External Attack Surface Mapping (EASM)

Know what you own, not what you documented

External attack surface mapping (EASM) finds everything reachable from the internet, documented or not, then lets you test any of it in one click.

SOC 2 Type II Certified G2 rating 4.7 out of 5 stars Gartner Hype Cycle 2026 LPT certified eCPPTPT certified
We Map Webapps API Subdomain Cloud host Mobile LLM apps AI agents
Trusted by security teams at

Your inventory is a spreadsheet. Your attack surface is not

The staging box left running since 2023 is not in it. Nor is the acquired subsidiary whose DNS still points at live infrastructure, or the certificate expiring in eleven days on a subdomain nobody owns. A CMDB records what was requested through a process. Attackers do not work from that list. They build their own.

The gap

An asset that is not in your inventory is not in your scope, not in your pentest, and not in your risk report. It is still on the internet.

The pressure

Auditors ask for a complete asset inventory. Acquirers ask what they are buying. Neither accepts “as far as we know”.

What you get

One root domain in. No agents, no credentials. Every asset is one click from a full authenticated test, so visibility and validation share a platform.

From one root domain to a ranked, testable inventory

Four stages, each one picking up where the last left off. Jump to any of them.

1 Discover

Find the infrastructure your team stopped thinking about

One root domain in. Historical DNS surfaces hosts your team assumed were decommissioned years ago.

<1 hr
First inventory
0
Agents or credentials
100%
Non-intrusive
  • Subdomain enumeration from one root. The full connected surface, including shadow IT nobody registered.
  • Historical DNS cross-referencing. Dormant and abandoned hosts surfaced, then live-checked.
  • Technology fingerprinting. What each asset is running, without a credentialed scan.
  • Multiple roots and custom scoping. Add subsidiaries, and toggle anything you do not own out of scope in one click, right in the asset table, no ticket required.
  • Monitoring coverage, visible at a glance. See exactly which domains are actively monitored and which are not, so a gap doesn't hide in a sea of green.
Get a free attack surface scan
discovery input
Input acme.io
Method non-intrusive
Agents 0
Credentials none
Subdomains found 4,270
Active 2,204
First result 00:41:12
2 Grade

Know which exposures are already a problem

A list of assets still leaves you guessing what to fix first. Here, every asset arrives already graded.

A+ to F
TLS and certificate grading
3
Fingerprint types captured: MD5, SHA1, SHA256
Where allowed
Screenshot and geo captured
  • TLS and certificate grading. Protocol strength, cipher suites and expiry, scored A+ to F per asset.
  • Full certificate forensics. Issuer, validity period, MD5, SHA1 and SHA256 fingerprints, and serial number, not just a letter grade.
  • Every cipher suite named and rated. Each TLS 1.2 and 1.3 cipher suite in use on a host, flagged as recommended or not.
  • HTTP and redirect behaviour. Request type, response code, response time, redirect chain and content length, captured per host.
  • Screenshot and geographic location, where available. Visual proof of what's exposed on hosts that allow it, plus country, timezone and whether it's your origin server or a CDN edge.
  • Standard, high-risk and unusual ports flagged per host. Not just whether a port is open, but whether it's one that shouldn't be.
tls posture · filterable by org, root domain, technology and status
A+ · TLS 1.3 only 704 hosts
A 630 hosts
B 197 hosts
F · expired or invalid cert 75 hosts
Hosts graded 1,991
3 Posture

See the estate, not just the asset

Individual grades roll up into one estate-wide view: what your whole estate looks like today, and where it's trending.

9,297
Weak cipher suites flagged, estate-wide
37
Domains tracked
1,991
Hosts graded
  • Estate-wide TLS and cipher posture. Every weak cipher suite and deprecated protocol, counted across all hosts at once.
  • Email security per domain. SPF, DMARC, MX and mail-related TXT records, so a phishing gap can't sit unnoticed on a domain nobody watches.
  • Certificate expiry as a trend. Next expiry date plotted 90 days back and forward, live on the dashboard.
  • Who runs, issued and registered what. Tech stack, certificate issuer and registrar for every asset, tied to ownership so a subsidiary or shadow registration stands out instead of blending into the totals.
  • Geography, explained. Asset counts by country on a live map, with a note when a location is a CDN edge rather than your origin.
  • Every grade failure in one view. Everything below an A in one place, and a clean all-clear when there's nothing to fix.
estate posture · updated continuously
Domains tracked 37
Subdomains 4,270
Active 2,204
Weak cipher suites 9,297
Deprecated SSL/TLS versions 459
Insecure network protocols 805
Misconfigured email records 24
4 Act

From “we found it” to “we tested it” without leaving the page

This is the part most attack surface tools do not have. Any asset, one click from a full test. The inventory you hand an auditor becomes the same one your team tests from.

