Attack Surface Management
What is Attack Surface Management (ASM)?
Attack surface management is the practice of continuously finding, listing, and watching everything your organization exposes to the internet, so you see it before an attacker maps it first. Lavawall® Scout scans your external attack surface free.
Run a free domain scan See how it works
Domains · subdomains · open ports · TLS · email authentication · exposure over time
Definition
Your attack surface is the sum of everything an outsider can reach or learn about you without any inside access: your domains and subdomains, public IP addresses and open ports, web applications and login portals, TLS certificates, cloud storage buckets, and the DNS records that govern your email. Attack surface management is the discipline of keeping an accurate, current picture of all of it.
The reason it earns its own name is that the list is never static and never complete from memory. A marketing team spins up a subdomain for a campaign, a developer exposes a test server, a certificate lapses, an SPF record drifts past its lookup limit. Each change quietly adds a way in, and none of it shows up on an internal inventory. ASM works from the outside in, the way an attacker does, so those forgotten assets surface on your list instead of theirs.
Good ASM is continuous rather than a once-a-year snapshot. It discovers assets, assesses each one for exposure, prioritizes what actually matters, and re-checks on a schedule so a new gap is caught days after it opens, not months.
Core components
- Asset discovery. Finding the domains, subdomains, IPs, and services tied to you, including the ones no one documented.
- Exposure assessment. Checking each asset for open ports, weak or expired TLS, exposed admin panels, and misconfigured email authentication.
- Email and DNS posture. Verifying SPF, DKIM, and DMARC so attackers cannot spoof your domain and your real mail still lands.
- Prioritization. Ranking findings by real risk so a genuinely exposed service outranks cosmetic issues.
- Continuous monitoring. Re-scanning on a schedule and alerting when something new appears or a posture regresses.
Why it matters
Most breaches start with something the defender did not know was exposed: a forgotten subdomain, an open remote-desktop port, a domain with no DMARC enforcement that anyone can spoof. You cannot protect an asset you have not counted, and the internet-facing list drifts faster than anyone tracks by hand. ASM turns that blind spot into a maintained inventory.
It also shows up on the paperwork. Cyber-insurance underwriters increasingly run their own external scans before they quote, and questionnaires for SOC 2, CMMC 2.0, and NIST CSF ask how you identify and monitor internet-facing assets. Seeing your own exposure first, and fixing it, is cheaper than having an underwriter or an auditor point it out.
How Lavawall® helps with attack surface management
Scout is the free external scanner built into Lavawall®. Point it at a domain and it maps the internet-facing picture: the domain and its subdomains, TLS state, exposed services, and the SPF, DKIM, and DMARC records that decide whether someone can impersonate you. Two domains scan free, forever, so you can watch your own posture without a subscription.
Where a standalone scanner stops at the outside view, Lavawall® joins it to the inside one. The same platform correlates external exposure with what it sees on your endpoints and in your Microsoft 365 tenant, so an exposed asset and a matching internal signal become one alert rather than two you connect by hand. MSPs can run Scout white-labelled under their own brand, which turns a prospect's own exposure into a first conversation.
Frequently asked
- Is attack surface management the same as a vulnerability scan?
- They overlap but are not the same. A vulnerability scan checks known assets for known weaknesses. ASM starts a step earlier by discovering the assets themselves, including the ones nobody remembered, then watches them over time as they change.
- What counts as part of my attack surface?
- Anything an outsider can reach or learn about you: domains and subdomains, public IP addresses and open ports, web apps and login portals, TLS certificates, exposed cloud storage, and your email authentication records (SPF, DKIM, DMARC).
- Does Lavawall® do attack surface management?
- Yes. Scout, the free external scanner included with Lavawall®, maps your internet-facing domain, email authentication, and exposure, and the platform then correlates that outside view with what it sees inside your endpoints and Microsoft 365 tenant.