Best Attack Surface Management Tools for Internet-Exposed Assets
The internet already sees the name your CMDB missed.
CISA Binding Operational Directive 23-01 still requires automated asset discovery at least every 7 days across the IPv4 space an agency uses, not only the hosts an authenticated scanner was told to touch.
The wrong assumption is that a green internal scan equals an external attack surface program. The marketing subdomain that still resolves, the forgotten VPN concentrator, and the cloud bucket nobody tagged never sat in last year’s scoped pentest.
Cortex Xpanse puts the market timing bluntly: attackers scan the internet for weaknesses within 45 minutes, while enterprises average three or more weeks to find and fix the same class of exposure. Unit 42’s Attack Surface Threat Report attributes 73% of high-risk exposures to IT and networking infrastructure, business operations applications, and remote access services.
ASM and EASM products on this shortlist do different jobs once the inventory starts moving: internet-scale discovery, proof that a finding is real, prioritization against business context, exposure workflows into tickets, and remediation ownership when a playbook can close the hole. Queued CVEs from scanners you already run live on vulnerability management platforms.
How we evaluated
We read first-party docs, pricing pages, licenses, and release notes. We asked whether the product discovers names and ports you own, whether it validates exposures or only lists them, whether prioritization and ticketing are first-class, whether remediation ownership sits in the product or in a wiki, and whether an OSS path exists. A marketing page is a claim, not proof two products do the same work. Stay on assets you own or have written permission to examine.
| Tool | Best for | What to check |
|---|---|---|
| Censys | Internet-scale discovery across all 65K ports | Commercial ยท Internet Map ยท ARC workflows |
| Cortex Xpanse | Enterprise ASM with Active Response playbooks | Commercial ยท attribution ยท Cortex family |
| Microsoft Defender EASM | Azure-native external inventory and risk views | Commercial ยท asset-per-day ยท Defender stack |
| runZero | Agentless CAASM across IT, OT, and IoT | Commercial ยท free under 100 ยท fingerprinting |
| Detectify | Continuous discovery plus payload-based validation | Commercial ยท Surface Monitoring ยท per-domain meter |
| OWASP Amass | OSS enumeration you run on names you own | Apache-2.0 ยท you operate it ยท no SaaS desk |
Censys
Best for internet-scale discovery across all 65K ports

Censys frames ASM as internet visibility, not a CMDB export. The Internet Map claims coverage across all 65,535 ports so services on nonstandard ports and self-signed hosts still show up in the inventory attackers can already query.
ASM pushes exposure deltas into ticketing and VM tools. Censys ARC adds rapid-response alerts when a critical exposure or active exploitation pattern hits assets attributed to you. Pivot into the broader Censys Platform when the question becomes adversary infrastructure, not only “fix this host.”
Key features:
- First-party Internet Map across all TCP ports
- Continuous ASM inventory with history preserved
- ARC rapid-response notifications for critical exposures
- Integrations that open remediation tickets in existing queues
Why we like it:
When the requirement is “show me what the internet already indexes about us,” Censys is the discovery-grade answer with a path into investigation, not only a DNS seed expander.
Limits:
Commercial. A hit in the index is not permission to test a third party. Validation depth is thinner than a payload-based AppSec desk; many teams still pair Censys with a scanner or Detectify-style tester.
License or pricing: Commercial Censys Platform / ASM. Contact sales for enterprise ASM. Public research and limited search tiers exist separately from the managed ASM product.
Cortex Xpanse
Best for enterprise ASM with Active Response playbooks

Cortex Xpanse is the enterprise attribution desk: continuous internet discovery, supervised learning that maps what belongs to you, and Active Response playbooks that close exposures instead of only opening tickets.
First-party claims include scanning 4.3 billion IPv4 addresses multiple times a day and 500 billion ports daily. Forrester named Palo Alto a Leader in Attack Surface Management on their marketing pages. The product still sits in the Cortex family, so integration stories lean Cortex SOAR and the broader Palo Alto stack.
Key features:
- Active discovery across the public internet without an agent
- Machine-learning attribution of unknown assets to your org
- Active Response automation and playbooks
- Use cases for shadow cloud, M&A diligence, and zero-day blast radius
Why we like it:
When leadership wants remediation ownership on the same contract as discovery, Xpanse is the hosted answer that sells playbooks, not only an inventory export.
Limits:
Commercial, sales-quoted. Active Response is documented as an add-on path. Teams outside the Palo Alto ecosystem should price integration work honestly.
License or pricing: Commercial Cortex Xpanse. No public list price on the product page we read. Demo and contact-sales CTAs.
Microsoft Defender EASM
Best for Azure-native external inventory and risk views

