Home / Services / Web Security / ASM

Web Security / Discover and monitor internet-facing assets

Find what attackers can see,
before they do.

ASM (Attack Surface Management) automatically discovers your internet-facing assets every day and continuously inspects their open ports, TLS certificates and the technologies they use. It surfaces forgotten subdomains and database ports left open by mistake, and alerts you first about assets affected by vulnerabilities that are actually being exploited.

Challenges

Sound familiar?

The asset inventory doesn't match reality

Sites set up by business units or contractors, environments from finished campaigns, and test servers stay public without anyone managing them.

Slow first response to new vulnerabilities

When a critical vulnerability is disclosed, just finding out which of your systems are affected takes days.

Too many findings to act on

A vulnerability scan lists hundreds of results, but you can't tell which are truly dangerous and need fixing today.

Features

ASM key features

01Daily automated discovery

For each domain you register, ASM finds subdomains through Certificate Transparency (CT) logs and DNS enumeration, and adds only those that actually respond as assets. False positives caused by wildcard DNS are excluded.

02Imports public AWS resources

From connected AWS accounts, ASM automatically imports ALB, CloudFront, API Gateway, App Runner, Amplify, Elastic Beanstalk, EC2 instances with public IPs, and more. Assets that are hard to find from the outside are not missed.

03Open port checks

Every day, ASM checks common ports that should never be open to the outside, such as databases (MySQL, PostgreSQL, MongoDB, Redis, Elasticsearch, etc.), remote desktop, and Docker and Kubernetes APIs.

04TLS certificates and technology stacks

Detects expired, soon-to-expire, self-signed and hostname-mismatched certificates. Identifies server software and JavaScript library versions and matches them against known vulnerabilities.

05Active checks for known vulnerabilities, exposures and misconfigurations

Nuclei templates check for CVEs, exposed confidential information, misconfigurations and exposed admin panels. High-impact templates such as DoS and brute force are excluded, and only new templates are run incrementally.

06Prioritization with KEV and EPSS

Combines CISA KEV (vulnerabilities confirmed as exploited), known ransomware use, EPSS (exploit prediction scores) and severity to rank findings into tiers such as “Urgent”, “Priority” and “Watch”. KEV remediation due dates are shown too.

07Prompt alerts on changes

Get notified by email, Slack or webhook about newly discovered assets, newly opened ports, new vulnerabilities and certificates nearing expiry. Choose which types each destination receives.

08Active checks only on approved targets

Active checks that send attack patterns run only on targets for which an administrator has confirmed and agreed to three points: ownership, impact and revocability. Consent expires if the URL changes, and every action is recorded in the audit log.

How it works

Discovery, inspection and alerts,
running automatically every day

All ASM needs to start is a registered domain and a connected AWS account. Asset discovery, port and certificate checks, and vulnerability database updates run automatically every day, and you are notified only about what changed since the last run.

DISCOVER

Discover

Collects assets from Certificate Transparency logs, DNS enumeration and public AWS resources, and lists them with ASN, organization and country information.

RECON

Inspect

Checks open ports, service banners, TLS certificates and technology stacks, and records changes since the last run (new ports, new vulnerabilities, certificate issues).

ACTIVE CHECK

Verify

Actively checks approved targets for known vulnerabilities, exposures and misconfigurations. It can also detect vulnerabilities that require out-of-band responses, such as Log4Shell.

Prioritization

Not “everything is critical”:
start with what to fix today

Sorting by severity alone leaves more “critical” findings than you can handle. ASM combines whether a vulnerability is confirmed as exploited (CISA KEV), whether it is used by ransomware, and how likely it is to be exploited in the future (EPSS) to show you the order in which to respond.

KEV / RANSOMWARE

Confirmed exploited (KEV)

Vulnerabilities CISA has confirmed as exploited come first. Those known to be used in ransomware are flagged separately, and KEV remediation due dates are shown. The vulnerability catalog is updated every 6 hours.

EPSS

Exploit prediction (EPSS) × severity

Findings in the top 5% of EPSS with high severity are “Urgent”, the top 20% are “Priority”, and the top 50% are “Watch”. Hundreds of findings narrow down to the few to start on today.

Specifications

Scope and delivery

Discovery scope
  • Registered domains (Certificate Transparency logs, DNS enumeration)
  • Public resources in connected AWS accounts
Checks
  • Open ports and banners / TLS certificates / technology stacks and known vulnerabilities
  • Known CVEs, exposures, misconfigurations, exposed admin panels (active checks)
Frequency
  • Discovery, inspection, active checks: daily
  • Vulnerability data: KEV every 6 hours, NVD and EPSS daily
Notifications
  • Email / Slack / Webhook (choose types per destination)
Pricing
  • Billed by the number of monitored targets you enable

Please note: Domain ownership is based on your own declaration when you enable active checks. Cloud asset import currently supports AWS. Port checks cover common ports and are not a full scan of all ports. Asset discovery and inspection have a limit on the number of items per run.

Getting started

Getting started

  1. Register your domains

    Register your domains and, if needed, connect AWS accounts using a read-only role.

  2. Review your assets

    Discovered assets appear by the next day. Choose which to monitor continuously and exclude any that aren't relevant.

  3. Approve active checks

    After confirming ownership and impact, enable active checks for known vulnerabilities.

  4. Get alerts and respond

    When new assets or vulnerabilities are found, you're notified with a priority level.

FAQ

FAQ

Does registering a domain send any attack traffic?

No. Asset discovery and inspection use only light traffic, such as connection checks and about one HTTP request. Active checks that send real attack patterns don't run until you approve each target.

How is this different from an external vulnerability assessment?

ASM focuses on rediscovering your public assets every day and keeping track of changes and known vulnerabilities. To verify whether a weakness it finds can actually be exploited, pairing it with AutoPentest is effective.

Works well with

ASM — details and demo requests

Our team will explain deployment options and pricing for your environment.