[{"data":1,"prerenderedAt":171},["ShallowReactive",2],{"wissen-en-external-attack-surface-management":3,"wissen-related-en-external-attack-surface-management":161},{"id":4,"title":5,"body":6,"description":140,"extension":141,"lang":142,"meta":143,"navigation":144,"path":145,"related":146,"seo":151,"short":152,"sitemap":153,"stem":154,"synonyms":155,"updated":159,"__hash__":160},"wissenEn\u002Fen\u002Fwissen\u002Fexternal-attack-surface-management.md","External Attack Surface Management (EASM)",{"type":7,"value":8,"toc":128},"minimark",[9,13,18,21,24,28,31,66,69,73,76,80,83,87,90,94,97,101],[10,11,12],"p",{},"External attack surface management (EASM) inventories and monitors from the outside every internet-facing asset of a company: domains, subdomains, IP addresses, open ports, services, web applications, certificates and the technologies behind them. EASM works without credentials and without agents, using only what an attacker can see as well.",[14,15,17],"h2",{"id":16},"why-easm-matters","Why EASM matters",[10,19,20],{},"The external attack surface grows faster than IT departments document it. Marketing registers a campaign domain, a developer spins up a cloud instance for a test, a service provider puts an admin portal online. Each of these systems is reachable but in no inventory. Incident reports have shown the same pattern for years: initial access frequently happens through an asset the company was not aware of. EASM delivers the list of these assets and keeps it current.",[10,22,23],{},"There is also the regulatory side: NIS2, DORA and ISO 27001 require an asset inventory and a traceable vulnerability management process. Without external discovery both remain incomplete.",[14,25,27],{"id":26},"how-external-attack-surface-management-works","How external attack surface management works",[10,29,30],{},"EASM starts with a few seeds, usually the main domains and known IP ranges, and expands them automatically:",[32,33,34,42,48,54,60],"ul",{},[35,36,37,41],"li",{},[38,39,40],"strong",{},"Subdomain enumeration"," via passive sources (certificate transparency, DNS datasets) and active techniques (wordlists, permutations, large-scale DNS resolution).",[35,43,44,47],{},[38,45,46],{},"Host and port discovery",": which IPs respond, which ports are open, which services run there?",[35,49,50,53],{},[38,51,52],{},"Web and technology fingerprinting",": which applications, frameworks, server versions and products are in use? This produces a technology inventory (CPE) that is later matched against new CVEs.",[35,55,56,59],{},[38,57,58],{},"Certificate and DNS checks",": expired or soon-expiring certificates, faulty configurations, DNS records pointing at deleted cloud resources.",[35,61,62,65],{},[38,63,64],{},"Assessment",": every finding is rated by reachability, vulnerabilities, exploit availability and criticality.",[10,67,68],{},"Because the picture changes daily, the process runs continuously. Assets that disappear must be detected just like new ones.",[14,70,72],{"id":71},"how-blacklensio-implements-easm","How blacklens.io implements EASM",[10,74,75],{},"blacklens.io runs discovery as a pipeline from host to service, web, technology and lookalike domains. Thirteen specialised scanning engines work together, from port and service scans through DNS resolution to vulnerability checks, complemented by 786 HTTP fingerprints for 374 vendors and a subdomain wordlist of more than 200,000 entries. The scope expands automatically; suggestions come from cloud inventories, RIPE registrations and threat intelligence. All scans originate exclusively from Austria, Germany and Switzerland from fixed IP ranges that you can allow-list.",[14,77,79],{"id":78},"does-easm-need-access-to-my-systems","Does EASM need access to my systems?",[10,81,82],{},"No. EASM works purely from the outside with publicly reachable information. Neither agents nor credentials are required. For internal networks and authenticated checks, add an internal scanner such as the Sentry agent.",[14,84,86],{"id":85},"how-does-easm-differ-from-a-vulnerability-scanner","How does EASM differ from a vulnerability scanner?",[10,88,89],{},"A vulnerability scanner tests a predefined list of targets. EASM builds this list first, keeps it current and then tests. The value lies in discovery: a scanner cannot find a hole in a system nobody told it about.",[14,91,93],{"id":92},"how-quickly-does-easm-deliver-first-results","How quickly does EASM deliver first results?",[10,95,96],{},"With blacklens.io, discovery, vulnerabilities, technologies, lookalikes and dark web hits for a main domain are usually available within 24 hours of setup. Ongoing operation then updates the picture continuously.",[14,98,100],{"id":99},"related-terms","Related terms",[32,102,103,110,116,122],{},[35,104,105],{},[106,107,109],"a",{"href":108},"\u002Fen\u002Fwissen\u002Fattack-surface-management","Attack Surface Management (ASM)",[35,111,112],{},[106,113,115],{"href":114},"\u002Fen\u002Fwissen\u002Fcontinuous-threat-exposure-management","Continuous Threat Exposure Management (CTEM)",[35,117,118],{},[106,119,121],{"href":120},"\u002Fen\u002Fwissen\u002Ftyposquatting","Typosquatting",[35,123,124],{},[106,125,127],{"href":126},"\u002Fen\u002Fwissen\u002Fvulnerability-management","Vulnerability Management",{"title":129,"searchDepth":130,"depth":130,"links":131},"",3,[132,134,135,136,137,138,139],{"id":16,"depth":133,"text":17},2,{"id":26,"depth":133,"text":27},{"id":71,"depth":133,"text":72},{"id":78,"depth":133,"text":79},{"id":85,"depth":133,"text":86},{"id":92,"depth":133,"text":93},{"id":99,"depth":133,"text":100},"EASM explained: what external attack surface management is, why it finds shadow IT, how agentless discovery works and how blacklens.io implements it.","md","en",{},true,"\u002Fen\u002Fwissen\u002Fexternal-attack-surface-management",[147,148,149,150],"attack-surface-management","continuous-threat-exposure-management","typosquatting","vulnerability-management",{"title":5,"description":140},"External attack surface management inventories and monitors from the outside every internet-facing asset of a company, exactly as an attacker sees it.",{"loc":145},"en\u002Fwissen\u002Fexternal-attack-surface-management",[156,157,158],"EASM","External attack surface monitoring","Outside-in attack surface analysis","2026-09-14","ds20_hY9va_XAseRZ7LgqYczamhS8WSUezSWojSZolk",[162,164,166,169],{"path":108,"title":109,"short":163},"Attack surface management is the continuous discovery, assessment and reduction of every point through which an attacker can reach a company: external, internal and in the cloud.",{"path":114,"title":115,"short":165},"CTEM is a programme described by Gartner with five phases (scoping, discovery, prioritisation, validation, mobilisation) that reduces the attack surface continuously instead of at points in time.",{"path":120,"title":167,"short":168},"Typosquatting (Lookalike Domains)","Typosquatting is the registration of domains that closely resemble a known brand in order to lead users to phishing or fraud pages through typos or deception.",{"path":126,"title":127,"short":170},"Vulnerability management is the ongoing process of detecting vulnerabilities in systems, prioritising them by risk, fixing them and evidencing the fix.",1789638255886]