Attack Surface Management
Attack Surface Management (ASM) data provides an insight into the assets of your organization exposed to public networks. The ASM data allows you to quickly identify vulnerabilities, misconfigured services, out-of-date software, and other issues that make your organization vulnerable to attacks. By pinpointing your most critical threats, you can take control of evolving cyber threats and identify what to remediate first.
To start generating ASM results, your organization must have an active license for the Attack Surface Management service. Contact Anomali Customer Support or your Anomali Sales representative for details. Once the ASM license is activated, the ASM data is generated weekly for the domain names, IPs, and IP ranges that a user with Org Admin privileges configured when they accessed the Attack Surface Management page for the first time. See Configuring Attack Surface Management Settings for more information.
Details of generated ASM results can be accessed in the followings ways:
-
View in the ThreatStream interface. See Viewing Asset Inventory and Viewing Report Details in the ThreatStream Interface for details
-
Download as an HTML file to view unique counts of discovered issues and to drill down each discovered issue. See Viewing ASM Report Details in an HTML File for details.
-
Download as a CSV file to view displayed data in a CSV file. See Exporting Attack Surface Management Data for details.
-
Download as a PDF file to view selected widgets in a PDF file. See Exporting Widgets to a PDF File for details.
ASM data provides a rich context for your Internet-facing assets, such as:
-
Unreachable assets
-
Internet facing hosts
-
SSH services
-
Open ports
-
Common Vulnerabilities and Exposures (CVEs)
-
CVEs with documented exploits
-
Invalid or expired certificates
-
End-of-life software