[{"data":1,"prerenderedAt":166},["ShallowReactive",2],{"wissen-en-attack-surface-management":3,"wissen-related-en-attack-surface-management":156},{"id":4,"title":5,"body":6,"description":135,"extension":136,"lang":137,"meta":138,"navigation":139,"path":140,"related":141,"seo":146,"short":147,"sitemap":148,"stem":149,"synonyms":150,"updated":154,"__hash__":155},"wissenEn\u002Fen\u002Fwissen\u002Fattack-surface-management.md","Attack Surface Management (ASM)",{"type":7,"value":8,"toc":123},"minimark",[9,13,18,21,24,28,31,60,63,67,70,74,77,81,84,88,91,95],[10,11,12],"p",{},"Attack surface management (ASM) is the continuous discovery, assessment and reduction of every point through which an attacker can reach a company. The attack surface covers externally reachable systems, internal networks, cloud accounts, identities and the traces a company leaves on the dark web. ASM turns all of this into a continuously updated inventory and rates every entry by its risk.",[14,15,17],"h2",{"id":16},"why-attack-surface-management-matters","Why attack surface management matters",[10,19,20],{},"Most successful attacks do not start with a sophisticated zero-day but with a system nobody had in mind: a test server from an old project, a subdomain still pointing at a cancelled cloud instance, a VPN gateway with outdated firmware, or a password that an infostealer put into circulation. Conventional vulnerability scans only check what they are told to check. Attackers check everything. ASM closes this gap by switching perspective: what is reachable from the internet, what of that is vulnerable, and what of that is actually exploitable?",[10,22,23],{},"For companies under NIS2, DORA or ISO 27001, a current asset inventory is no longer optional but an auditable foundation of risk management.",[14,25,27],{"id":26},"how-attack-surface-management-works","How attack surface management works",[10,29,30],{},"ASM runs as a cycle of four steps:",[32,33,34,42,48,54],"ol",{},[35,36,37,41],"li",{},[38,39,40],"strong",{},"Discovery",": Starting from a few seeds (main domains, IP ranges, cloud accounts), subdomains, hosts, open ports, services, web applications, certificates and technologies in use are discovered automatically. Good solutions suggest additional assets, for example from RIPE registrations or cloud inventories.",[35,43,44,47],{},[38,45,46],{},"Assessment",": Every asset is checked for vulnerabilities, misconfigurations and exposed services and enriched with context: is an exploit public? Is the vulnerability in the CISA KEV catalogue? What is the EPSS score?",[35,49,50,53],{},[38,51,52],{},"Prioritisation",": Reachability, exploitability and criticality produce a ranking that says what to fix first.",[35,55,56,59],{},[38,57,58],{},"Remediation and evidence",": Findings are assigned, fixed and closed automatically by a re-scan.",[10,61,62],{},"The difference from a one-off audit lies in the word \"continuous\": the attack surface changes daily, so the inventory has to keep up daily.",[14,64,66],{"id":65},"how-blacklensio-implements-attack-surface-management","How blacklens.io implements attack surface management",[10,68,69],{},"blacklens.io brings external discovery (domains, subdomains, IPs, services, web apps, technologies, certificates), internal scans via the Sentry agent, cloud inventories from AWS, Azure, Microsoft 365, GCP, Cloudflare and Hetzner, and dark web signals together in one workflow. New CVEs are matched in real time against the technology inventory; findings are prioritised by EPSS, CISA KEV and exploit availability. Assets that have not been seen for seven days disappear from the inventory automatically so that it reflects reality.",[14,71,73],{"id":72},"what-is-the-difference-between-asm-and-vulnerability-management","What is the difference between ASM and vulnerability management?",[10,75,76],{},"Vulnerability management checks known systems for known vulnerabilities. ASM starts one step earlier and first finds out which systems exist and are reachable at all. In practice the two complement each other: ASM provides the inventory, vulnerability management the testing and remediation process.",[14,78,80],{"id":79},"how-often-should-the-attack-surface-be-mapped","How often should the attack surface be mapped?",[10,82,83],{},"Continuously. New subdomains, cloud resources and services appear daily, and new vulnerabilities are published hourly. A weekly or monthly scan gives attackers several days' head start on average.",[14,85,87],{"id":86},"do-small-companies-need-attack-surface-management","Do small companies need attack surface management?",[10,89,90],{},"Yes, especially them. Small and mid-sized companies rarely have a complete inventory and no security team of their own to keep it up. Automated ASM does not replace a security owner, but it gives them the list they can work with.",[14,92,94],{"id":93},"related-terms","Related terms",[96,97,98,105,111,117],"ul",{},[35,99,100],{},[101,102,104],"a",{"href":103},"\u002Fen\u002Fwissen\u002Fexternal-attack-surface-management","External Attack Surface Management (EASM)",[35,106,107],{},[101,108,110],{"href":109},"\u002Fen\u002Fwissen\u002Fcontinuous-threat-exposure-management","Continuous Threat Exposure Management (CTEM)",[35,112,113],{},[101,114,116],{"href":115},"\u002Fen\u002Fwissen\u002Fvulnerability-management","Vulnerability Management",[35,118,119],{},[101,120,122],{"href":121},"\u002Fen\u002Fwissen\u002Ftyposquatting","Typosquatting",{"title":124,"searchDepth":125,"depth":125,"links":126},"",3,[127,129,130,131,132,133,134],{"id":16,"depth":128,"text":17},2,{"id":26,"depth":128,"text":27},{"id":65,"depth":128,"text":66},{"id":72,"depth":128,"text":73},{"id":79,"depth":128,"text":80},{"id":86,"depth":128,"text":87},{"id":93,"depth":128,"text":94},"Attack surface management explained: definition, why unknown assets are the biggest risk, how the ASM cycle works and how blacklens.io implements it.","md","en",{},true,"\u002Fen\u002Fwissen\u002Fattack-surface-management",[142,143,144,145],"external-attack-surface-management","continuous-threat-exposure-management","vulnerability-management","typosquatting",{"title":5,"description":135},"Attack surface management is the continuous discovery, assessment and reduction of every point through which an attacker can reach a company: external, internal and in the cloud.",{"loc":140},"en\u002Fwissen\u002Fattack-surface-management",[151,152,153],"ASM","Attack Surface Monitoring","Attack surface analysis","2026-09-14","wQJqH15xDDuUhfkiLHUeCh09S2tmVPKYm5hRZsQFlfM",[157,159,161,164],{"path":109,"title":110,"short":158},"CTEM is a programme described by Gartner with five phases (scoping, discovery, prioritisation, validation, mobilisation) that reduces the attack surface continuously instead of at points in time.",{"path":103,"title":104,"short":160},"External attack surface management inventories and monitors from the outside every internet-facing asset of a company, exactly as an attacker sees it.",{"path":121,"title":162,"short":163},"Typosquatting (Lookalike Domains)","Typosquatting is the registration of domains that closely resemble a known brand in order to lead users to phishing or fraud pages through typos or deception.",{"path":115,"title":116,"short":165},"Vulnerability management is the ongoing process of detecting vulnerabilities in systems, prioritising them by risk, fixing them and evidencing the fix.",1789638254590]