Book an Appointment

EASM: Your Attack Surface Through an Attacker's Eyes

How continuous discovery from an attacker's point of view makes unknown assets, shadow IT and exposed services visible – from initial detection all the way to remediation.

Most organizations know only part of their internet-facing IT: subdomains from old projects, cloud resources spun up by individual business units, test environments and systems operated by service providers appear and disappear constantly – often without ever being recorded in the official inventory. It is precisely these unknown and forgotten assets that make a preferred entry point: according to Mandiant M-Trends 2026, exploits were the most common initial infection vector for the sixth year in a row, at 32%. External Attack Surface Management (EASM) addresses exactly this gap, continuously identifying, inventorying and assessing the external attack surface from an attacker's perspective. This article explains the concept, data sources and working method of EASM – and how it differs from vulnerability scans and penetration tests.

The Essentials at a Glance

01

What EASM is: continuous discovery from the outside

EASM refers to the ongoing identification, inventorying and assessment of all of an organization's internet-facing assets – from the outside perspective and without prior knowledge of the internal inventory. The focus is on the “unknown unknowns”: forgotten subdomains, legacy systems, test and staging environments, cloud resources procured independently by business units (shadow IT), and exposed services such as remote access points, admin interfaces or databases. OWASP describes the attack surface as the sum of all paths through which data and commands enter and leave a system – EASM applies this view systematically to an organization's entire publicly reachable IT.

02

Data sources: how unknown assets are found

Starting from a handful of starting points (“seeds” such as primary domains, IP ranges or company names), EASM techniques correlate publicly available data sources: active and passive DNS, Certificate Transparency logs (public, append-only registers of issued TLS certificates per RFC 9162), WHOIS/RDAP data, ASN and IP allocations from the internet registries, and internet-wide scan data on open ports and services. Leak sources such as credential dumps and paste sites are added to detect exposed credentials belonging to the organization's own domains. Because the very same sources are open to attackers as well, the result shows exactly the picture an attacker sees during reconnaissance.

03

Prioritizing and validating the findings

Not every finding is a relevant risk. Raw discovery data must first be attributed: does the asset actually belong to your own organization, to a service provider or to a CDN? Findings are then validated – is the service really reachable, is the configuration actually weak, is the vulnerability practically exploitable? – and prioritized by exposure, exploitability and business criticality. Without these steps, EASM produces long lists instead of actionable results; with them, remediation focuses on the findings an attacker would realistically use first.

04

Drawing the line: EASM, vulnerability scan, pentest

A vulnerability scanner checks known systems against known vulnerabilities – it presupposes a well-maintained inventory and remains blind to assets nobody has registered. A penetration test examines a predefined scope manually and in depth, but delivers a snapshot in time. EASM comes in before both: it first answers the inventory question (“What is actually visible from the outside?”) and thereby delivers the scope that scanning and pentesting require. The three approaches do not replace one another – they interlock: EASM finds the surface, the scan tests it in breadth, the pentest in depth.

05

Continuous rather than a snapshot

External attack surfaces change constantly: new cloud deployments, automatically issued certificates, configuration changes, acquisitions and expiring contracts shift the picture, sometimes daily. An annual scan or pentest cannot capture this change. How short the intervals have become is illustrated by the US cybersecurity agency CISA: its directive BOD 23-01 (2022) requires US federal agencies to perform automated asset discovery at least every seven days and vulnerability enumeration of all discovered assets every 14 days. The NIST Cybersecurity Framework 2.0 likewise anchors maintained inventories of hardware, software and services (category ID.AM) as a foundation of risk management.

06

Typical workflow: from discovery to remediation

In practice, EASM follows a recurring cycle: starting from seeds, discovery identifies assets, consolidates them into an inventory and assigns each one to an owner. Assessed and validated findings enter the existing processes (vulnerability management, ITSM) as prioritized, traceably documented tickets – including concrete remediation recommendations such as decommissioning, patching, hardening or moving behind VPN or Zero Trust access. After remediation, a renewed check from the outside confirms that the exposure has actually been eliminated. Metrics such as time to remediation and the number of newly discovered unknown assets make maturity measurable over time.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Mandiant / Google Cloud · 2026

M-Trends 2026

Exploits were the most common initial infection vector for the sixth year in a row, at 32%; based on more than 500,000 hours of incident response investigations in 2025.

CISA · 2022

BOD 23-01: Improving Asset Visibility and Vulnerability Detection on Federal Networks

Requires US federal agencies (FCEB) to perform automated asset discovery every 7 days and vulnerability enumeration every 14 days – a reference point for continuous visibility.

IETF · 2021

RFC 9162: Certificate Transparency Version 2.0

Standard for public, append-only logs of issued TLS certificates – a key data source for subdomain discovery.

OWASP Cheat Sheet Series · 2026

Attack Surface Analysis Cheat Sheet

Continuously maintained reference defining the attack surface as the sum of all entry and exit paths of a system (accessed 07/2026).

NIST · 2024

The NIST Cybersecurity Framework (CSF) 2.0

Category ID.AM calls for maintained inventories of hardware, software, systems and services as a foundation of cyber risk management.

How large is your external attack surface really?

In a no-obligation initial consultation, we assess together what visibility you have today and whether continuous EASM is the right next step for your organization.