Platform
Attack Surface Management
Introduction

Attack Surface Management module

Overview

Attack Surface Management (ASM) is a comprehensive security capability designed to help you discover, monitor, and secure your organization's external digital footprint. By providing your domains and IP addresses, the platform automatically identifies all externally exposed assets - such as web applications, network services, technologies, and SSL certificates - and continuously scans them to detect security weaknesses.

Why ASM? ASM gives you the attacker's view of your external security posture—showing exactly what's exposed and exploitable before adversaries find it.

What ASM Delivers

  • Deep Asset Discovery - Comprehensive enumeration of your external attack surface
  • Automated Security Scanning - Active testing powered by a template-based scanning engine
  • Vulnerability Detection - Identification and validation of exploitable security weaknesses
  • Actionable Remediation - Clear fix guidance, CVSS scoring, and exploitation likelihood

This enables security teams to proactively reduce risk across web applications, network services, IP addresses, and technology stacks.


Core Capabilities

Attack Surface Management provides continuous, active security testing across your entire external digital footprint—giving you the attacker's view before adversaries find it.

  1. Active Security Testing ASM actively interacts with your assets to uncover vulnerabilities that passive techniques cannot detect, such as authentication bypasses, injection flaws, and insecure configurations.

  2. Template-Based Scanning Engine Scans leverage an extensive and continuously updated library of security templates aligned with real-world attack techniques.

  3. Continuous Monitoring Automated, scheduled scans ensure your security posture remains current as your infrastructure changes.

  4. Actionable Results Each finding includes severity scoring, exploitation context, and clear remediation steps—helping teams prioritize effectively.


How It Works

Add Top-Level Assets

Begin by adding your organization's primary external assets:

Asset TypeDescriptionExamples
DomainsRoot or primary domainsexample.com, company.org
IP AddressesPublic-facing infrastructure IPs203.0.113.10

Once added, ASM automatically runs an asset discovery workflow. Asset discovery focuses on visibility, while security scans focus on risk.

DNS Discovery

DiscoveryDescription
DNS RecordsA, CNAME, NS, MX, TXT, SOA, CAA
SubdomainsAutomatically enumerated subdomains
Associated IPsIPs resolved from DNS data

Application Discovery

DiscoveryDescription
Web ApplicationsHTTP/HTTPS services and responses
TechnologiesFrameworks, CMSs, and libraries (e.g., nginx, React, WordPress)
SSL CertificatesCertificate chain, expiration, and security grade
HTTP HeadersSecurity headers and server metadata
ScreenshotsVisual previews of discovered web applications

Network Discovery

DiscoveryDescription
Open PortsExposed TCP/UDP ports
Network ServicesServices running on each port
Service BannersVersion and service identification
ProtocolsTCP/UDP protocol detection
SSL/TLS ConfigurationEncryption details per service

IP Metadata Enrichment

Each discovered IP is enriched with contextual metadata:

MetadataDescription
ProviderHosting or cloud provider (e.g., AWS, Azure, Cloudflare)
GeolocationCountry and region
ASN InformationASN number and organization

Tip: If an asset is not discovered automatically, it can be added manually at any time to ensure full coverage.

Security Scanning

Once assets are identified, ASM performs active security scans to identify vulnerabilities and misconfigurations.

Default Scans

Default scans are preconfigured and enabled automatically:

  • Cover all discovered assets
  • Use all available scan templates
  • Run on a recurring schedule

This provides immediate and continuous security coverage with no setup required.

Custom Scans

You can create targeted scans to fit specific needs:

Scan TypeFocus AreaApplies To
DNS ScanDNS security and configurationDomains
Application ScanWeb apps, technologies, certificatesDomains, IPs
Network ScanPorts, services, and protocolsIP addresses

Port Configuration (Network Scans)

OptionDescription
Top 100Fast scans of common ports
Top 1000Broader coverage with common services
CustomSpecific ports or ranges (e.g., 80, 443, 8000–8100)

Scan Execution Options

Scans can be run:

  • Automatically — via default scheduling
  • On-demand — triggered manually at any time
  • On a schedule — using custom cron expressions

Vulnerability Detection

ASM performs active vulnerability validation, going beyond simple version matching to confirm whether vulnerabilities are actually exploitable.

Vulnerability Categories

CategoryExamples
CVE VulnerabilitiesActively validated known vulnerabilities
Web VulnerabilitiesXSS, SQL injection, SSRF, path traversal
Authentication IssuesAuth bypass, IDOR
MisconfigurationsDefault credentials, exposed admin panels
SSL/TLS IssuesWeak ciphers, expired certificates
DNS SecuritySPF/DMARC issues, spoofing risks
Information DisclosureSensitive files, debug endpoints
Cloud MisconfigurationsInsecure cloud service exposure

Severity Levels

SeverityMeaning
CriticalImmediate action required
HighHigh-risk issue requiring prompt remediation
MediumModerate risk
LowMinor issue
InfoInformational finding

Remediation Guidance

Every vulnerability includes:

  • Clear technical description
  • Business and security impact
  • CVSS severity score
  • Exploitation likelihood assessment
  • Step-by-step remediation guidance
  • External references and documentation

Scan Templates

ASM is powered by a template-based scanning engine, with dedicated templates for each scan type:

  • Application Scan Templates — Web security checks
  • Network Scan Templates — Network and service-level checks
  • DNS Scan Templates — DNS security validation

Customizing Templates

  • Use all templates for maximum coverage
  • Select specific templates for focused assessments

Continuous Updates

The template library is continuously updated with:

  • New CVE detections
  • Emerging attack techniques
  • Improved validation logic

Learn what each template detects, how intrusive it is, and when to use it:

Scanning Templates Catalog

Best Practices

  1. Assets are discovered automatically on a weekly basis — add your domains and IPs to get started
  2. Use Top 100 ports initially for faster insights
  3. Enable scheduled scans for continuous visibility
  4. Prioritize Critical and High findings
  5. Monitor newly discovered assets and changes over time

FAQ

What IP addresses are used for scanning?

To whitelist our scanners in your firewall or allowlist, use these IP addresses:

  • 66.234.148.106
  • 88.218.2.206
  • 66.234.150.90
  • 185.183.32.71
  • 175.110.121.93
  • 146.70.36.70
  • 66.234.151.234
NordStellar © 2026Privacy Policy