Request demo

External Attack Surface Management

Map Everything You Own on the Internet. Especially What You Forgot.

External Attack Surface Management finds and watches everything your organization exposes to the internet. Deepinfo starts from your domain, finds the subdomains, IP addresses, certificates, open ports and technologies behind it, including the ones nobody listed, and ranks them by how likely they are to be used against you.

acme.example, seen from the public internet. A site plan of your campus, roofs only: the hosts in your inventory inside its boundary, and past it one host nobody listed, with what EASM finds on each.
  1. Inside a surveyed boundary that is your inventory: www, mail, api, staging, shop, blog, each a building with its name on its roof.
  2. Asset discovery: past the boundary, a hut nobody listed, vpn-legacy.acme.example at 203.0.113.24, not in inventory: 3389/tcp · RDP open, critical.
  3. Continuous scanning: the api tower, api.acme.example: Certificate expires in 6 days, medium.
  4. Risk detection: the shop, shop.acme.example: PHP 7.4 · end of life, high.
  5. Risk scoring: the staging shed, staging.acme.example, runs Apache httpd 2.4.49: CVE-2021-41773, CVSS 9.8, listed in CISA KEV, critical.
  6. Remediation: the same CVE, owner assigned, marked as resolved, then verified resolved after the rescan.

You Can’t Secure What You Don’t Know You Own.

Organizations have more internet-facing assets than their security teams can name. Attackers go looking for exactly the ones you lost track of.

Growth

Subsidiaries and Acquisitions

Group companies register their own domains. Acquisitions arrive with infrastructure nobody has inventoried yet.

Speed

Campaigns and Projects

Marketing launches from a new subdomain. A staging server built for one release is still answering a year later.

Distance

Partners and Agencies

Infrastructure run on your behalf, under your name, on networks you don’t operate.

One Root Domain and What It Leads To.

Discovery starts from a seed domain and follows what the internet ties to it: the subdomains, the IP addresses they resolve to, the certificates that name them and the services behind them.

  1. Root domain

    acme.example

    IP address

  2. www.acme.example

    443/tcp · TLS 1.3

    nginx 1.25

    198.51.100.10

  3. mail.acme.example

    25/tcp · SMTP

    MX · SPF record

    198.51.100.12

  4. api.acme.example

    Certificate expires in 6 days Medium

    198.51.100.40

  5. staging.acme.example

    Apache httpd 2.4.49 High

    CVE-2021-41773 Critical KEV

    203.0.113.7

  6. shop.acme.example

    PHP 7.4 · end of life High

    198.51.100.77

  7. blog.acme.example

    Login page · HTTP 200

    192.0.2.15

  8. Asset discovery

    not in inventory · found from the root

  9. vpn-legacy.acme.example, not in inventory

    3389/tcp · RDP open Critical

    203.0.113.24

Each Layer Is Scanned and Kept With Its History.

The platform stores each layer separately, with its own history, so you can see what changed and when.

  • WHOIS: registrar, registration and expiry dates, registrant where published
  • IP WHOIS: ASN, network owner, country
  • DNS: A, AAAA, MX, NS, SOA, TXT and other record types
  • SSL: certificate, issuer, validity, the names it covers
  • Ports: open TCP and UDP ports and the services behind them
  • Web data: page content, technologies, login pages, screenshots
  • HTTP: response headers and status codes

Scanall checked

staging.acme.example 203.0.113.7

  1. WHOISwhois

    acme.example · renews in 41 days

    snapshot 2026-09-24

  2. IP WHOISipwhois

    AS64500 · 203.0.113.0/24

    snapshot 2026-09-24

  3. DNSdns

    A 203.0.113.7

    snapshot 2026-09-24

  4. SSLssl

    *.acme.example · valid for 212 days

    snapshot 2026-09-24

  5. Portsport_scan

    80/tcp · 443/tcp

    snapshot 2026-09-24

  6. Web datawebdata

    Apache httpd 2.4.49 · CVE-2021-41773

    snapshot 2026-09-24

    Critical
  7. HTTPhttp

    200 · response headers

    snapshot 2026-09-24

CVEs Ranked by What Attackers Exploit.

CVSS says how bad a vulnerability could be. It does not say whether anyone is exploiting it.

