Blog Details Banner Image
Blog

Attack Surface Management: A Technical Guide

Date Icon
July 30, 2026
Category Icon
Category :
Attack Surface Management: A Technical Guide

Attack Surface Management (ASM) is the continuous discovery, inventory, monitoring and reduction of every asset an attacker could reach across an environment. The attack surface is not static. It expands with every deployment, cloud resource, SaaS integration, identity grant and third party connection, which is why ASM has to be a continuous process rather than a periodic inventory. This guide covers the surface types, the discovery methods for each, and how ASM feeds a wider exposure program.

Internal, external and identity attack surface

The attack surface has distinct layers, and effective ASM covers all three.

External attack surface is everything reachable from the public internet: domains, subdomains, exposed services and ports, certificates, cloud storage, APIs and forgotten or subsidiary assets. Managing this specifically is often called EASM.

Internal attack surface is everything reachable once inside the perimeter: internal services, hosts, lateral movement paths and trust relationships between systems.

Identity attack surface is accounts, entitlements, roles and federation trust. In cloud and SaaS heavy environments, identity is frequently the primary attack path, over permissioned roles and standing privileges often matter more than any single host vulnerability.

Focusing only on the external edge leaves the internal and identity paths that adversaries use after initial access unmanaged.

Discovery methods

External discovery (EASM)

  • Passive DNS and certificate transparency to enumerate domains, subdomains and hosts.
  • ASN and IP range enumeration to map owned network space.
  • External port and service scanning to identify exposed services and versions.
  • Technology fingerprinting to map software to potential known vulnerabilities.
  • Subsidiary mapping to surface assets from related entities and acquisitions.

Internal and asset discovery (CAASM)

  • Aggregation from cloud provider APIs for authoritative asset inventory in IaaS and PaaS.
  • EDR and agent telemetry for endpoint visibility.
  • CMDB and network scanning for on premises assets.
  • Identity provider integration for account and entitlement mapping

Continuous monitoring

Discovery is not a one time exercise.

  • New assets, exposure and configuration drift appear constantly.
  • Continuous monitoring detects: Newly exposed services and ports.
  • Certificate expiry and misconfiguration. New cloud resources outside the known inventory (shadow IT).
  • Configuration drift from a secure baseline.
  • New or changed identities and entitlements.

The value of ASM depends on cadence. Periodic discovery leaves blind spots between runs, which is precisely where unmanaged assets accumulate.

Where ASM fits in CTEM

ASM is the discovery engine of a Continuous Threat Exposure Management program. Discovery tells you what exists and is reachable. It does not tell you which of those assets carry genuinely exploitable exposure, or what to fix first. That requires the prioritisation and validation stages of CTEM. ASM finds the surface; CTEM decides what to do about it. See what CTEM is for the full model and CTEM vs EASM for how external discovery fits the program. A complete asset inventory is a common false finish line. Knowing an asset exists does not establish that it is exploitable or that remediating it is worthwhile. Validation, covered in the CTEM lifecycle, closes that gap.

Clarifying the terminology

What is the difference between ASM, EASM and CAASM?

ASM is the overall discipline covering internal and external surface. EASM is the external, internet facing subset. CAASM is the internal asset correlation layer built from API and agent data.

Is attack surface management the same as vulnerability management?

No. ASM discovers and monitors assets and exposure across the environment. Vulnerability management scans known assets for known CVEs. Both feed a CTEM program.

How often should attack surface discovery run? Continuously.

The surface changes constantly, so periodic discovery leaves gaps between runs.

Crossbow runs ASM as the discovery layer of a managed CTEM program, then validates exploitability with a CREST accredited testing team. See the CTEM programme or the penetration testing services.

Contact us

Get Cybersec

Cybersecurity processes are required to be baked into an organizations day-to-day processes for seamless adoption. Identify what is best for you.
We can help. Connect with us – we always love having a chat.

Let's Discuss together.

Have any queries ?
explore@crossbowsec.com