What is external attack surface management?
External attack surface management, or EASM, is the continuous, outside-in discovery and monitoring of everything an attacker could reach from the public internet: hosts, domains and subdomains, exposed services, certificates and cloud-facing assets. It runs agentlessly, because it has to work on assets nobody told you about.
That last point is what sets EASM apart from the rest of the security stack. Most tools begin with a list you supply. EASM begins with your organisation's public footprint and works out what belongs to you, which is the only way to find the things that are exposed precisely because no one is tracking them.
On PentestOps, EASM re-checks the perimeter between scheduled scans, raises real-time alerts on what changed, and ships every observation with an HMAC signature so the record is tamper-evident. For a vendor-neutral explanation of the category, read EASM explained.
| Question | Short answer |
|---|---|
| What it covers | Internet-facing assets, known and unknown, discovered from the outside in. |
| How often it runs | Continuously between scheduled scans, with 7-day asset re-verification. |
| What it needs installed | Nothing. EASM is agentless by design. |
| What it produces | A live inventory, a drift ledger, and real-time alerts on change. |
| Which plan | Continuous monitoring (EASM) is an Enterprise capability. See pricing. |
Attackers do not wait for your next scan window
A perimeter is never static. A staging subdomain gets pointed at production. A developer spins up a public-facing test instance and forgets about it. A certificate quietly expires. A cloud security group gets widened for a vendor integration and never wound back. None of these show up in a report written the month before, and any one of them is enough to hand an attacker a way in.
External attack surface management, or EASM, is built for that gap. Instead of waiting for the next scheduled engagement to notice a change, PentestOps keeps re-checking the external perimeter agentlessly, using the same discovery approach that drives a full scan, and flags what is different. For a vendor-neutral explanation of the category, read what EASM is.
This is a Continuous Security capability, not a separate product. It sits alongside your scheduled scans and the wider continuous penetration testing programme, closing the window between formal engagements rather than replacing them.
What EASM watches
PentestOps keeps a live picture of everything an attacker could reach from the outside, and revisits it continuously rather than on demand.
- Perimeter discovery. The same recon approach behind external network testing keeps mapping what the internet can see, without needing an agent installed anywhere.
- Asset inventory. AI classification with criticality, bulk CSV/XLSX import, and cloud sync across AWS, Azure, GCP and M365 keep the inventory of internet-facing assets current.
- 7-day re-verification. Every asset is re-checked on a 7-day cycle, so new and disappeared hosts do not sit unnoticed.
- Drift detection. A full change ledger tracks new hosts, missing hosts and unauthorised changes, so a spike in perimeter activity is visible rather than buried in a static list.
EASM, CAASM and the shadow IT problem
Two acronyms get used together and mean different things. EASM works outside-in: it discovers what the internet can see, with no prior knowledge of your estate. CAASM, cyber asset attack surface management, works inside-out: it consolidates the asset data you already hold, from cloud accounts, directories, spreadsheets and internal discovery, into one authoritative inventory.
You want both, because they fail in opposite directions. An inside-out inventory is only ever as complete as the systems feeding it, so it never sees the microsite a contractor stood up on a personal cloud account. An outside-in view finds that microsite but cannot tell you who owns it or how much it matters. Shadow IT lives in exactly that gap: assets that are real, reachable and unmanaged, often standing on a stale software version that no patch cycle covers.
PentestOps runs both sides on one platform. Continuous EASM does the outside-in discovery, while the asset inventory does the CAASM work: AI classification with criticality, bulk CSV/XLSX import, cloud sync across AWS, Azure, GCP and M365, and multi-method LAN discovery through the on-prem agent. It all lands in a single inventory with 7-day re-verification and a drift ledger, so a newly discovered host gets an owner and a criticality instead of sitting in a separate tool waiting to be reconciled.
How EASM differs from a vulnerability scanner
A vulnerability scanner answers the question 'what is wrong with these targets?'. You give it a target list, it checks each item against a signature set, and it returns findings. It is good at depth on assets you already know about, and blind to everything you forgot to include in the list.
EASM answers a different question: 'what is out there, and what changed?'. Discovery and change detection are the product rather than a side effect, ownership attribution matters as much as severity, and it runs continuously instead of inside a scan window. The two are complementary: EASM decides what belongs on the target list, and deep testing decides what is wrong with it.
PentestOps does not stop at either. Anything EASM surfaces can be scored with CVSS v3.1, checked against CISA KEV, and, where your Rules of Engagement allow, validated with safe exploitation, so an alert becomes proof rather than another queue item.
How EASM fits the scan cycle
EASM is not a replacement for a scheduled scan; it is the layer that keeps watching in between.
- Baseline. A scheduled scan or engagement establishes what is currently exposed, following the same 7-phase methodology as every PentestOps assessment.
- Continuous re-checks. Between scans, the platform agentlessly re-checks the perimeter and compares what it finds against the baseline.
- Alert on change. New hosts, exposed services or unauthorised changes generate a real-time threat alert.
- Tamper-evident evidence. Every observation is shipped with an HMAC signature, giving you a defensible record of what changed and when.
- Validate, do not guess. The next scheduled scan, or a manual re-run, scores the change with CVSS v3.1, checks exploit availability and CISA KEV listing, and where authorised, validates it with safe exploitation.
Proof, not just a notification
An alert tells you something changed. It does not tell you whether it matters. PentestOps closes that loop through exposure management: the same prioritisation and safe, RoE-gated exploitation used across the platform applies to what EASM finds, so you get evidence, not just noise.
What EASM adds beyond a scheduled scan alone
The value of EASM is easiest to see next to a scan that only runs on a schedule.
| Signal | Scheduled scan alone | With continuous EASM |
|---|---|---|
| A new public host appears | Missed until the next scheduled scan runs | Picked up by continuous re-checks and added to inventory |
| An exposed service changes configuration | Missed until the next scheduled scan runs | Flagged in the drift detection change ledger |
| Something needs urgent attention | Waits for the next report | Real-time threat alert as the change is observed |
| Evidence integrity for auditors | Report as issued | HMAC-signed log shipping, tamper-evident by design |
| Asset roster accuracy | As current as the last scoping conversation | Kept current by 7-day re-verification |
Watching the outside, the agent watching the inside
EASM covers what the internet can see. The on-premise agent provides the same continuous discipline inside your network: 24/7 monitoring, asset inventory and unauthorised-change alerts, deployed in about 5 minutes with 0 inbound firewall rules and outbound-only connectivity over TLS 443. Together they mean nothing in the estate, external or internal, goes unwatched between engagements.
Where EASM fits in your programme
Continuous monitoring (EASM) is an Enterprise capability. Asset inventory, 7-day re-verification and drift detection are part of the platform's broader asset management, and scheduled scans and scan comparison are available from the Professional plan. See pricing for current plan details.
EASM does not remove the value of a formal engagement or periodic continuous penetration testing cadence. It is the coverage layer that keeps the picture current between them, so the next scan starts from an accurate baseline instead of a stale one.
Why PentestOps
- Agentless by design: EASM re-checks the perimeter without deploying anything onto assets you do not control.
- Every alert can be validated with safe, RoE-gated exploitation, so your team acts on proof, not guesswork.
- Asset-wise pricing with unlimited scans within fair use, so continuous coverage does not multiply your bill by scan count.
- Findings map to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes.
- Australian-built and operated. The platform is hosted in Australia, customer data is stored in Australia, and Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified.