Advisor
SecOps
Attack Surface Management (ASM)
Attack Surface Management (ASM) refers to the continuous process of identifying, monitoring, and assessing all external digital assets and exposures that could be targeted by threat actors.
Attack Surface Management (ASM) refers to the continuous process of identifying, monitoring, and assessing all external digital assets and exposures that could be targeted by threat actors. ASM solutions provide organizations with visibility into their internet-facing infrastructure, including domains, IP addresses, cloud services, and third-party assets, to help uncover unknown or unmanaged resources that may introduce risk. Core capabilities of ASM include automated asset discovery, vulnerability detection, risk prioritization, and contextual analysis of exposures. These solutions often leverage external scanning, passive intelligence, and correlation with threat intelligence to map the organization’s attack surface as seen from an adversary’s perspective. ASM tools support ongoing monitoring to detect changes or new exposures in real time. Security teams, risk managers, and IT administrators typically use ASM to reduce the likelihood of external breaches by proactively managing digital exposures. Unlike vulnerability management, which focuses on known assets and internal scanning, ASM emphasizes the discovery and assessment of unknown or shadow assets outside the traditional security perimeter. Cyberin provides a neutral platform for organizations to explore and compare Attack Surface Management solutions based on their specific requirements.
31
Vendors
32
Products
82
Datapoints
Vendor Landscape how the vendors in this category relate
neutral · data-driven
Arrange bySimilarityThis categorySecOps DomainThe Cyberin Framework (TCF)SeniorityEmployee countStock price
Related Wiki Articles
Some products are hidden. Sign up for free to see them all.
Filters
Asset Coverage, Vulnerability Intel, Integrations, Compliance Map +6 more Show ↓
Vendor
All Palo Alto Networks HackerOne Detectify CrowdStrike NetSPI BitSight Fortinet Bugcrowd + 23 more
Asset Coverage
All Web Applications Domains Subdomains IP Addresses APIs Cloud Accounts SaaS Apps Mobile Apps
Vulnerability Intel
All CVE Mapping Threat Feeds Vulnerability Context Attack Trends Exploit Intelligence KEV Alignment Malware Associations Zero-Day Watch
Integrations
All ServiceNow Slack Jira Splunk GitHub Snowflake Microsoft Sentinel Datadog
Compliance Map
All ISO 27001 SOC 2 NIST CSF CIS Controls GDPR PCI DSS
Risk Types
All Exposed Services Misconfigurations Data Exposure Vulnerable Software Open Ports Leaked Credentials Typosquatting Shadow IT
Discovery Methods
All Passive Discovery Agentless Web Crawling DNS Enumeration Active Scanning Certificate Analysis Cloud API IP Range Sweep
Reporting
All Compliance Reports Custom Dashboards Executive Summaries Risk Heatmaps Technical Report Email Alerts Ticket Workflows
Use Cases
All Third-Party Risk Continuous Discovery Brand Protection Vulnerability Prioritization Cloud Security Attack Path Analysis Red Team Support M&A Diligence
Data Refresh
All Continuous Daily Real-Time Hourly Weekly
Deployment
All SaaS On-Premises Managed Service
24 products
Sort:
Show:
Attack Surface Management
FireCompass
Active ScanningCloud AccountsExposed Services
Attack Surface Management
Group-IB
Certificate AnalysisDomainsData Exposure
FortiRecon
Fortinet
Certificate AnalysisDomainsData Exposure
Attack Surface Analytics
BitSight
Cloud APICloud AccountsData Exposure
Attack Surface Intelligence
Recorded Future
Certificate AnalysisDomainsData Exposure
Shodan Monitor
Shodan
Banner GrabbingDomainsExposed Services
Cosmos
Bishop Fox
Active ScanningAPIsExposed Services
Discovery
ImmuniWeb
Certificate AnalysisAPIsData Exposure
Attack Surface Management
Assetnote
Active ScanningAPIsExposed Services
IONIX Attack Surface Management
IONIX
Cloud APIAPIsData Exposure
PREVENT/ASM
Darktrace
Attack Surface GraphAPIsExposed Services
Surface Monitoring
Detectify
DNS EnumerationAPIsData Exposure
Attack Surface Management
NetSPI
Active ScanningAPIsExposed Services
Attack Surface Management
Bugcrowd
Active ScanningAPIsData Exposure
Attack Surface Management
ZeroFox
Certificate AnalysisDomainsData Exposure
Attack Surface Management
UpGuard
Cloud APIDomainsData Exposure
Censys Attack Surface Management
Censys
DNS EnumerationCertificatesExposed Services
External Attack Surface Management
Qualys
Certificate AnalysisAPIsData Exposure
Falcon Surface
CrowdStrike
Certificate AnalysisAPIsData Exposure
Tenable.asm
Tenable
Active ScanningCertificatesExposed Services
Microsoft Defender External Attack Surface Management
Microsoft
Certificate AnalysisCloud AccountsData Exposure
Cortex Xpanse
Palo Alto Networks
Banner GrabbingCertificatesExposed Services
Cortex Xpanse Active ASM
Palo Alto Networks
Active ScanningAPIsExposed Services
External Attack Surface Management
Rapid7
Certificate AnalysisCloud AccountsExposed Services
Also in Security Operations & Threat Intelligence
Filter by Vendor
Palo Alto Networks
2 products
HackerOne
1 product
Detectify
1 product
CrowdStrike
1 product
NetSPI
1 product
BitSight
1 product
Fortinet
1 product
Bugcrowd
1 product
SecurityScorecard
1 product
Rapid7
1 product
Darktrace
1 product
UpGuard
1 product
Tenable
1 product
Censys
1 product
Mandiant
1 product
Recorded Future
1 product
CyCognito
1 product
Microsoft
1 product
SOCRadar
1 product
IONIX
1 product
IBM
1 product
Group-IB
1 product
Assetnote
1 product
Qualys
1 product
ZeroFox
1 product
Axonius
1 product
Bishop Fox
1 product
Shodan
1 product
FireCompass
1 product
ImmuniWeb
1 product
Intruder
1 product
0 selected
Compare
Looking for the best Attack Surface Management (ASM) tool? Our Advisor can help you compare.
Ask the Advisor
CYBERIN ADVISOR