CTEM/ASM Platform — 7 Categories × Continuous Monitoring

Your Unseen Assets AreYour Greatest Vulnerability

Domains, IPs, ports, cloud buckets exposed to the internet — the assets missing from your inventory are the first targets attackers seek. PentaTrail monitors your attack surface continuously, from an attacker's perspective.

Blind Spots

Three Blind Spots Organizations Face Today

Invisible External Assets

Cloud migration, M&A, departmental subdomains — IT asset inventories alone can't capture the full picture of your external exposure. What attackers can see, you cannot.

Key-Person Dependent Security

Scan result interpretation, priority decisions, executive reporting — all depending on specific individuals. When people change, so do response quality and risk judgments.

Risks You Can't Explain

When the board asks "Are we secure?" — can you answer with quantitative evidence? Organizations need the ability to explain risk with numbers, not intuition.

CTEM Framework

Gartner's 5-Stage Process, Fully Implemented

CTEM (Continuous Threat Exposure Management) is a framework proposed by Gartner in 2022 for continuously discovering, evaluating, and remediating externally visible weaknesses. Rather than a one-time assessment, it shrinks your attack surface by repeating five stages.

Each stage maps to one of two plans. CTEM is the higher tier and includes everything in ASM. ASM (attack-surface management) = asset discovery, vulnerability detection and risk rating (TER), and reading the AI remediation guidance. CTEM adds business-impact asset weighting & grouping (prioritization), validation, remediation task workflow, and executive reporting. Each stage shows which plans it's available in.

Exposure management comes down to three questions — discoverability (attack surface), susceptibility (vulnerabilities), and exploitability (validation). The five stages below are how you work through them continuously. PentaTrail covers discoverability and susceptibility with ASM, and adds exploitability (validation) with CTEM.

The concept itself is explained in What is CTEM?, and the asset-discovery side in ASM (Attack Surface Management).

STEP 01
ASMCTEM

Scoping

Register your target domains and define the monitoring scope

Build an operational structure with groups and view permissions

STEP 02
ASMCTEM

Discovery

Daily discovery of external assets across 7 categories

Hosts, IPs, ports, tech stacks, URLs, cloud buckets, and WHOIS / DNS. Nine OSINT APIs refresh every day.

STEP 03
CTEM

Prioritization

Weight assets by business impact (BI Score) and group them by division or subsidiary. The same risk (TER) is a different priority for a payment system vs. a test environment

Beyond CVSS alone — priority combines EPSS (exploit-probability prediction), KEV (known exploited vulnerabilities), and business impact (BI Score). Same CVSS, different priority for payment vs. test systems

STEP 04
CTEM

Validation

Recon tooling + AI-generated templates prove exploitability without disruption

AI-generated templates + Nuclei engine. Evidence Grade for confidence

STEP 05
ASMCTEM

Mobilization

Reading the AI remediation guidance is in ASM; owner assignment, task workflow, and executive reporting are in CTEM, tracked to closure

Owner assignment, deadlines & progress tracking to ensure completion

Based on Gartner, "Implement a Continuous Threat Exposure Management (CTEM) Program" (2022)

Why PentaTrail

Discovery Alone Is Not Enough

Most ASM products stop at asset discovery and vulnerability detection. PentaTrail goes further, covering all five CTEM framework stages — from validation through remediation to executive reporting — in a single solution.

The ASM plan covers asset discovery, vulnerability detection and risk rating (TER), and reading the AI remediation guidance. The CTEM plan adds business-impact asset weighting & grouping (prioritization), validation, remediation task workflow, and executive reporting — covering everything.

Deterministic Discovery

No AI ambiguity

DNS, CT Logs, WHOIS, reverse IP — we combine internet protocols and OSINT for deterministic asset discovery. No reliance on AI inference; only technically verified results.

Daily Scanning

Never miss a change

Most ASM services scan monthly or weekly. PentaTrail runs automated daily scans, detecting new assets and service changes by the next day.

Non-Destructive Safety Guards

Security by architecture

Scans are limited to domains verified by DNS ownership proof. Deep scans only run non-destructive checks — no operations that could impact your systems are ever used.

AI-Native Architecture

Designed by security practitioners, built with AI

Architected from CSIRT and governance operations, implemented entirely with generative AI. Discovery stays deterministic; AI powers what comes after — vulnerability templates, remediation guidance, and executive summaries as core capabilities.

Customer API / MCP

An ASM that plugs into AI agents

REST API and MCP Server out of the box. Your AI agents pull vulnerability data from PentaTrail and automate the hand-off to SIEMs, ticketing systems, and remediation workflows — a native building block of the AI ecosystem.

Features

End-to-End External Attack Surface Management

All five CTEM stages in a single platform

Discovery, detection, and risk rating plus reading AI remediation guidance are in the ASM plan; weighting & grouping (prioritization), validation, remediation workflow, and executive reporting are in the CTEM plan.

