Subscribe to our tailored platform plans by August 31st, 2026 and get the 1st month free.  Discover the plans

Attack Surface Monitoring (ASM) 2
Adaptive Workflow Routing
Native add-on · Attack Surface Monitoring

You can't defend what you can't see - and attackers can already see it. ASM shows you your whole external surface the way an adversary does, cuts through it to what's dangerous, and turns every exposure into a threat you can shut down before it's used. 

Why ASM, not just vulnerability scanning

Threat actors watch the perimeter continuously - internet-scale scanners catalog every new IP, certificate and exposed service within hours, and exploitation often begins within days of disclosure. The tooling built for the old world can’t keep up:

Authenticated scanners

only see what’s already in the CMDB - so shadow IT and unmanaged assets are invisible by definition.

Network scanners

only see what’s reachable from inside the perimeter - so externally-exposed cloud and SaaS fall outside their view.

Penetration tests

produce a snapshot already stale by the time the report is signed, against a pre-agreed scope rather than the real surface.

None of them answers the question that matters most: what does my attack surface look like to a threat actor, right now?

What ASM does differently

It operates continuously, from the outside in. It discovers assets with no prior knowledge of them, proves they belong to you, scores their exposure against real-world threat data, and feeds the result into the workflow where analysts already work. It’s the difference between knowing your perimeter on paper and knowing it the way an adversary does.

What changes for you

For enterprises

 

See your whole surface
Shadow IT, forgotten cloud, exposed services and dark-web exposure, in one ranked picture.

Trust every finding
0-100 attribution kills false positives on shared CDN IPs and third-party assets.

Fix what matters first
EPSS and CISA KEV prioritization, not a fifty-thousand-row dump.

Prove it
Continuous, audit-ready evidence for the board and regulators.

For MSSPs

 

One platform, many tenants
Row-level isolation and per-tenant quotas from one deployment.

Productized exposure management
Cross-tenant console, white-label reporting, per-tenant branding.

Better margins
Automation-grade discovery and attribution absorb the volume; analysts focus on judgment.

Economics that scale
Tenant-pool pricing grows with your book, not seat-by-seat.

Detection coverage

CapabilityWhat it delivers
Continuous multi-source discoveryYour full external surface, not just the CMDB - Certificate Transparency monitoring, cloud-bucket discovery and shadow-IT detection, corroborated across sources before anything enters inventory.
Six-signal attributionStop chasing false positives on shared CDN IPs - every asset scored 0-100 with a visible evidence trail; low-confidence assets queue for review, not active scope.
Contextual risk prioritizationVulnerability detection enriched with EPSS exploit-prediction, the CISA KEV catalog and business-context tagging - so analysts work what adversaries actually exploit.
State & change detectionDelta-based alerting on what’s new, not the same finding daily; every asset versioned over time to answer “when did this appear, and what changed with it?”
Severity-tiered SLAsTime-to-fix targets per severity, with breach alerts and SLA-compliance reporting in the executive dashboard.
MSSP-grade multi-tenancyRow-level isolation, per-tier gating, per-tenant quotas, white-label reporting and a cross-tenant console - a productized model, not a build per customer.
Complete workflow lifecycleA full finding state machine (new → triaged → in-progress → resolved → reopened → risk-accepted), false-positive marking with reasoning, risk acceptance with expiry, and Jira/Slack/Teams/email integration.

 

Attribution - the accuracy differentiator

A single false positive on a board-reported risk dashboard erodes trust faster than ten true findings build it. So ASM never attributes an asset on one signal: it runs multiple independent attribution sources in parallel and combines them into one confidence score, banded to drive workflow behavior - not just dashboard colors.

Confirmed

≥70

Auto-included in scope; active scans permitted; alerts can fire.

Likely

40-69

Auto-included with elevated review priority; surfaced for confirmation.

Suspicious

10-39

Shadow-IT queue; no active probing; manual analyst decision.

