Skip to content

Attack Surface Management (ASM)

Definition

Attack surface management is the continuous discovery, assessment and reduction of every point through which an attacker can reach a company: external, internal and in the cloud.

Also known asASMAttack Surface MonitoringAttack surface analysis

Updated:

Newly discovered assets+4 since yesterday
beispiel-gmbh.atRoot domain
vpn.beispiel-gmbh.atFortiGate SSL-VPN 7.0.12Critical
dev-old.beispiel-gmbh.atGitLab 15.2Shadow ITHigh
mail.beispiel-gmbh.atExchange Server 2019Medium
203.0.113.24OpenSSH 8.9NewInfo

Visuals show sample data.

How blacklens.io covers this

Attack surface management (ASM) is the continuous discovery, assessment and reduction of every point through which an attacker can reach a company. The attack surface covers externally reachable systems, internal networks, cloud accounts, identities and the traces a company leaves on the dark web. ASM turns all of this into a continuously updated inventory and rates every entry by its risk.

Why attack surface management matters

Most successful attacks do not start with a sophisticated zero-day but with a system nobody had in mind: a test server from an old project, a subdomain still pointing at a cancelled cloud instance, a VPN gateway with outdated firmware, or a password that an infostealer put into circulation. Conventional vulnerability scans only check what they are told to check. Attackers check everything. ASM closes this gap by switching perspective: what is reachable from the internet, what of that is vulnerable, and what of that is actually exploitable?

For companies under NIS2, DORA or ISO 27001, a current asset inventory is no longer optional but an auditable foundation of risk management.

How attack surface management works

ASM runs as a cycle of four steps:

  1. Discovery: Starting from a few seeds (main domains, IP ranges, cloud accounts), subdomains, hosts, open ports, services, web applications, certificates and technologies in use are discovered automatically. Good solutions suggest additional assets, for example from RIPE registrations or cloud inventories.
  2. Assessment: Every asset is checked for vulnerabilities, misconfigurations and exposed services and enriched with context: is an exploit public? Is the vulnerability in the CISA KEV catalogue? What is the EPSS score?
  3. Prioritisation: Reachability, exploitability and criticality produce a ranking that says what to fix first.
  4. Remediation and evidence: Findings are assigned, fixed and closed automatically by a re-scan.

The difference from a one-off audit lies in the word "continuous": the attack surface changes daily, so the inventory has to keep up daily.

How blacklens.io implements attack surface management

blacklens.io brings external discovery (domains, subdomains, IPs, services, web apps, technologies, certificates), internal scans via the Sentry agent, cloud inventories from AWS, Azure, Microsoft 365, GCP, Cloudflare and Hetzner, and dark web signals together in one workflow. New CVEs are matched in real time against the technology inventory; findings are prioritised by EPSS, CISA KEV and exploit availability. Assets that have not been seen for seven days disappear from the inventory automatically so that it reflects reality.

What is the difference between ASM and vulnerability management?

Vulnerability management checks known systems for known vulnerabilities. ASM starts one step earlier and first finds out which systems exist and are reachable at all. In practice the two complement each other: ASM provides the inventory, vulnerability management the testing and remediation process.

How often should the attack surface be mapped?

Continuously. New subdomains, cloud resources and services appear daily, and new vulnerabilities are published hourly. A weekly or monthly scan gives attackers several days' head start on average.

Do small companies need attack surface management?

Yes, especially them. Small and mid-sized companies rarely have a complete inventory and no security team of their own to keep it up. Automated ASM does not replace a security owner, but it gives them the list they can work with.

See which of these apply to your company.

The free exposure check shows in seconds which systems, technologies and dark web traces of your company are publicly visible.

  • 14 days free, all features
  • No credit card required
  • We walk you through your first findings