What is Attack Surface Management (ASM)? Seeing your own assets from outside

PentaTrail Team···8 min read
Contents

What attackers go after is the asset the defender does not know about. A subdomain missing from the inventory, or a storage bucket left public and forgotten, offers nothing to attach a control to.

Attack Surface Management (ASM) is the practice of enumerating what an attacker can see, from the same vantage point, and then keeping up with it.

01 / Enumerate what is visible from outside, by type

Starting from a domain, everything reachable from it is collected mechanically. What comes back sorts into six types of asset, with detected findings added alongside.

Diagram sorting externally visible assets into six types. Hosts, IP addresses, ports and services, technologies in use, cloud buckets and URLs are collected, and detected findings are added alongside

Figure 1: The types of asset collected, and the findings added to them

Deep dive: registration data sits in its own place

Registration details — registrar, expiry, name servers — appear per domain rather than in the asset count. Missing an expiry has direct consequences, so it is kept separate from the inventory.

02 / Assets you don't know about keep accumulating on their own

An inventory goes stale not because someone was lazy. Several routes create assets, and none of them has to pass through the IT department.

Diagram of the three routes by which unknown assets accumulate. Shadow IT, where departments sign up for cloud services on their own; M&A and reorganizations, which leave unmanaged domains behind; and cloud misconfiguration, such as storage left public or APIs with weak access control

Figure 2: Three routes by which assets slip out of the inventory

Deep dive: nobody involved acted in bad faith

A department signing up for a cloud service, or a dev team standing up a subdomain to test against, are both people moving work forward. Our piece on shadow IT goes into it. Domains inherited through an acquisition are the same: they fell out of a handover, not out of anyone's intent to hide them.

03 / Getting started is four steps, seeded by the assets you already know

Rather than searching for everything at once, the inventory you already have becomes the seed. Discovery needs a starting point, so the first step is the one a person supplies.

Diagram of the four steps to adopting ASM. Organize known assets, run automated discovery from that starting point, assess the risk of what is found, and monitor continuously

Figure 3: Four steps, seeded by assets you already know

Deep dive: step two is usually where the surprise lands

Discovery from a known domain tends to return a batch of subdomains and ports nobody had on the list. That reaction is common on adoption, and it is also the point of ASM. Ordering what turns up is handled by TER bands.

04 / One scan is not enough; what you follow is the change

Assets appear, configurations shift, vulnerabilities publish daily. The same asset being fine yesterday and not fine today is an ordinary occurrence.

Diagram contrasting a one-off scan with continuous monitoring. A one-off scan shows only the state at that moment, while continuous monitoring captures three kinds of change: new assets appearing, configurations changing, and newly published vulnerabilities

Figure 4: What you follow is the change, not the snapshot

Deep dive: keeping the changes on a timeline

Recording what changed and when lets you line up what appeared against what disappeared. A jump in findings right after a configuration change points straight at the change as the cause.

05 / ASM covers CTEM's discovery stage; ordering is the next stage's job

What ASM answers is "what exists." Which of it to start on is decided separately, by crossing asset weight with vulnerability weight.

Diagram of how ASM relates to CTEM. ASM covers the discovery stage of CTEM's five stages and hands the collected assets and findings to the prioritization stage, where TER bands are decided

Figure 5: ASM carries discovery; the order is set in the next stage

Seeing what your own domain turns up is free to try for 14 days.

Appendix: what counts as attack surface, and what PentaTrail covers

Table 1: assets treated as externally visible

Type What it includes
Domains and subdomains Not only production, but development and staging
IP addresses and ports Exposed services and APIs
Web applications Admin panels, API endpoints, forms
Cloud resources S3 buckets, Azure Blob, GCS and similar storage
SSL/TLS certificates Expiry and configuration defects
Technologies in use CMS, framework and library versions
WHOIS data How much domain registration data is public

Table 2: what PentaTrail covers

Capability Detail
Asset discovery Six types: hosts, IPs, ports and services, technologies, cloud buckets, URLs
Continuous scanning Scheduled automatic scans detect change
Security score A composite score out of 400 expressing the state of the attack surface
Change timeline What changed and when, in sequence

Ordering is handled by TER bands, and active confirmation of exploitability by AI deep scan. The full picture is in What is CTEM?.

The asset types were checked against PentaTrail's dashboard implementation on 2026-08-17.

Visualize your attack surface with PentaTrail CTEM/ASM

From discovery to vulnerability validation and remediation — all powered by the CTEM framework.

Get Started

See pricing/Compare and choose