Services · EASM
Find the parts of your attack surface you do not know about.
Many companies have significantly more internet-facing assets than their security team knows about. Forgotten subdomains. Old marketing sites. Cloud accounts spun up by a developer six months ago. Each unknown asset is a possible entry point. External Attack Surface Management (EASM) finds them all, monitors them continuously, and tells you when something new appears that should not be there.
What our EASM service covers
Six layers - because asset discovery alone is not enough.
A scanner that knows your assets is straightforward. The hard part is building the asset list in the first place, and getting useful, prioritized signal out of the resulting noise.
Continuous asset discovery
We start from your root domain(s) and IP ranges and discover everything connected: subdomains (via DNS, certificate transparency logs, passive sources), associated IPs, cloud assets (AWS, Azure, GCP), exposed services (open ports, running software, versions), and SSL/TLS certificates. Daily refresh.
Shadow IT detection
SaaS spun up by a marketing team. A staging server that became production. A subdomain pointing to an old hosting provider. We flag assets associated with your domain that do not appear in your asset inventory - and route the alert to the person who should know.
Risk-scored vulnerability findings
Every discovered asset is scanned for vulnerabilities (CVEs, weak SSL/TLS configuration, exposed admin panels, missing security headers, outdated software). Findings are prioritized by exploitability and asset criticality - not just CVSS score - so your team works on what matters first.
Change monitoring + alerting
You are notified when something changes on your attack surface: a new subdomain appears, a port opens, a certificate is about to expire, a service version downgrades, an exposed database becomes publicly reachable. Alerts route via email, Slack, or webhook.
Manual triage by analysts
Automated EASM alerts can generate noise. Every critical finding is reviewed by a human analyst before it reaches you. We give context: "this is exploitable in your stack" or "this is theoretically present but the version is patched."
Remediation guidance, not just findings
Every finding comes with specific remediation steps - what to change, where, in what order. For complex findings, we get on a call with your engineering team and walk them through the fix.
Who needs EASM
If any of these describes your situation, you need it.
Engineering teams that ship to the internet
If developers can spin up infrastructure without security review, you need EASM. The blind spot is built into the workflow.
Companies with acquisitions or mergers
You inherit someone else attack surface. EASM maps it - on day one, not after the auditor asks.
Companies with marketing microsites
Campaign sites, landing pages, partner microsites - created by marketing, forgotten by IT. EASM catches them.
Companies preparing for SOC 2 / ISO 27001
Auditors increasingly ask "how do you know your full asset inventory?" EASM is the answer.
Companies in regulated industries
Fintech (SEC, PCI), healthcare, ecommerce. Regulators expect you to know your exposure - and ask for it specifically.
Companies after a near-miss or breach
Once you have seen an unknown asset bite you, you do not want it to happen again. EASM is the preventive layer.
What EASM is NOT
To be useful, here is what EASM does not replace.
EASM is one layer in a complete security program. We are honest about that - and we will tell you whether you need EASM right now, or whether a different control gives you more value first.
Internal vulnerability scanning
EASM is external-facing. Internal networks need separate scanning.
Manual penetration testing
Automated discovery catches the obvious. Manual testing catches business-logic flaws no automation will find. Both are needed.
Endpoint security
EASM does not see laptops or workstations. EDR / XDR is a separate concern.
SIEM or SOC monitoring
EASM tells you about exposure; a SOC tells you about active attacks. Different signal, different layer.
Pricing
Three tiers - sized by domain count + alert depth.
All tiers include onboarding (asset confirmation, alert routing setup) at no extra cost.
Discover
For small SMBs
Starting from
- Up to 2 root domains
- Extra domains $29 each per month
- Monthly report
- Email alerts
- Daily refresh of asset inventory
Monitor
For growing teams
- Up to 10 root domains
- Extra domains $29 each per month
- Daily refresh
- Slack / webhook alerts
- Monthly analyst review call
- Manual triage on critical findings
Manage
For mid-market + SDFs
- Domain count scoped to your estate
- Real-time alerting
- Dedicated analyst
- Integration with your ticketing
- Monthly remediation calls
EASM FAQ
How is this different from a vulnerability scanner?
Will this find shadow-sm IT my employees set up?
Is this Vexta?
How fast do you find new assets?
Can I see a sample report?
Next steps
Pick the next step.
Pick whichever fits how far along you are - we will meet you there.
Run a free website scan
Point it at a website you own and get a findings summary - no sales call needed.
Get a quote
Four short fields below. A fixed quote back within one business day.
Book a call
30 minutes, no deck, no pre-qualification. Bring the actual problem.
Try Vexta free
Run the same scanning engine yourself, self-hosted, on your own schedule.
Get a quote
Four fields. A fixed quote within one business day.
No sales call required to get a number. Tell us what triggered this and when you need it by, and we will come back with a fixed price for EASM.
See your full attack surface.
30-minute demo. We run discovery against one of your domains, walk you through the assets you did not know about, and recommend a tier (or no tier - if you do not need EASM, we will say so).