Defender External Attack Surface Management is the Microsoft-stack EASM workspace: seed domains, IP ranges, WHOIS org names, or ASNs, then expand into a searchable inventory of internet-facing apps, dependencies, and infrastructure Microsoft attributes to you.
Pricing is consumption-based per billable asset per day through Azure, so cost tracks confirmed inventory size rather than a flat seat count. The value lands when Defender XDR or Microsoft security operations already own the rest of the desk and EASM is the external feed those teams lack.
Key features:
- Global discovery of internet-exposed resources including shadow IT
- Dynamic inventory across cloud and external dependencies
- Risk prioritization views for security and network responders
- Azure portal provisioning with asset-per-day metering
Why we like it:
When the organization already standardized on Defender, EASM is the external inventory that does not require a fourth vendor identity graph.
Limits:
Microsoft-centric. Confirmed billable assets drive cost, so noisy seed data is a budget problem. Not a payload-based AppSec tester.
License or pricing: Commercial Azure consumption. Microsoft documents asset-per-day billing; use the Azure pricing calculator for the current regional rate.
runZero
Best for agentless CAASM across IT, OT, and IoT

runZero is the CAASM-shaped seat on this list: agentless active scanning, passive discovery, and integrations that fingerprint IT, OT, IoT, cloud, and remote assets. The point is validating what other tools claim exists, including unmanageable devices inside the network.
A free tier covers home use and environments under 100 assets. SaaS and on-prem options exist, including air-gapped paths. First-party pages also document a planned combination with Dragos under a large Accenture-backed OT security platform. Treat that as corporate news, not as a reason to skip a current trial.
Key features:
- Agentless active scanning safe for many OT and IoT environments
- Always-on passive discovery where active probes are blocked
- Fingerprinting that enriches OS, services, and hardware context
- Ingress and egress integrations with EDR, MDM, cloud, and VM tools
Why we like it:
External ASM lists names the internet sees. runZero answers the sibling question: which assets inside and at the edge actually exist when owners swear they are gone.
Limits:
Not a pure internet-index EASM replacement. You still deploy explorers and own scan windows. Commercial beyond the small free tier.
License or pricing: Commercial runZero Platform. Free for under 100 assets. Contact sales above that. Dragos combination announced; product still marketed under runZero.
Detectify
Best for continuous discovery plus payload-based validation

Detectify Surface Monitoring continuously maps domains, subdomains, IPs, technologies, ports, and protocols, then runs payload-based vulnerability testing on what it finds. New assets are scanned when they appear instead of waiting for a quarterly DAST window.
The Crowdsource research model feeds modules from ethical hackers; first-party pages claim 99% of vulnerabilities they find lack a CVE. Application Scanning and API Scanning sit beside Surface Monitoring on the same platform when you need deeper authenticated DAST.
Key features:
- Continuous external discovery with subdomain and tech fingerprinting
- Payload-based testing rather than signature-only matching
- Crowdsource-driven modules and Alfred AI CVE-to-test pipelines
- Apex discovery and IP range options on higher plans
Why we like it:
When the program already knows most names but cannot prove which exposures are exploitable, Detectify is the validation workflow that still starts from the external surface.
Limits:
Commercial. Surface Monitoring is an add-on meter per domain on top of platform fees. Web-forward; not an OT fingerprinting desk.
License or pricing: Commercial. Public platform fees from โฌ0 (Starter), โฌ2,500 (Standard), โฌ5,000 (Professional), and โฌ15,000 (Enterprise) annual, plus additional cost per domain for Surface Monitoring.
OWASP Amass
Best for OSS enumeration you run on names you own

