Definition · External Attack Surface Management

What is Asset Discovery?

Asset discovery is the process of building and maintaining an inventory of everything an organisation owns or operates — domains, subdomains, IP addresses, servers, web applications, certificates, and cloud resources. In an external security context, it means finding every asset that is reachable from the internet, including the ones nobody remembered to document.

Discovery techniques

External asset discovery combines multiple data sources:

  • DNS enumeration — resolving known domains and brute-forcing or permuting subdomain names
  • Certificate Transparency logs — public logs of issued TLS certificates, which reveal hostnames the moment a certificate is requested
  • Passive DNS and WHOIS data — historical records linking domains, IPs, and registrants
  • Port scanning — probing discovered hosts to find live services

Why it matters

Every downstream security activity — vulnerability management, penetration testing, incident response — assumes an accurate asset inventory. Assets that are missing from the inventory are still visible to attackers, and unmonitored assets are disproportionately likely to be unpatched or misconfigured. Shadow IT and forgotten infrastructure are common sources of breaches for exactly this reason.

Continuous, not one-off

Attack surfaces change constantly as teams deploy, migrate, and decommission services. EASM platforms such as SurfaceLoop treat asset discovery as a continuous process, re-enumerating the attack surface on a schedule rather than as an annual exercise.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.