Unknown

<10

Discarded from inventory; logged for traceability, not surfaced.

It gets sharper on its own. On the first confirmed scan, ASM bootstraps favicon hashes and JARM TLS fingerprints from your in-scope assets - then recognizes new assets bearing the same fingerprints automatically. Attribution accuracy improves with every scan, without manual tuning.

Beyond the perimeter - dark-web and third-party exposure

A modern attack surface is bigger than your own infrastructure. ASM applies the same discovery, attribution and workflow discipline to the places traditional scanners never look - all landing in the same UI, with the same severity and confidence model.

  • Compromised credentials - stealer logs, breach dumps and credential shops scanned against your domains; fresh captures with live session cookies elevated to critical, stale dumps routed to low-priority so there’s no noise.
  • Brand protection - impersonator and typo-squat domains surfaced as phishing precursors before an adversary can weaponize them.
  • Breach & exposure - ransomware-blog mentions and exposed-data discovery cross-referenced against your brand and assets, with two-signal attribution before any leak finding surfaces.
  • Planned-attack early warning - Initial Access Broker listings and forum threads naming your infrastructure surface as critical within hours, cross-referenced so generic claims don’t fire false alarms.
  • Threat-actor activity - emerging TTPs and tooling targeting your stack feed your detection-engineering and patching priorities, ATT&CK-tagged.

Proven against the MITRE ATT&CK playbook

ASM works the pre-attack stages - Reconnaissance and Resource Development - denying an adversary the very first move. Every finding carries its explicit MITRE ATT&CK technique, so it states the objective the moment it fires, and aligns to the frameworks boards and regulators recognize (NIST CSF, ISO 27001, NIS2, DORA).

Sharper on the platform

ASM is a native add-on reporting to the TDIR core - the hub every add-on connects through. It’s a closed loop: ASM → TDIR streams asset inventory, attribution metadata, vulnerability findings and state-change events as enrichment and standalone detections; TDIR → ASM flows detection observations and incident outcomes back, so an asset under active attack auto-elevates and a confirmed exploitation escalates its risk score. 

Correlated on TDIR, an exposure verdict meets the DNS verdict from DNS Shield, the compromised users from ITP, the endpoint context from ETMR and the response of Active Defense and SOAR. “RDP brute-force against 198.51.100.42” tells you nothing; the same alert, enriched by ASM as a newly-exposed production database, verified yours via JARM/SOA and live for six hours, is instantly a critical incident.

It covers your supply chain too

Your attack surface includes assets and code you don’t control. ASM extends the same external-discovery and dark-web treatment to your named third parties - so a vendor’s exposed services, certificate hygiene, leaked credentials or ransomware-blog mention surface before they become your incident. 

It also ingests Software Bills of Materials (SPDX and CycloneDX) and matches components against CVE, EPSS and KEV continuously. 

Every finding lands in the same risk register, scored the same way and aligned to DORA, NIS2 and the EU Cyber Resilience Act - with no separate TPRM dashboard.

How it deploys

ASM works outside-in, so there’s nothing to install on your assets to see them - it discovers your surface from the internet, the way an adversary does. It’s delivered as a native ClearSkiesTM add-on with first-class, bidirectional TDIR integration, or as a complete standalone product.

Licensing built for MSSPs

Exposure-aligned

priced on the attack surface monitored, so cost tracks the surface you actually protect.

Tenant-pool for MSSPs

sized to your book of business, with volume-aligned partner pricing and reseller rights.

White-label

per-tenant branding on reports, portals and notifications.

One operator console

findings, alerts and SLA status across every tenant, with bulk actions.

You’re not handed a scanner and left to it

ASM ships with a full services wrap: onboarding & scoping (defining scope and seeding attribution so discovery is accurate from day one), integration (into the platform), enablement & training (role-based tracks on attribution, prioritization and the finding lifecycle), and ongoing optimization (reviews of scope, attribution accuracy and SLA performance as your surface changes).