OWASP Amass is the open-source attack surface intelligence framework you operate yourself. It combines OSINT collection, DNS enumeration, and network mapping so a CMDB that cannot lose a name still gets a second opinion.
Active modes change the wire. Run them only against domains and networks you own or have written permission to examine. Amass is not a SaaS triage desk and does not sell remediation playbooks.
Key features:
- Passive and active enumeration modes documented upstream
- Intel and enum workflows for domains you authorize
- Apache-2.0 license on the owasp-amass/amass repository
- OWASP project governance and public docs
Why we like it:
It is the enum seat you can install without a sales call. Teams that later buy Censys or Xpanse still keep Amass for controlled passes on names they own.
Limits:
You operate it. No hosted attribution graph. Docs assume practitioners who already know recon scope rules. Active collection is not a third-party scan cookbook.
License or pricing: Apache-2.0 open-source framework. You host and operate it.
How to choose an ASM tool
Four questions before the quote. Names below are the shortlist, not a scored bake-off.
| Critical question | Why it matters | What to evaluate | Red flag |
|---|---|---|---|
| Do we need internet discovery, internal CAASM, or both? | Public indexes and on-network fingerprinting answer different maps. | Censys, Defender EASM, Xpanse for external. runZero for IT/OT/IoT truth. Amass for owned-domain enum. | A CMDB export sold as external ASM. |
| Must findings prove exploitability, or is inventory enough? | Unvalidated lists drown owners. | Detectify payload-based Surface Monitoring. runZero fingerprinting. Censys ARC for critical exposure alerts. | Banner matches with no validation path. |
| Who owns remediation after the alert? | Tickets without playbooks rot. | Xpanse Active Response. Platform integrations into Jira/ServiceNow. Detectify findings into engineering queues. | Discovery-only SKU with no named owner. |
| Is this a module on a stack we already pay for? | A fourth identity graph is debt. | Defender EASM inside Azure/Defender. Xpanse inside Cortex. Censys when internet intel is the buy. Amass when OSS is enough. | A VM brochure that mentions ASM in a PDF only. |
What we left out
- Shodan: the other known internet index. Censys already covers the search-engine discovery job on this rewrite.
- SecurityTrails: historical DNS. Useful, but passive history is not a full ASM desk.
- CyCognito, CrowdStrike Falcon Surface, Tenable ASM, Rapid7 Surface Command: platform or VM-adjacent EASM seats. Pick them when that stack is already the contract.
- ProjectDiscovery toolkit: strong recon CLIs. Amass holds the OSS enum seat here so the shortlist stays six.
What practitioners argue about ASM
Live threads keep returning to the same split: querying a public index is not the same as launching your own scan, and discovery without an owner is still noise. The dissenting view is that free recon only solves the map, while enterprise desks are sold for attribution and tickets.
Security Stack Exchange · Nov 2017
“Shodan and Censys searches can be considered passive because they are showing you results of a scan that took place some time in the past; the scan itself was active, but retrieving the results is passive.”
Operators still argue the legal line in rules of engagement. The useful distinction for buyers is inventory from an index versus a probe you authorize against assets you own.
Hacker News · Jan 2025
“Not just websites, but anything hosting a favicon. I’ve used runZero to find vulnerable internal assets that companies swore were no longer an issue.”
That is the CAASM argument in one sentence: external indexes miss the internal asset owners insist is gone. Text-only here because the Censys incident comment already uses the single HN permalink on this page.
Start with an internet inventory you trust, then add validation and remediation ownership. Keep the CVE queue on vulnerability management platforms. Stay on assets you own.
FAQs
Is ASM a pentest?
No. ASM continuously inventories and monitors what is visible. A pentest is a scoped engagement. Different jobs.
Does this replace vulnerability management?
No. ASM lists and prioritizes exposures on assets you may not have known about. Vulnerability platforms queue scanner findings on assets you already scan. Open both lists when you need both maps.
Can I scan a vendor from this page?
Not from this page. Only assets you own or have written permission to test. Querying a public index is not authorization to probe a third party.
Is this a scored bake-off?
No. Order is editorial.