Attack Surface Management
Attack surface management is the continuous process of discovering, inventorying, and reducing the external-facing assets and exposures that an attacker could target. It maps what an organization exposes to the internet and prioritizes risks based on exploitability and business impact.
itDefensive security and security operations | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic — Attack Surface Management
Attack surface management, or ASM, is the recurring task of finding the ways an attacker can reach systems and deciding which routes deserve to disappear. Before that, teams often had inventories, scanners, and ticket queues that each held a different corner of the map. None of them reliably answered whether a public thing was still there, belonged to anyone, or mattered. A surprisingly popular arrangement, right up until it is not.
The useful mental model is a loop: discover, attribute, enrich, prioritize, remediate, and verify. Discovery finds names, addresses, services, certificates, and other clues. Attribution asks whether a clue is owned, a dependency, worth monitoring, or unrelated. That pause matters because a hostname that resembles an organization is evidence, not a deed of ownership.
Then add the awkward details. An outside-in view can see a reachable route but not its business value, data sensitivity, owner, or compensating controls. That is enrichment: joining the observation to the records that explain what it serves and who can change it. A finding without an accountable owner is not a remediation plan. It is a very organized form of waiting.
The common surprise is that a patched issue can leave the exposure intact. A public administration route might run a supported version tomorrow and still have no reason to be public. Prioritize the plausible path, not the loudest severity label. Reachability, exploit evidence, control weakness, privilege path, business impact, and available treatment each answer a different question.
The last step is verification. A closed ticket is useful evidence that work happened, but it does not prove the route stopped responding. Reobserve from the same vantage point, check alternate names and routes, and keep before-and-after evidence. Then watch for recurrence, because cloud templates and old DNS records have an unfortunate talent for remembering things you hoped they had forgotten.
Read the Intro for the full operating loop and its limits. Use the Cheatsheet when you need the asset, exposure, finding, and treatment distinctions close at hand. The Practice Reference turns the loop into a safe record-making exercise, and the Quiz checks whether a scanner result has tempted you into treating evidence as certainty.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://www.ncsc.gov.uk/guidance/external-attack-surface-management-buyers-guide
Supports
- ASM scope and outside-in discovery
- https://cheatsheetseries.owasp.org/cheatsheets/Attack_Surface_Analysis_Cheat_Sheet.html
Supports
- Attack-surface analysis
- https://www.cisa.gov/news-events/directives/bod-23-01-improving-asset-visibility-and-vulnerability-detection-federal-networks
Supports
- Asset visibility and vulnerability detection
- https://csrc.nist.gov/CSRC/media/Projects/risk-management/800-53%20Downloads/800-53r5/SP_800-53_v5_1-derived-OSCAL.pdf
Supports
- Inventory and vulnerability monitoring
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Supports
- Known exploitation evidence
- https://www.first.org/epss/user-guide.html
Supports
- Exploit probability
- https://www.first.org/epss/faq
Supports
- EPSS limitations
- https://learn.microsoft.com/en-us/azure/external-attack-surface-management/what-is-discovery
Supports
- Seed-based discovery and attribution
- https://www.ncsc.gov.uk/guidance/asset-management
Supports
- Asset ownership and lifecycle
- https://learn.microsoft.com/en-us/azure/defender-for-cloud/concept-easm
Supports
- Microsoft external attack-surface discovery
- https://docs.censys.com/docs/asm-quick-start-guide
Supports
- Censys ASM discovery and monitoring
- https://www.tenable.com/products/attack-surface-management
Supports
- Tenable external attack-surface mapping
- https://www.cycognito.com/platform/attack-surface-management.php
Supports
- CyCognito attribution and validation
- https://www.paloaltonetworks.com/cortex/cortex-xpanse
Supports
- Cortex Xpanse external discovery