1 click
Discovery to test
Auto
New assets queued for assessment
0
Context switches
  • Launch a test from the asset view. AI-native DAST, vulnerability assessment, or a scoped expert-led engagement.
  • Auto-queue new assets. Newly discovered infrastructure goes for assessment as it appears.
  • Criticality tagging, Mission Critical to Negligible Impact. Set once on the asset, inherited by every finding raised against it.
  • Compliance mapping happens at test time. Mapping does not log or score findings on its own; launch a test on any asset and what comes back is mapped automatically to CWE, OWASP and the PCI DSS, HIPAA and ISO 27001 controls it violates.
See how the four stages connect
discovery → finding
Asset api-staging.acme.io
Action run full test
Authenticated yes
Findings 4
Highest severity Critical
Mapped to PCI 7.2.1 · CWE-639

AISO™ reads the backlog before you do

Discovery finds the assets. AISO writes the decisions: what is exposed now, what is about to break, and where remediation is slipping.

Your AI Security Officer, offering real-time insights and risk-based decision support.

Medium Priority
8
Imminent SSL/TLS Certificates Expiry

8 SSL/TLS certificates will expire in the next 30 days, which could lead to service disruptions and security risks.

High Priority
22
Inefficiencies in Vulnerability Remediation Cycles

MTTR for certain critical vulnerabilities exceeds 7 days, indicating inefficiencies in your current remediation process.

High Priority
10
Unrestricted Hacker Access Through Unpatched Exploits

10 vulnerabilities allow unauthenticated exploitation and have public exploits already available.

High Priority
7
Zero-Day Vulnerabilities Jeopardize Security

Multiple unpatched vulnerabilities could grant attackers unauthorized access to critical systems.

Critical
12
Vulnerabilities Lacking Patches Pose Immediate Risk

Active vulnerabilities identified with no patch currently available, increasing your attack surface.

Low Priority
5
Vulnerabilities Enable Lateral Movement or Privilege Escalation

A number of new vulnerabilities allow lateral movement across systems and privilege escalation.

INTEGRATIONS

Fits into the stack you already run.

Jira
ServiceNow
Slack
GitHub
Okta SSO
Qualys
View all

Attack surface mapping vs the tools you run now

Manual inventory / CMDB Standalone discovery tool Siemba, unified
How assets are found Recorded when requested Automated external discovery Continuous automated external discovery, plus historical DNS for dormant infrastructure
Access required Internal and credentialed Varies by vendor None: no agents, no credentials, no network access
Freshness As current as the last update Scheduled scans Rescanned every 8 hours once monitoring is on, not a weekly or monthly scan
Exposure detail Hostname and owner Ports and services TLS and cipher grade A+ to F, certificate expiry, technology fingerprint, screenshot, geo
What you can do about it Raise a ticket Export a CSV Launch a full authenticated test on any asset, in one click
Where findings go Nowhere A separate console One list shared with assessment, autonomous testing and manual pentest, de-duplicated at ingest
Compliance evidence Manual mapping Basic tagging Not native to discovery; launch a DAST run on any asset and the findings map to CWE, OWASP and the PCI DSS, HIPAA and ISO 27001 controls they violate

How Siemba compares

vs a standalone EASM or discovery tool

Most EASM tools find assets and stop. You still need a scanner, a dynamic testing tool and a pentest vendor to do anything about what turned up, plus four consoles to reconcile. Here, discovery is the front of one pipeline that ends in a verified fix.

vs your cloud provider’s inventory

It knows what is in your accounts. It does not know about the subsidiary’s DNS, the contractor’s landing page, or the host migrated off three years ago that is still resolving.

Free scan

See your external attack surface before you talk to anyone

Enter one root domain. You get the inventory an attacker would build: subdomains, live hosts, technology fingerprints, TLS grades and certificate expiries. No sales call required.

The outcomes security teams get from Siemba

What teams say about working with us
★★★★★
Taught us how to think about security.
Siemba didn't just find issues, they taught us how to think about security.
Alvin Allen
Head of Cybersecurity · FRONTSTEPS
Customer
★★★★★
Powerful all-in-one solution.
Uncovered assets we missed. Risks validated in hours, not weeks.
Arun C.
Verified · G2
G2
★★★★★
Great end-to-end tool for small teams.
Structured reports within minutes. Zero heavy overhead.
Mevin B.
Verified · G2
G2
★★★★★
Great end-to-end security platform.
Immediate visibility. Speed and ease of use, all in one.
Anandu N.
Verified · G2
G2
★★★★★
"Pentesting on steroids."
Continuous, automated, and actually actionable.
Security Professional
LinkedIn Review
LinkedIn

Pricing scales with your estate, not per seat

Automated assessment, mapping and autonomous testing come on one subscription. Expert-led engagements are scoped per application.

See pricing

The questions you'll actually ask

What is external attack surface mapping (EASM)?