Deepinfo enriches the CVEs found on your assets with EPSS, which estimates the probability of exploitation in the next 30 days, and with CISA’s Known Exploited Vulnerabilities catalog, which lists the ones already exploited.

The queue your team works from puts exploited and likely-to-be-exploited issues on exposed assets first, instead of all the “critical” ones in severity order.

  • CVSS base score and vector
  • EPSS probability
  • CISA KEV listing
  • CWE, mapped to OWASP Top 10 2021
  • vDeep, Deepinfo’s own CVSS scoring layer

CVE on one of your assets

Fix first listed in CISA KEV, known to be exploited

  1. CVE-2021-44228

    CVSS 10.0

    EPSS 0.99999 CISA KEV

    Critical

  2. CVE-2021-41773

    CVSS 9.8

    CISA KEV

    Critical

The normal patch cycle EPSS low, not in CISA KEV

  1. a CVE

    CVSS 9.8

    EPSS low

    Critical

  2. a CVE

    CVSS 5.3

    EPSS low

    Medium

CVSS alone cannot tell the two 9.8s apart. CISA KEV and EPSS can.

From First Seen to Verified Gone.

An issue is never simply deleted. Every scan checks it again: when the signal is gone, the scan verifies it resolved on its own, and when a scan cannot tell, it sets not applicable. Your team can accept, ignore or disprove it, and every decision stays on record. If a resolved signal returns, the issue reopens as reappeared.

Found

Open

The team can decide

Each scan checks

newly detected

orreappeared

unresolved

checked again on every scan

optional, kept on record

  • marked as resolved
  • risk accepted
  • ignored
  • marked as false positive

verified resolved

the signal is gone: no one has to mark itnot applicablewhen a scan cannot tell

What Your Team Gets Out of It.

Reporting

Reports for Executives and Operators

Executive summary, weekly progress, asset detail, vulnerability detail and overview, issue overview and detail. On demand or on a schedule, as PDF.

Alerting

Notifications on Your Terms

New issues, reappeared issues, score changes, certificate, WHOIS and DNS changes, new assets, new vulnerabilities, new open ports. Instant, hourly, daily, weekly or monthly.

Frameworks

Compliance in One Filter

Issues are classified against OWASP Top 10 2021, PCI DSS 4.0 and 3.2, HIPAA, CWE, CAPEC and WASC, so “which findings fall under PCI DSS 4.0?” takes one filter to answer.

API

An API for Everything Else

Asset search across all layers, filter-driven bulk actions and per-asset scan history, all scriptable.

EASM API reference

Questions About External Attack Surface Management

What is External Attack Surface Management?

External Attack Surface Management (EASM) is the continuous discovery, monitoring and risk assessment of an organization’s internet-facing assets. It treats discovery as ongoing: new domains, subdomains, exposed services and configuration changes are picked up as they appear, not once a year.

What does Deepinfo EASM detect?

Domains, subdomains and IP addresses tied to your organization, including ones missing from your inventory; open ports and exposed services; DNS and SSL/TLS misconfigurations; expired or expiring certificates; login and admin pages on the public internet; end-of-life technologies; and CVEs, each ranked with CVSS, EPSS and CISA KEV.

How is EASM different from vulnerability management?

Vulnerability management scans the assets you already know about, usually on a schedule. EASM starts by finding the assets you don’t know about, keeps watching them, and ranks findings by real exploitation signal as well as severity.

What does a typical workflow look like?

You give the platform a seed, usually your primary domain. It proposes related assets for your team to approve, scans the approved ones layer by layer, and raises scored issues. Your team assigns owners, works each issue through its states, and gets notified when something new appears or something resolved comes back.

Do we need to install anything?

No. Discovery and scanning work from the public internet, so there is no agent to deploy and no scan window to book. That also means internal systems, and anything reachable only through a VPN, stay out of view.

How often are assets scanned?

Monitored assets are rescanned on a recurring schedule that Deepinfo sets, and each check is stored with its date. Any asset can also be scanned on demand, from the platform or with one API call.

How is EASM priced?

Pricing depends on the scope you monitor. See pricing for how it works, or talk to us for a scoped quote.

What counts as an asset?

A domain, a subdomain or an IP address, each counted once. Discovered candidates your team ignores are neither monitored nor billed.

See What’s on Your Attack Surface. Right Now.

Book a working demo with our team.