Attack Surface Monitoring

Also known as:ASM

Attack Surface Monitoring (ASM) is the continuous discovery, inventory, and surveillance of all assets and exposures — both external and internal — that an attacker could target. While point-in-time assessments like penetration testsPenetration TestingAuthorized, methodical testing of a system for exploitable weaknesses, to find them before real attackers do. and vulnerability assessmentsVulnerability AssessmentSystematically identifies and assesses vulnerabilities in a defined environment. provide snapshots, ASM operates around the clock, detecting new assets, changed configurations, expired certificates, leaked credentials, and emerging vulnerabilities as they appear rather than weeks or months later during the next scheduled scan.

Modern organizations have sprawling, dynamic attack surfaces: cloud instances provisioned by developers, SaaS applications adopted by business units, APIs exposed by microservices, forgotten subdomains, and third-party integrations. ASM brings visibility to this constantly shifting landscape and alerts security teams before exposures are exploited.

What is monitored?

ASM covers any element that expands the attack surfaceAttack SurfaceThe totality of all potentially vulnerable entry points of a system. or introduces risk. Externally, this includes internet-facing IP addresses and open ports, DNS records and subdomains (including dangling CNAMEs vulnerable to takeover), TLS/SSL certificates and their expiration status, web applications and login pages, exposed APIs and development endpoints, cloud storage buckets and object permissions, code repositories and CI/CD pipeline artifacts, leaked credentials and secrets on paste sites, dark web marketplaces, and breach databases, email security posture (SPF, DKIM, DMARC), and third-party components with known vulnerabilitiesVulnerabilityA technical or organizational weakness that can be exploited by a threat..

Internally, ASM extends to unmanaged devices joining the network, misconfigured services and internal applications, identity and access configuration drift, database instances with default credentials, and development or staging environments accessible beyond their intended scope.

How ASM differs from EASM and vulnerability management

External Attack Surface Management (EASM)External Attack Surface ManagementIdentifies and monitors assets and risks accessible from the Internet. focuses specifically on internet-facing assets discovered from an outside-in perspective. ASM is broader: it includes internal assets, identity infrastructure, and exposures that only become visible with authenticated or agent-based visibility.

Traditional vulnerability managementVulnerability ManagementContinuous process for the detection, prioritization, remediation, and tracking of vulnerabilities. starts with a known asset inventory and scans for CVEs on those assets. ASM inverts the model — it first discovers assets (including unknown ones) and then correlates them with vulnerability data. Vulnerability management answers “are my known assets patched?” while ASM answers “what assets do I have, and which ones are exposed?”

In practice, ASM, EASM, and vulnerability management are complementary. Many organizations use all three, with ASM serving as the discovery and monitoring layer that feeds both EASM and vulnerability management programs.

How it works

Asset discovery — ASM platforms use a combination of techniques to build and maintain a comprehensive asset inventory. External discovery leverages DNS enumeration, certificate transparency logs, WHOIS data, BGP routing information, search engine indexing, and web crawling. Internal discovery uses network scanning, agent deployment, cloud API integration, and Active Directory queries. The result is a continuously updated inventory that includes assets the organization may not know about — shadow ITShadow ITIT systems, applications, and cloud services that are not officially approved or managed..

Continuous scanning — discovered assets are continuously scanned for open ports, running services, software versions, security headers, and known vulnerabilities. Scan frequency varies by asset criticality, with internet-facing systems scanned more frequently than internal development servers.

Change detection — ASM platforms track changes over time: new subdomains appearing, ports opening, certificates expiring, services being deployed, or configurations changing. Change detection is critical because many exposures are transient — a misconfigured staging server deployed on a Friday afternoon and forgotten over the weekend.

Risk scoring — each discovered asset and exposure receives a risk score based on factors like internet exposure, known vulnerabilities, asset criticality, data sensitivity, and compensating controls. Risk scores enable security teams to prioritize attention rather than drowning in a flat list of findings.

Alerting — when new exposures are detected or risk scores change significantly, ASM platforms generate alerts through integrations with SIEM, ticketing systems, and communication tools. Alert thresholds are tunable to balance signal quality with coverage.

ASM in practice

Effective ASM implementation starts with defining the organization’s digital footprint: domain names, IP ranges, cloud accounts, and subsidiaries. Initial discovery typically surfaces assets that security teams did not know existed — orphaned subdomains, forgotten development servers, and cloud resources provisioned outside of governed processes.

Operationally, ASM works best when integrated into existing security workflows. New asset discoveries feed into the vulnerability management pipeline. High-risk exposures trigger incident response procedures. Trend data informs quarterly risk reporting. The continuous nature of ASM aligns well with continuous monitoringContinuous MonitoringOngoing monitoring and assessment of security states, events, and deviations. requirements in frameworks like NIST CSF, ISO 27001, and SOC 2.

Organizations pursuing a CTEMContinuous Threat Exposure ManagementA continuous program for identifying, prioritizing, and validating threat exposures across all attack surfaces. program often position ASM as the primary tool for the Discovery stage, feeding findings into the Prioritization and Validation stages.

  • External Attack Surface Management (EASM)External Attack Surface ManagementIdentifies and monitors assets and risks accessible from the Internet.: Continuous discovery and monitoring focused specifically on internet-facing assets.
  • Attack SurfaceAttack SurfaceThe totality of all potentially vulnerable entry points of a system.: The totality of points where an attacker can attempt to enter or extract data from an environment.
  • Asset InventoryAsset InventoryAn authoritative inventory of hardware, software, identities, services, and cloud resources.: A comprehensive catalog of an organization’s hardware, software, and digital assets.
  • Continuous MonitoringContinuous MonitoringOngoing monitoring and assessment of security states, events, and deviations.: Ongoing observation of systems and networks to detect changes, threats, and anomalies.
  • Vulnerability ManagementVulnerability ManagementContinuous process for the detection, prioritization, remediation, and tracking of vulnerabilities.: The discipline of identifying, classifying, and remediating software vulnerabilities.
  • Shadow ITShadow ITIT systems, applications, and cloud services that are not officially approved or managed.: Technology resources deployed without the knowledge or approval of the IT or security organization.