Attack Surface Management

Note: The Attack Surface Management page is hidden by default. The Attack Surface Management license is required to access the page. Contact Anomali Customer Support or your Anomali Sales representative for details.

Attack Surface Management (ASM) data provides an insight into the assets of your organization exposed to public networks. The ASM data allows you to quickly identify vulnerabilities, misconfigured services, out-of-date software, and other issues that make your organization vulnerable to attacks. By pinpointing your most critical threats, you can take control of evolving cyber threats and identify what to remediate first.

To start generating ASM results, your organization must have an active license for the Attack Surface Management service. Contact Anomali Customer Support or your Anomali Sales representative for details. Once the ASM license is activated, the ASM data is generated weekly for the domain names, IPs, and IP ranges that a user with Org Admin privileges configured when they accessed the Attack Surface Management page for the first time. See Configuring Attack Surface Management Settings for more information.

Note: Non-Org Admin users cannot see ASM data until ASM settings are configured by an Org Admin and at least one ASM report is generated.

Details of generated ASM results can be accessed in the followings ways:

ASM data provides a rich context for your Internet-facing assets, such as:

  • Unreachable assets

  • Internet facing hosts

  • SSH services

  • Open ports

  • Common Vulnerabilities and Exposures (CVEs)

  • CVEs with documented exploits

  • Invalid or expired certificates

  • End-of-life software