Most organisations have an inventory. Fewer can prove that it includes everything visible from the internet. External attack surface management approaches the problem from the attacker’s perspective and continuously tests the assumed boundary.
Start with seed information
Discovery begins with known domains, brands, legal entities, IP ranges, autonomous system numbers and cloud relationships. These seeds are expanded through observable connections rather than trusted as a complete list.
Common discovery techniques
- DNS records and historical DNS relationships
- Certificate Transparency logs and certificate names
- WHOIS and registration relationships where available
- IP and ASN ownership
- Cloud-hosting and content-delivery relationships
- Web technology, headers, favicons and service fingerprints
- Links, redirects, analytics identifiers and shared infrastructure
Discovery is not attribution
A technical relationship is evidence, not proof of ownership. Shared hosting, suppliers and inherited domains create false associations. Each candidate needs confidence, validation and an ownership workflow. The objective is a governed inventory, not the largest possible asset count.
What EASM tends to find
Typical findings include forgotten campaign sites, old test environments, unmanaged certificates, exposed administration interfaces, acquisition assets, third-party hosted services and cloud resources created outside normal processes. Many are not vulnerabilities in the CVE sense. Weak authentication, unsafe configuration and unclear ownership can be equally important.
The operating workflow
- Discover a candidate asset.
- Validate that it belongs to or materially affects the organisation.
- Identify the accountable owner.
- Classify the service, exposure and data handled.
- Assess weaknesses and attack paths.
- Remove, secure or formally govern it.
- Monitor for recurrence and ownership drift.
The NCSC’s EASM buyer’s guide highlights the value of an automated, continuously updated external view and the importance of integrating it with wider vulnerability-management processes.