External Attack Surface Management
Map Everything You Own on the Internet. Especially What You Forgot.
External Attack Surface Management finds and watches everything your organization exposes to the internet. Deepinfo starts from your domain, finds the subdomains, IP addresses, certificates, open ports and technologies behind it, including the ones nobody listed, and ranks them by how likely they are to be used against you.
- Inside a surveyed boundary that is your inventory: www, mail, api, staging, shop, blog, each a building with its name on its roof.
- Asset discovery: past the boundary, a hut nobody listed, vpn-legacy.acme.example at 203.0.113.24, not in inventory: 3389/tcp · RDP open, critical.
- Continuous scanning: the api tower, api.acme.example: Certificate expires in 6 days, medium.
- Risk detection: the shop, shop.acme.example: PHP 7.4 · end of life, high.
- Risk scoring: the staging shed, staging.acme.example, runs Apache httpd 2.4.49: CVE-2021-41773, CVSS 9.8, listed in CISA KEV, critical.
- Remediation: the same CVE, owner assigned, marked as resolved, then verified resolved after the rescan.
You Can’t Secure What You Don’t Know You Own.
Organizations have more internet-facing assets than their security teams can name. Attackers go looking for exactly the ones you lost track of.
Growth
Subsidiaries and Acquisitions
Group companies register their own domains. Acquisitions arrive with infrastructure nobody has inventoried yet.
Speed
Campaigns and Projects
Marketing launches from a new subdomain. A staging server built for one release is still answering a year later.
Distance
Partners and Agencies
Infrastructure run on your behalf, under your name, on networks you don’t operate.
One Root Domain and What It Leads To.
Discovery starts from a seed domain and follows what the internet ties to it: the subdomains, the IP addresses they resolve to, the certificates that name them and the services behind them.
-
Root domain
acme
.example IP address
-
www.acme.example
443/tcp · TLS 1.3
nginx 1.25
198.51.100.10
-
mail.acme.example
25/tcp · SMTP
MX · SPF record
198.51.100.12
-
api.acme.example
Certificate expires in 6 days Medium
198.51.100.40
-
staging.acme.example
Apache httpd 2.4.49 High
CVE-2021-41773 Critical KEV
203.0.113.7
-
shop.acme.example
PHP 7.4 · end of life High
198.51.100.77
-
blog.acme.example
Login page · HTTP 200
192.0.2.15
-
Asset discovery
not in inventory · found from the root
-
vpn-legacy.acme.example, not in inventory
3389/tcp · RDP open Critical
203.0.113.24
Each Part Feeds the Next.
Discovery feeds scanning, scanning feeds detection, detection feeds remediation, and all of it feeds the score.
Asset Discovery
Find every domain, subdomain and IP tied to your organization, including subsidiary infrastructure, shadow IT and inherited assets.
Continuous Scanning
Scan monitored assets layer by layer, from WHOIS to HTTP, and keep each layer’s history so you can see what changed.
Risk Detection
Misconfigurations, weak TLS, expiring certificates, exposed services, end-of-life technology and known CVEs in one feed.
Remediation
Each finding carries its evidence and keeps its state on record until a rescan confirms it is gone.
Risk Scoring
A security score per asset and per domain, with every CVE ranked by CVSS, EPSS and CISA KEV together.
Each Layer Is Scanned and Kept With Its History.
The platform stores each layer separately, with its own history, so you can see what changed and when.
- WHOIS: registrar, registration and expiry dates, registrant where published
- IP WHOIS: ASN, network owner, country
- DNS: A, AAAA, MX, NS, SOA, TXT and other record types
- SSL: certificate, issuer, validity, the names it covers
- Ports: open TCP and UDP ports and the services behind them
- Web data: page content, technologies, login pages, screenshots
- HTTP: response headers and status codes
Scanall checked
staging.acme.example
-
WHOIS
whoisacme.example · renews in 41 days
snapshot 2026-09-24
-
IP WHOIS
ipwhoisAS64500 · 203.0.113.0/24
snapshot 2026-09-24
-
DNS
dnsA 203.0.113.7
snapshot 2026-09-24
-
SSL
ssl*.acme.example · valid for 212 days
snapshot 2026-09-24
-
Ports
port_scan80/tcp · 443/tcp
snapshot 2026-09-24
-
Web data
webdataApache httpd 2.4.49 · CVE-2021-41773
snapshot 2026-09-24
Critical -
HTTP
http200 · response headers
snapshot 2026-09-24
CVEs Ranked by What Attackers Exploit.
CVSS says how bad a vulnerability could be. It does not say whether anyone is exploiting it.
