Skip to content
VITI Security

Services · EASM

Find the parts of your attack surface you do not know about.

Many companies have significantly more internet-facing assets than their security team knows about. Forgotten subdomains. Old marketing sites. Cloud accounts spun up by a developer six months ago. Each unknown asset is a possible entry point. External Attack Surface Management (EASM) finds them all, monitors them continuously, and tells you when something new appears that should not be there.

What our EASM service covers

Six layers - because asset discovery alone is not enough.

A scanner that knows your assets is straightforward. The hard part is building the asset list in the first place, and getting useful, prioritized signal out of the resulting noise.

Continuous asset discovery

We start from your root domain(s) and IP ranges and discover everything connected: subdomains (via DNS, certificate transparency logs, passive sources), associated IPs, cloud assets (AWS, Azure, GCP), exposed services (open ports, running software, versions), and SSL/TLS certificates. Daily refresh.

Shadow IT detection

SaaS spun up by a marketing team. A staging server that became production. A subdomain pointing to an old hosting provider. We flag assets associated with your domain that do not appear in your asset inventory - and route the alert to the person who should know.

Risk-scored vulnerability findings

Every discovered asset is scanned for vulnerabilities (CVEs, weak SSL/TLS configuration, exposed admin panels, missing security headers, outdated software). Findings are prioritized by exploitability and asset criticality - not just CVSS score - so your team works on what matters first.

Change monitoring + alerting

You are notified when something changes on your attack surface: a new subdomain appears, a port opens, a certificate is about to expire, a service version downgrades, an exposed database becomes publicly reachable. Alerts route via email, Slack, or webhook.

Manual triage by analysts

Automated EASM alerts can generate noise. Every critical finding is reviewed by a human analyst before it reaches you. We give context: "this is exploitable in your stack" or "this is theoretically present but the version is patched."

Remediation guidance, not just findings

Every finding comes with specific remediation steps - what to change, where, in what order. For complex findings, we get on a call with your engineering team and walk them through the fix.

Who needs EASM

If any of these describes your situation, you need it.

Engineering teams that ship to the internet

If developers can spin up infrastructure without security review, you need EASM. The blind spot is built into the workflow.

Companies with acquisitions or mergers

You inherit someone else attack surface. EASM maps it - on day one, not after the auditor asks.

Companies with marketing microsites

Campaign sites, landing pages, partner microsites - created by marketing, forgotten by IT. EASM catches them.

Companies preparing for SOC 2 / ISO 27001

Auditors increasingly ask "how do you know your full asset inventory?" EASM is the answer.

Companies in regulated industries

Fintech (SEC, PCI), healthcare, ecommerce. Regulators expect you to know your exposure - and ask for it specifically.

Companies after a near-miss or breach

Once you have seen an unknown asset bite you, you do not want it to happen again. EASM is the preventive layer.

What EASM is NOT

To be useful, here is what EASM does not replace.

EASM is one layer in a complete security program. We are honest about that - and we will tell you whether you need EASM right now, or whether a different control gives you more value first.

Internal vulnerability scanning

EASM is external-facing. Internal networks need separate scanning.

Manual penetration testing

Automated discovery catches the obvious. Manual testing catches business-logic flaws no automation will find. Both are needed.

Endpoint security

EASM does not see laptops or workstations. EDR / XDR is a separate concern.

SIEM or SOC monitoring

EASM tells you about exposure; a SOC tells you about active attacks. Different signal, different layer.

Pricing

Three tiers - sized by domain count + alert depth.

All tiers include onboarding (asset confirmation, alert routing setup) at no extra cost.

Discover

For small SMBs

Starting from

$139/ month
  • Up to 2 root domains
  • Extra domains $29 each per month
  • Monthly report
  • Email alerts
  • Daily refresh of asset inventory
Get a quote
Most popular

Monitor

For growing teams

Quoted to your scope
  • Up to 10 root domains
  • Extra domains $29 each per month
  • Daily refresh
  • Slack / webhook alerts
  • Monthly analyst review call
  • Manual triage on critical findings
Get a quote

Manage

For mid-market + SDFs

Quoted to your scope
  • Domain count scoped to your estate
  • Real-time alerting
  • Dedicated analyst
  • Integration with your ticketing
  • Monthly remediation calls
Get a quote

EASM FAQ

How is this different from a vulnerability scanner?
A vulnerability scanner takes a list of assets you give it and reports vulnerabilities. EASM builds the list, then scans it. The hard part is discovery, not scanning.
Will this find shadow-sm IT my employees set up?
Yes, if it is internet-facing and associated with your domain or IP space. SaaS tools accessed via employees personal credentials (e.g., personal Dropbox) are out of scope - for that you need a separate Shadow SaaS discovery tool.
Is this Vexta?
Vexta is the platform we use for scanning. EASM is the service layer on top - adding manual triage, remediation guidance, and analyst support. You can buy Vexta as a self-serve product, OR buy this EASM service which bundles Vexta with our team.
How fast do you find new assets?
Most new assets appear in your dashboard within 24 hours of going public. Certificate transparency logs (where every new SSL cert is logged) give us a fast signal - usually within minutes of certificate issuance.
Can I see a sample report?
Yes. Book a call and we will run a discovery against one of your domains in advance and walk you through what we find. No commitment - you keep the report regardless.

Next steps

Pick the next step.

Pick whichever fits how far along you are - we will meet you there.

Get a quote

Four fields. A fixed quote within one business day.

No sales call required to get a number. Tell us what triggered this and when you need it by, and we will come back with a fixed price for EASM.

A fixed quote within one business day. No CRM funnel, no SDR call.

See your full attack surface.

30-minute demo. We run discovery against one of your domains, walk you through the assets you did not know about, and recommend a tier (or no tier - if you do not need EASM, we will say so).