External attack surface mapping (EASM) is the continuous discovery, monitoring and grading of every internet-facing asset an organisation owns, the way an attacker would find it, rather than relying on a manually maintained inventory. It typically covers domains, subdomains, cloud hosts, certificates and exposed services, kept current as the estate changes.

What's the difference between attack surface mapping and vulnerability management?

Attack surface mapping answers what you have and whether it's reachable from the internet. Vulnerability management answers what's actually exploitable, given what you have. EASM builds and maintains the inventory; vulnerability management and testing work from that inventory to find and prioritise the flaws. Used together, EASM feeds vulnerability management a current, complete list of what to assess.

What's the difference between EASM and CAASM?

EASM discovers what's reachable from outside your network, without credentials or agents. CAASM (cyber asset attack surface mapping) works internally: it aggregates asset data from your existing tools, such as a CMDB, EDR or cloud console, via API, to build a unified internal inventory. The two are complementary: EASM shows what an attacker can see; CAASM shows what you already know internally, and where the two disagree.

Why does attack surface mapping matter?

An asset nobody knows about can't be patched, monitored or included in a risk report, and attackers routinely find infrastructure internal teams have forgotten: a staging environment left running, a subsidiary's DNS still resolving, a certificate nobody renewed. Attack surface mapping closes that gap by continuously finding what's actually exposed, rather than relying on what was documented when it was built.

Do I need EASM if I already run penetration tests?

Yes, they solve different problems. A penetration test is a deep, point-in-time look at a defined scope, agreed in advance. EASM is continuous and unscoped: it finds the infrastructure nobody thought to include in that scope. In practice, EASM often tells you what should be in scope, and some of the most useful pentest findings come from assets EASM surfaced that weren't on anyone's list.

Is EASM necessary for a small company?

It scales down as easily as it scales up. A small company's external footprint is smaller, but the risk of an unmanaged, unmonitored asset is the same. Since it needs no agents or credentials and delivers a first inventory in under an hour, there is little practical setup cost even for a lean team.

Does this need agents, credentials, or network access?

None of the three. Give it a root domain and it works outward, enumerating subdomains and connected infrastructure, cross-referencing historical DNS for hosts your team assumed were long gone, then confirming what is still reachable today. Nothing is installed on your systems and nothing needs approving by your network team.

How is this different from the asset inventory we already have?

Your CMDB records what was requested through a process. This records what is reachable from the internet, whether anyone requested it or not. In practice the interesting results are the ones that were never in the CMDB: a staging environment left running, a subsidiary's DNS still pointing at live infrastructure, a landing page an agency stood up on a subdomain.

How do you handle assets we don't actually own?

Custom asset scoping. External discovery will surface things that resolve from your domain but are not yours: a shared CDN edge, a partner-hosted portal, a vendor's subdomain. Exclude them once and they stay excluded, so your numbers reflect your responsibility rather than inflating a dashboard.

Can we use this for subsidiaries or M&A due diligence?

Yes, and it is one of the more common reasons people start here. Add each entity as an additional root domain and you get separate, continuous coverage per company across your whole corporate footprint, including abandoned infrastructure surfaced through historical DNS, which is usually where the surprises live in a diligence process.

Does mapping actually test anything, or just find it?

Mapping is deliberately non-intrusive: it discovers, fingerprints and grades, but does not attack. Testing is the next step, and it is one click from any asset in the inventory: AI-native DAST for web apps and APIs, vulnerability assessment for hosts and services, or an expert-led engagement when something warrants a human. Keeping them separate is the point: discovery runs permissionlessly and continuously, while testing runs where and when you authorise it.

How quickly do we see the first inventory, and how often does it refresh?

The first pass typically completes in under an hour. Turn monitoring on for a domain and it is rescanned every eight hours for new subdomains, rather than waiting for a weekly or monthly scan. Domains with monitoring off keep their initial inventory but are not rescanned for anything new. The test-run allowance applies to deep test runs.

Is attack surface mapping the same thing as external attack surface mapping?

Broadly, yes. External attack surface mapping is the category name, and this is the discovery and monitoring core of it. We call it mapping because that is what it honestly does: finds, fingerprints and grades your external estate. What most tools in the category promise beyond that, namely validation, prioritisation and remediation tracking, happens here too, but through vulnerability assessment, autonomous testing and shared findings management.

How is the A+ to F certificate grade calculated?

Several signals feed into it: the certificate's own validity and strength, which TLS protocol versions the host has enabled, and which cipher suites it supports. Weak or deprecated combinations, such as TLS 1.0 or an outdated cipher, pull the grade down even if the certificate itself is otherwise valid.

Someone is mapping your attack surface today. Make sure it’s you first

Point Siemba at one domain and see the inventory an attacker would build. No contract, no agents, no sales call.