EASM (External Attack Surface Management)
External Attack Surface Management (EASM) is the continuous discovery, attribution and assessment of an organisation’s internet-facing assets (domains, subdomains, certificates, exposed services and cloud surfaces) from an attacker’s outside-in perspective, using the same public sources an attacker would.
EASM answers the question every security team should be able to answer but often cannot: what do we actually expose to the internet, including the assets we have forgotten?
Unlike internal asset inventory or CAASM, EASM works from zero knowledge, discovering assets from public signals: DNS, Certificate Transparency logs, ASN registrations, WHOIS and cloud-provider metadata. The best EASM tools attribute each finding with a citation trail and control noise so analysts see real risk, not a firehose.
The core challenge EASM addresses is that most organisations do not have a complete inventory of their own internet-facing assets. Cloud adoption, shadow IT, mergers, and years of accumulated infrastructure leave forgotten subdomains, expired certificates, exposed admin panels and abandoned services that no one is watching but an attacker can find. EASM finds these before an attacker does.
EASM differs from a vulnerability scanner in where it starts. A scanner assesses assets you already know about and point it at; EASM begins with discovery, attributing assets to your organisation from public data with no prior list. The two are complementary: EASM tells you what you expose, and scanning or testing then assesses each discovered asset for weaknesses.
Good EASM controls noise as much as it discovers. Internet-wide data produces large volumes of findings, many of them irrelevant or already known, so the value is in accurate attribution, deduplication and prioritisation that surface genuine new exposure rather than a firehose. Continuous monitoring then flags changes, such as a newly exposed service or an expiring certificate, as they appear.
EASM discovers assets from the same public signals an attacker would use, including DNS records, Certificate Transparency logs, autonomous system and IP registrations, WHOIS data and cloud-provider metadata. The hard part is attribution: correctly determining which of the assets found on the internet actually belong to a given organisation, especially after mergers, acquisitions and years of decentralised infrastructure decisions that no central team ever recorded.
A common and high-value use of EASM is during mergers and acquisitions, where the acquiring organisation inherits an unknown external footprint and needs to understand its exposure quickly. More broadly, EASM answers the question of what an organisation looks like to an attacker performing reconnaissance, which is the starting point of most real intrusions and something internal asset inventories, built from the inside out, cannot fully provide.
For security teams, the practical payoff of EASM is the elimination of blind spots. The assets an organisation does not know it exposes are the ones it cannot patch, monitor or defend, and they are disproportionately the ones attackers find first. By surfacing that unknown footprint continuously and attributing it correctly, EASM turns the external perimeter from a source of surprises into something that can be measured, monitored and steadily reduced.
Precursor’s EASM is passive: it surfaces your external exposure from internet-wide data with no agents and no scanning of your systems, structured against the NCSC EASM Buyer’s Guide.