.
  • Exposure management and CTEM are wider programs that use ASM findings to prioritize, validate and fix exposures in a repeating cycle.

What makes up an external attack surface

AssetExamplesCommon exposures
Domains and subdomainswww, mail, vpn, dev, stagingForgotten test sites, subdomain takeover
IP addresses and hostingCloud instances, on-premises serversServers nobody owns any more
Open ports and servicesWeb, remote access, databases, file transferDatabases or admin panels open to the internet
Web applicationsCustomer portals, APIs, login pagesUnpatched software, injection flaws
TLS certificatesCertificates on each public hostnameExpired or weak certificates
DNS and email recordsSPF, DKIM, DMARC, CNAME recordsSpoofable domains, dangling records
Third-party code and servicesScripts, widgets, SaaS toolsSupply-chain risk
Credentials and secretsStaff logins in breach data, keys in public codeDirect account access
Brand assetsLookalike domains, fake accountsPhishing and fraud

Shadow IT, meaning systems set up without the security team knowing, cuts across all of these rows. It is the main reason inventories built from what IT already knows are incomplete.

Why attack surface management matters

Attackers scan the whole internet continuously for the easiest way in: an exposed remote-access service, a database without a password, an old server running software with a known exploit, or a login page that accepts leaked passwords. They don’t need a map of your network. One forgotten system is enough.

Organizations also change faster than their asset lists. New projects, cloud accounts, acquisitions, contractors and marketing sites all add assets. Annual audits and quarterly scans capture a snapshot; attack surface management keeps the inventory current between them.

How attack surface management works

  1. Discovery. Starting from your domain names, ASM finds related subdomains, IP addresses, cloud services and certificates, using sources such as certificate transparency logs, passive DNS and subdomain enumeration.
  2. Inventory and classification. Each asset is identified: what it runs, whether it is live and who it likely belongs to.
  3. Assessment. Assets are checked for open ports, outdated software, known vulnerabilities, weak TLS, missing security headers and misconfigured DNS and email records.
  4. Prioritization. Findings are ranked by severity, exploitability (for example, whether a vulnerability is known to be exploited) and how exposed the asset is.
  5. Remediation and validation. Owners fix the top issues, and the fix is checked.
  6. Continuous monitoring. The cycle repeats, so new assets and new weaknesses are found as they appear.

ASM vs vulnerability scanning vs penetration testing

Attack surface managementVulnerability scanningPenetration testing
Starting pointYour domain namesA list of targets you provideAn agreed scope
Finds unknown assetsYesNoSometimes, within scope
DepthBroad, externalKnown vulnerabilities on given targetsDeep, manual, chained attacks
FrequencyContinuous, usually dailyScheduledUsually once a quarter or once a year
Best forKeeping the inventory and exposure currentPatch managementProving real-world impact

They work best together. ASM finds what exists and what changed, scanning checks known targets in depth, and penetration testing shows what an attacker could really do.

Attack surface management and CTEM

Continuous threat exposure management (CTEM) is a five-stage program: scope, discover, prioritize, validate and mobilize. Attack surface management supplies the discovery stage and much of the data for prioritization. CTEM then turns that data into fixes by agreeing scope with the business, confirming which exposures can really be exploited, and assigning owners.

How to reduce your external attack surface

  1. Build an inventory from the outside in, starting from each domain you own.
  2. Remove what you don’t need: old subdomains, test and staging servers, unused open ports and dangling DNS records.
  3. Move admin panels, databases and remote access behind a VPN or zero-trust access, off the open internet.
  4. Patch exposed services first, starting with vulnerabilities known to be exploited.
  5. Fix TLS, security headers and email authentication (SPF, DKIM and DMARC).
  6. Reset leaked credentials and turn on multi-factor authentication for internet-facing logins.
  7. Give each asset an owner, so findings have someone to fix them.
  8. Keep monitoring, because the attack surface grows back.

What to look for in an attack surface management tool

  • Discovery from a domain name, with no agents or network access needed.
  • Daily monitoring that flags new assets and changes.
  • Validated, prioritized findings rather than a raw list of open ports.
  • Exploitability context, such as known-exploited vulnerabilities and public exploits.
  • Coverage of leaked credentials and brand abuse, which attackers combine with exposed assets.
  • Reports for auditors and executives, and exports for your ticketing or threat-intelligence tools.
  • Multi-tenant support if you serve several clients.

How HebeGuard handles attack surface management

HebeGuard starts from your domain and discovers subdomains, IP addresses, open ports, services, certificates and cloud assets, including shadow IT. Findings are validated and weighted by severity, exploitability and exposure into one 0-100 risk score that maps to ISO 27001 and PCI-DSS control families, and the checks repeat daily.

The same console covers dark web monitoring and brand monitoring, and reports export as PDF, XLS or STIX 2.1.

FAQ

What is an example of an attack surface?

A company’s external attack surface includes its website and subdomains, email servers, VPN and remote-access gateways, cloud storage, APIs, and any server or service reachable from the internet. Leaked staff passwords and lookalike domains are part of it too, because attackers use them to get in.

Is attack surface management the same as vulnerability management?

No. Vulnerability management finds and fixes weaknesses on assets you already know about. Attack surface management finds the assets first, including unknown ones, and then checks them. Many teams feed ASM discoveries into their vulnerability management process.

How often should you scan your attack surface?

Continuously, or at least daily. New subdomains, cloud services and vulnerabilities appear all the time, and attackers scan the internet constantly.

Does attack surface management need agents or network access?

External attack surface management doesn’t. It works from the internet, starting from your domain names, which is the same view an attacker has.

Who needs attack surface management?

Any organization with an internet presence, and especially companies with many websites or cloud accounts, regulated industries, companies that have grown through acquisitions, and MSSPs that monitor clients.

We reply within one business day

See what an attacker can see of your company.

Send us your primary domain. We'll map your external attack surface and walk you through what we find.

sales@hebesec.com
What we'll cover
Asset inventoryExposure scoreValidated findingsDark-web hits
ISO 27001-alignedPCI-DSS-alignedNo agent