Skip to content
Weekly Signal

Guide

How EASM Finds Unknown Internet-Facing Assets

How external attack surface management discovers forgotten services, shadow IT and ownership gaps from the outside in.

Asset ManagementAttack Surface Management

Most organisations have an inventory. Fewer can prove that it includes everything visible from the internet. External attack surface management approaches the problem from the attacker’s perspective and continuously tests the assumed boundary.

Start with seed information

Discovery begins with known domains, brands, legal entities, IP ranges, autonomous system numbers and cloud relationships. These seeds are expanded through observable connections rather than trusted as a complete list.

Common discovery techniques

Discovery is not attribution

A technical relationship is evidence, not proof of ownership. Shared hosting, suppliers and inherited domains create false associations. Each candidate needs confidence, validation and an ownership workflow. The objective is a governed inventory, not the largest possible asset count.

What EASM tends to find

Typical findings include forgotten campaign sites, old test environments, unmanaged certificates, exposed administration interfaces, acquisition assets, third-party hosted services and cloud resources created outside normal processes. Many are not vulnerabilities in the CVE sense. Weak authentication, unsafe configuration and unclear ownership can be equally important.

The operating workflow

  1. Discover a candidate asset.
  2. Validate that it belongs to or materially affects the organisation.
  3. Identify the accountable owner.
  4. Classify the service, exposure and data handled.
  5. Assess weaknesses and attack paths.
  6. Remove, secure or formally govern it.
  7. Monitor for recurrence and ownership drift.

The NCSC’s EASM buyer’s guide highlights the value of an automated, continuously updated external view and the importance of integrating it with wider vulnerability-management processes.