What attackers go after is the asset the defender does not know about. A subdomain missing from the inventory, or a storage bucket left public and forgotten, offers nothing to attach a control to.
Attack Surface Management (ASM) is the practice of enumerating what an attacker can see, from the same vantage point, and then keeping up with it.
01 / Enumerate what is visible from outside, by type
Starting from a domain, everything reachable from it is collected mechanically. What comes back sorts into six types of asset, with detected findings added alongside.

Figure 1: The types of asset collected, and the findings added to them
Deep dive: registration data sits in its own place
Registration details — registrar, expiry, name servers — appear per domain rather than in the asset count. Missing an expiry has direct consequences, so it is kept separate from the inventory.
02 / Assets you don't know about keep accumulating on their own
An inventory goes stale not because someone was lazy. Several routes create assets, and none of them has to pass through the IT department.

Figure 2: Three routes by which assets slip out of the inventory
Deep dive: nobody involved acted in bad faith
A department signing up for a cloud service, or a dev team standing up a subdomain to test against, are both people moving work forward. Our piece on shadow IT goes into it. Domains inherited through an acquisition are the same: they fell out of a handover, not out of anyone's intent to hide them.
03 / Getting started is four steps, seeded by the assets you already know
Rather than searching for everything at once, the inventory you already have becomes the seed. Discovery needs a starting point, so the first step is the one a person supplies.

Figure 3: Four steps, seeded by assets you already know
Deep dive: step two is usually where the surprise lands
Discovery from a known domain tends to return a batch of subdomains and ports nobody had on the list. That reaction is common on adoption, and it is also the point of ASM. Ordering what turns up is handled by TER bands.
04 / One scan is not enough; what you follow is the change
Assets appear, configurations shift, vulnerabilities publish daily. The same asset being fine yesterday and not fine today is an ordinary occurrence.

Figure 4: What you follow is the change, not the snapshot
Deep dive: keeping the changes on a timeline
Recording what changed and when lets you line up what appeared against what disappeared. A jump in findings right after a configuration change points straight at the change as the cause.
05 / ASM covers CTEM's discovery stage; ordering is the next stage's job
What ASM answers is "what exists." Which of it to start on is decided separately, by crossing asset weight with vulnerability weight.

Figure 5: ASM carries discovery; the order is set in the next stage
Seeing what your own domain turns up is free to try for 14 days.
Appendix: what counts as attack surface, and what PentaTrail covers
Table 1: assets treated as externally visible
| Type |
What it includes |
| Domains and subdomains |
Not only production, but development and staging |
| IP addresses and ports |
Exposed services and APIs |
| Web applications |
Admin panels, API endpoints, forms |
| Cloud resources |
S3 buckets, Azure Blob, GCS and similar storage |
| SSL/TLS certificates |
Expiry and configuration defects |
| Technologies in use |
CMS, framework and library versions |
| WHOIS data |
How much domain registration data is public |
Table 2: what PentaTrail covers
| Capability |
Detail |
| Asset discovery |
Six types: hosts, IPs, ports and services, technologies, cloud buckets, URLs |
| Continuous scanning |
Scheduled automatic scans detect change |
| Security score |
A composite score out of 400 expressing the state of the attack surface |
| Change timeline |
What changed and when, in sequence |
Ordering is handled by TER bands, and active confirmation of exploitability by AI deep scan. The full picture is in What is CTEM?.
The asset types were checked against PentaTrail's dashboard implementation on 2026-08-17.
Visualize your attack surface with PentaTrail CTEM/ASM
From discovery to vulnerability validation and remediation — all powered by the CTEM framework.
Get StartedSee pricing/Compare and choose