01Introduction
You can't protect what you don't know exists. Marketing microsites, forgotten staging servers and acquired domains are all reachable by attackers and often missing from your inventory. Attack surface management finds them.
02What is ASM?
Attack surface management (ASM) is the continuous discovery, inventory and monitoring of every internet-reachable asset an organization owns, including domains, subdomains, IP addresses, cloud services, APIs and certificates, along with the exposures on each.
External ASM (EASM) works from the outside in, as an attacker would. It feeds discovery into CTEM and exposure management.
03How ASM works
ASM starts from what you know and expands outward.
- 1.
Seed
Start from known domains, IP ranges, cloud accounts and brand names.
- 2.
Expand
Use DNS, certificate transparency logs, WHOIS and scanning to find related assets.
- 3.
Fingerprint
Identify services, software versions and exposed interfaces on each asset.
- 4.
Assess and monitor
Flag risky exposures, test them, and alert when new assets appear.
04Threats and risks
Unknown assets are unmonitored assets.
Shadow IT
Services launched outside the security process, with default credentials and no patching.
Subdomain takeover
DNS records pointing to deprovisioned cloud resources that an attacker can claim.
Exposed admin panels
Management interfaces and dev tools left reachable from the internet.
Forgotten APIs
Old API versions still live, without the controls added to the new ones. See API security testing.
05How Parameter helps
Parameter discovers your external surface and tests what it finds.
Continuous discovery
External attack surface management maps what attackers can see.
Tested, not just listed
The pentesting agents probe discovered assets and prove what's exploitable.
Cloud inventory
Cloud Security inventories AWS, Google Cloud, Azure and Oracle Cloud resources, including ones nobody tagged.

