What attack surface monitoring actually covers (and what it doesn't)
Attack surface monitoring gets bundled with scanning and pentesting until the three blur together. They solve different problems. Knowing the boundary is how you avoid paying for overlap and missing the gaps.
What ASM does
Attack surface monitoring continuously discovers the internet-facing assets that belong to you — domains, subdomains, IP ranges, certificates, exposed services, cloud buckets, and the things nobody remembered to decommission. Its core job is discovery and change detection: telling you that something new is exposed, not auditing the security of every line of code behind it.
The value is in the word continuous. Your external footprint changes every time a team spins up a marketing site, a staging server, or a third-party integration. A point-in-time test can't see what didn't exist when it ran. ASM watches the perimeter so new exposure surfaces in days, not at the next annual assessment.
What ASM does not do
ASM is not a penetration test. It will flag that a login portal is exposed; it will not manually chain together a business-logic flaw to prove an attacker can drain an account. That depth requires a human tester.
It is also not a full vulnerability scanner of your internal network. ASM looks from the outside in — the same vantage point an attacker starts from. Internal posture, patch levels on workstations, and segmentation all need their own coverage.
- Discovery & inventory of external assets — yes
- Change and exposure alerting — yes
- Leaked credential and dark-web signal — often, as a paired feed
- Manual exploitation / proof of impact — no, that's pentesting
- Internal network and host auditing — no, that's a different scope
How the pieces fit together
Think of ASM as the always-on layer that decides what deserves a deeper look. It narrows an unbounded, ever-changing perimeter down to the handful of assets that are new, exposed, or drifting. Those become the targets you point a penetration test at.
Used that way, the three disciplines stack instead of overlap: monitoring finds the surface, scanning gives a fast first read, and human-led testing proves what an attacker could actually do with it.
Want this applied to your stack?
Every engagement starts with a no-obligation conversation about what you run and what worries you — the scoping is on us.
Talk to our team