ASM

Automated Asset Discovery

Hosts, IPs, ports, tech stacks, URLs, cloud buckets, and DNS — 7 asset categories surfaced by 9 OSINT APIs and refreshed daily in your inventory.

ASM

Vulnerability Scanning

Detect vulnerabilities through DAST and SSL scanning, then automatically rank them by risk (TER: S/A/B/C/D).

ASM

Change Detection

Detect new assets, service changes, and port openings daily. Score trends let you quantify how your security posture has improved over time.

CTEM

Continuous Security Management

Group assets by division or subsidiary and assign owners. AI generates per-vulnerability remediation steps and correlated-risk analysis, tracked to closure by the management-maturity score.

Dashboard

Intuitive Dashboard

Get a complete view of your attack surface at a glance

app.pentatrail.co/dashboard/asm
PentaTrail Dashboard — contract summary view

Ready to See Your Attack Surface?

Register in as little as 5 minutes — see your first attack-surface results within hours. 14-day free trial.

Start Your 14-Day Free Trial

Use Cases

Attack Surface Management for Every Scenario

For any organization that needs to manage its external attack surface

Continuous ASM

Discover shadow IT and unmanaged subdomains across 7 asset categories. Track management-maturity score over time and continuously reduce risk before incidents occur

Cloud Exposure Check

Surface cloud buckets and unintended public resources across AWS, GCP, and Azure. Business-impact scoring prioritizes the highest-risk items first

M&A Due Diligence

Discover acquisition targets' external assets comprehensively and validate vulnerabilities with AI deep scanning. A single score report surfaces IT risk for executive review

Small-Team Security Operations

AI auto-generates per-vulnerability remediation steps and priorities. Even a one-person IT team can run continuous attack-surface management — no specialist expertise required

Pre-Launch Check

Validate new services and APIs before launch with AI deep scanning. Detect information exposure and misconfigurations non-destructively, with auto-generated remediation steps

Post-Incident Reassessment

Re-inventory your attack surface across 7 asset categories after an incident. BI score × threat level identifies breach scope and quantifies prevention priorities

Audit & Certification

Auto-update asset inventories for ISMS, SOC 2, and other audits. Management-maturity scores and remediation history serve as ready-to-submit continuous-evaluation evidence

Third-Party Security Assessments

Answer security assessments from customers and parent companies with objective evidence of your own external exposure. Support your preparation for rising requirements — such as Japan's SCS assessment scheme — with continuous visibility

Quarterly Executive Report

Report quantitatively with business-impact (BI) score distribution and score trends. Explain security ROI to leadership in numbers, not gut feeling

Threat Landscape

The Numbers Tell the Story

84%

Intrusion via External-Facing Devices

Over 80% of ransomware breaches originated from external-facing devices such as VPN appliances and remote desktop services

Source: National Police Agency of Japan, H1 2025

7x

Surge in Edge Device Exploitation

Vulnerability attacks targeting external-facing devices like VPNs and edge appliances surged over 7x year-over-year. Zero-day exploitation observed

Source: Verizon DBIR 2025

73%

Incidents from Unmanaged Assets

Over 70% of security leaders reported experiencing incidents caused by previously unknown or unmanaged assets

Source: Trend Micro / CSO Online (2025)

0 days

Exploited on Day One

For the edge-device vulnerabilities DBIR analyzed, the median time from disclosure to the start of mass exploitation was zero days — no grace period for leaving exposure unaddressed

Source: Verizon DBIR 2025

Why Now

Supply-Chain Pressure Is Rising

Attackers increasingly target smaller organizations and reach in through suppliers, and customers increasingly ask for objective evidence of your security posture.

Third-Party Assessments Are Becoming Formalized

Japan's METI is launching a Supply Chain Security (SCS) assessment scheme by the end of FY2026, giving participating organizations objective star-rated levels to demonstrate their security posture.

Source: IPA / METI

Smaller Orgs and Suppliers Bear the Brunt

69% of ransomware cases hit organizations with 11–1,000 employees (Coveware Q4 2025), and third-party involvement in breaches doubled year-over-year (Verizon DBIR 2025) — external exposure matters regardless of size.

Source: Coveware Q4 2025 / Verizon DBIR 2025

Pricing

ASM

$290/month

Know — discover, monitor, rank by risk

Includes 3 origin domains and 5 users (unlimited subdomains underneath)

CTEM

$490/month

Verify, act, and report

Includes 3 origin domains and 5 users (unlimited subdomains underneath)

Downloads

Download our materials

Everything on the service, pricing, and company — free to download, no sign-up required.

Start Managing Your Attack Surface, One Domain at a Time

ASM $290 / CTEM $490 — start your 14-day free trial and deploy the CTEM framework immediately.

Start Your 14-Day Free Trial