Services / Testing
External Attack Surface Management
Continuous discovery of everything of yours that is exposed to the internet.
The problem
Someone spun up a demo environment two years ago for a customer trial. It is still online, still has real data, and nobody remembers it exists. It is not in the asset inventory, it is not in the scan scope, and it was never in the audit.
The method.
Discover from the outside, without being told what to look for
Start from the organisation, not from a list you provide: registered domains, certificate transparency logs, passive DNS, ASN and IP allocations, cloud tenancy fingerprints, code and package registry references, and acquired-company estates. The value is in the assets nobody would have put on the list.
Attribute carefully
Discovery generates false positives: shared hosting, look-alike domains, a former subsidiary. Each asset is attributed to your organisation with a stated basis. An inventory you cannot trust is one nobody will act on.
Fingerprint the exposure
For each internet-facing asset: open ports and services, technologies and versions, TLS configuration and certificate expiry, exposed admin panels and management interfaces, default credentials, forgotten staging and dev environments, dangling DNS records vulnerable to subdomain takeover, and exposed cloud storage.
Prioritise by what an attacker would reach for
An exposed admin login on a forgotten staging box with production data outranks a missing security header on the marketing site by a wide margin. Priority is set by exploitability, data sensitivity, and the presence of a known-exploited vulnerability, the way an attacker would choose.
Run continuously and alert on new exposure
The attack surface changes every time someone deploys. Continuous re-discovery means a new subdomain, a newly exposed port, an expiring certificate or a dangling DNS record is reported within days of appearing, which is far faster than any quarterly scan.
What is External Attack Surface Management?
External Attack Surface Management is the continuous discovery and assessment of every internet-facing asset belonging to an organisation (domains, subdomains, IP ranges, cloud endpoints, exposed services and certificates), including assets that were never documented. It works from the outside in, the way an attacker does, rather than from an internal inventory that is assumed to be complete.
How is EASM different from vulnerability scanning?
A vulnerability scanner tests a list of assets you give it. EASM finds the assets you did not know to give it. The forgotten staging environment, the demo box from a customer trial two years ago, the subdomain pointing at a decommissioned cloud bucket. These never appear in a scan scope, which is exactly why they are the ones that get exploited.
What is a subdomain takeover?
A subdomain takeover occurs when a DNS record still points at a cloud service or hosting provider that has been decommissioned, leaving the target name unclaimed. An attacker can register that name at the provider and serve content from your subdomain, which enables convincing phishing, cookie theft on the parent domain, and abuse of your brand. Dangling DNS records are found routinely in mid-market estates and are usually trivial to remove.