Attack Surface Management (ASM) is the continuous discovery, inventory, monitoring and reduction of every asset an attacker could reach across an environment. The attack surface is not static. It expands with every deployment, cloud resource, SaaS integration, identity grant and third party connection, which is why ASM has to be a continuous process rather than a periodic inventory. This guide covers the surface types, the discovery methods for each, and how ASM feeds a wider exposure program.
Internal, external and identity attack surface
The attack surface has distinct layers, and effective ASM covers all three.
External attack surface is everything reachable from the public internet: domains, subdomains, exposed services and ports, certificates, cloud storage, APIs and forgotten or subsidiary assets. Managing this specifically is often called EASM.
Internal attack surface is everything reachable once inside the perimeter: internal services, hosts, lateral movement paths and trust relationships between systems.
Identity attack surface is accounts, entitlements, roles and federation trust. In cloud and SaaS heavy environments, identity is frequently the primary attack path, over permissioned roles and standing privileges often matter more than any single host vulnerability.
Focusing only on the external edge leaves the internal and identity paths that adversaries use after initial access unmanaged.
Discovery methods
External discovery (EASM)
Internal and asset discovery (CAASM)
Continuous monitoring
Discovery is not a one time exercise.
The value of ASM depends on cadence. Periodic discovery leaves blind spots between runs, which is precisely where unmanaged assets accumulate.
Where ASM fits in CTEM
ASM is the discovery engine of a Continuous Threat Exposure Management program. Discovery tells you what exists and is reachable. It does not tell you which of those assets carry genuinely exploitable exposure, or what to fix first. That requires the prioritisation and validation stages of CTEM. ASM finds the surface; CTEM decides what to do about it. See what CTEM is for the full model and CTEM vs EASM for how external discovery fits the program. A complete asset inventory is a common false finish line. Knowing an asset exists does not establish that it is exploitable or that remediating it is worthwhile. Validation, covered in the CTEM lifecycle, closes that gap.
Clarifying the terminology
What is the difference between ASM, EASM and CAASM?
ASM is the overall discipline covering internal and external surface. EASM is the external, internet facing subset. CAASM is the internal asset correlation layer built from API and agent data.
Is attack surface management the same as vulnerability management?
No. ASM discovers and monitors assets and exposure across the environment. Vulnerability management scans known assets for known CVEs. Both feed a CTEM program.
How often should attack surface discovery run? Continuously.
The surface changes constantly, so periodic discovery leaves gaps between runs.
Crossbow runs ASM as the discovery layer of a managed CTEM program, then validates exploitability with a CREST accredited testing team. See the CTEM programme or the penetration testing services.