Deepinfo enriches the CVEs found on your assets with EPSS, which estimates the probability of exploitation in the next 30 days, and with CISA’s Known Exploited Vulnerabilities catalog, which lists the ones already exploited.
The queue your team works from puts exploited and likely-to-be-exploited issues on exposed assets first, instead of all the “critical” ones in severity order.
- CVSS base score and vector
- EPSS probability
- CISA KEV listing
- CWE, mapped to OWASP Top 10 2021
- vDeep, Deepinfo’s own CVSS scoring layer
CVE on one of your assets
Fix first listed in CISA KEV, known to be exploited
-
CVE-2021-44228
CVSS 10.0
EPSS 0.99999 CISA KEV
Critical
-
CVE-2021-41773
CVSS 9.8
CISA KEV
Critical
The normal patch cycle EPSS low, not in CISA KEV
-
a CVE
CVSS 9.8
EPSS low
Critical
-
a CVE
CVSS 5.3
EPSS low
Medium
CVSS alone cannot tell the two 9.8s apart. CISA KEV and EPSS can.
From First Seen to Verified Gone.
An issue is never simply deleted. Every scan checks it again: when the signal is gone, the scan verifies it resolved on its own, and when a scan cannot tell, it sets not applicable. Your team can accept, ignore or disprove it, and every decision stays on record. If a resolved signal returns, the issue reopens as reappeared.
Found
Open
The team can decide
Each scan checks
newly detected
orreappeared
unresolved
checked again on every scan
optional, kept on record
marked as resolvedrisk acceptedignoredmarked as false positive
verified resolved
the signal is gone: no one has to mark itnot applicablewhen a scan cannot tell
What Your Team Gets Out of It.
Reporting
Reports for Executives and Operators
Executive summary, weekly progress, asset detail, vulnerability detail and overview, issue overview and detail. On demand or on a schedule, as PDF.
Alerting
Notifications on Your Terms
New issues, reappeared issues, score changes, certificate, WHOIS and DNS changes, new assets, new vulnerabilities, new open ports. Instant, hourly, daily, weekly or monthly.
Frameworks
Compliance in One Filter
Issues are classified against OWASP Top 10 2021, PCI DSS 4.0 and 3.2, HIPAA, CWE, CAPEC and WASC, so “which findings fall under PCI DSS 4.0?” takes one filter to answer.
API
An API for Everything Else
Asset search across all layers, filter-driven bulk actions and per-asset scan history, all scriptable.
Query This Data Through the API
The subdomains, DNS records, certificates, ports and technologies this module finds come from Deepinfo’s own index. Your developers can query it through the API. The index holds 400M+ domains, 2B+ subdomains, 200B+ DNS records and 30B+ SSL certificates.
Questions About External Attack Surface Management
What is External Attack Surface Management?
External Attack Surface Management (EASM) is the continuous discovery, monitoring and risk assessment of an organization’s internet-facing assets. It treats discovery as ongoing: new domains, subdomains, exposed services and configuration changes are picked up as they appear, not once a year.
What does Deepinfo EASM detect?
Domains, subdomains and IP addresses tied to your organization, including ones missing from your inventory; open ports and exposed services; DNS and SSL/TLS misconfigurations; expired or expiring certificates; login and admin pages on the public internet; end-of-life technologies; and CVEs, each ranked with CVSS, EPSS and CISA KEV.
How is EASM different from vulnerability management?
Vulnerability management scans the assets you already know about, usually on a schedule. EASM starts by finding the assets you don’t know about, keeps watching them, and ranks findings by real exploitation signal as well as severity.
What does a typical workflow look like?
You give the platform a seed, usually your primary domain. It proposes related assets for your team to approve, scans the approved ones layer by layer, and raises scored issues. Your team assigns owners, works each issue through its states, and gets notified when something new appears or something resolved comes back.
Do we need to install anything?
No. Discovery and scanning work from the public internet, so there is no agent to deploy and no scan window to book. That also means internal systems, and anything reachable only through a VPN, stay out of view.
How often are assets scanned?
Monitored assets are rescanned on a recurring schedule that Deepinfo sets, and each check is stored with its date. Any asset can also be scanned on demand, from the platform or with one API call.
How is EASM priced?
Pricing depends on the scope you monitor. See pricing for how it works, or talk to us for a scoped quote.
What counts as an asset?
A domain, a subdomain or an IP address, each counted once. Discovered candidates your team ignores are neither monitored nor billed.
See What’s on Your Attack Surface. Right Now.
Book a working demo with our team.