# External Attack Surface Management (EASM)

External Attack Surface Management (EASM) keeps an inventory of your internet-facing assets, suggests related assets through discovery, and reports the issues, vulnerabilities and technologies found on them.

Source: https://docs.deepinfo.com/guide/easm/

Last updated: 2026-09-26

---
EASM keeps an inventory of your internet-facing assets and reports what it finds on them: issues,
vulnerabilities (CVEs) and the technologies they run. Discovery finds candidate assets related to yours, and a
security score grades your organization, each asset and each issue type from A to F.

## Before You Start

- **Package:** EASM. Without it, EASM pages are replaced by a notice that the package is not included, with a
  **TALK TO US** button that opens an e-mail to support@deepinfo.com.
- **Role:** Admin or Member.
- **Data:** at least one asset. While your inventory is empty, every EASM page sends you to
  [Add assets](/guide/easm/add-assets/).

## Where to Find It

**Sidebar:** **EXTERNAL ATTACK SURFACE MANAGEMENT** › **EASM DASHBOARD** · [https://platform.deepinfo.com/app/easm/dashboard](https://platform.deepinfo.com/app/easm/dashboard)

EASM is the blue **EXTERNAL ATTACK SURFACE MANAGEMENT** group in the sidebar (**EASM** when the sidebar is
collapsed). Most items open a page with in-page tabs under the title:

| Sidebar item | In-page tabs | Guide page |
|---|---|---|
| **EASM DASHBOARD** | None | [EASM dashboard](/guide/easm/dashboard/) |
| **ASSETS** › **INVENTORY** | **OVERVIEW** · **ASSETS LIST** · **INSIGHTS** | [Browse your asset inventory](/guide/easm/asset-inventory/), [Asset insights](/guide/easm/asset-insights/) |
| **ASSETS** › **DISCOVERY** | **OVERVIEW** · **DISCOVERED ASSETS** · **SETTINGS** | [Review discovered assets](/guide/easm/discovery/), [Tune smart discovery](/guide/easm/discovery-settings/) |
| **ISSUES** | **OVERVIEW** · **ISSUE LIST** · **INSIGHTS** | [Triage issues](/guide/easm/issues/), [Issue insights](/guide/easm/issue-insights/) |
| **TECHNOLOGIES** | **OVERVIEW** · **TECHNOLOGIES LIST** · **INSIGHTS** | [Review detected technologies](/guide/easm/technologies/), [Technology insights](/guide/easm/technology-insights/) |
| **VULNERABILITIES** | **OVERVIEW** · **VULNERABILITIES LIST** · **INSIGHTS** | [Prioritize vulnerabilities](/guide/easm/vulnerabilities/), [Vulnerability insights](/guide/easm/vulnerability-insights/) |

**ASSETS** expands in place when you select it. The **OVERVIEW** tabs hold the summary cards of each area;
the list tabs hold the records. The header breadcrumb starts with **EASM**, for example
**EASM / ISSUES / ISSUE LIST**.

The **+** button in the header also has **ADD ASSETS / MANUALLY** and **ADD ASSETS / UPLOAD FILE**.

![The EXTERNAL ATTACK SURFACE MANAGEMENT group in the sidebar with ASSETS expanded, next to the Inventory page with its in-page tabs.](/img/guide/easm/index-01.png)

## Concepts

### Assets

An asset is one item EASM monitors. It is one of these types:

| Type | Tab label | Example |
|---|---|---|
| Domain | **DOMAINS** | `acme.example` |
| Subdomain | **SUBDOMAINS** | `www.acme.example` |
| IP address | **IP ADDRESSES** | `192.0.2.10` |
| Website | **WEBSITES** | `www.acme.example:8443` |

A website's name includes its port (`host:port`). All your assets together form your **inventory**. Some
messages and dialogs say "portfolio"; it means the same thing, your own monitored assets.

Asset names can carry badges: **MAIN ASSET**, **SEEMS INACTIVE**, and icons for a login page, an
internationalized name (**IDN**), a parked domain or a redirect. You can also tag assets.
[Browse your asset inventory](/guide/easm/asset-inventory/) explains each one.

### Discovery

Discovery rules look for assets related to the ones you already have. Each candidate starts in review. You
approve it into your inventory or ignore it. See [Review discovered assets](/guide/easm/discovery/).

### Issues and Issue Types

An **issue type** is a kind of finding, for example an expired SSL certificate. An **issue** is one issue type
found on one asset. The **ISSUE LIST** shows issue types by default, with the number of affected assets, and
can switch to one row per issue. Issue types belong to **categories** and have one of these severities:
**CRITICAL**, **HIGH**, **MEDIUM**, **LOW** and **INFORMATION**.

### Vulnerabilities

A vulnerability is a CVE that affects at least one of your assets. The **VULNERABILITIES LIST** shows one row
per CVE. States are kept per asset: each CVE on each asset has its own state, and you change it there.

### States

Every issue, and every vulnerability on an asset, has a state. The platform sets **NEWLY DETECTED**,
**UNRESOLVED**, **REAPPEARED**, **NOT APPLICABLE** and **VERIFIED RESOLVED**. You can set **IGNORED**,
**RISK ACCEPTED**, **MARKED AS RESOLVED** and **MARKED AS FALSE POSITIVE**, and revert them. See
[Change the state of issues and vulnerabilities](/guide/easm/change-issue-state/).

### Technologies

EASM detects the software, frameworks and services your assets run, with their versions and known CVEs.
They are listed under **TECHNOLOGIES**; see [Review detected technologies](/guide/easm/technologies/).

### Security Score

Your organization, each asset and each issue type get a score and an A to F grade. See
[How security scores work](/guide/easm/security-score/).

## Pages in This Section

Start here:

1. [EASM dashboard](/guide/easm/dashboard/): the one-page summary.
2. [How security scores work](/guide/easm/security-score/): grades, bands and asset weight.
3. [Add assets](/guide/easm/add-assets/): type them or upload a file.
4. [Browse your asset inventory](/guide/easm/asset-inventory/): the **ASSETS LIST** and its **OVERVIEW** tab.
5. [Investigate an asset](/guide/easm/asset-details/): the asset drawer and detail page.
6. [Review discovered assets](/guide/easm/discovery/): approve or ignore candidates.
7. [Triage issues](/guide/easm/issues/): the **ISSUE LIST** and its **OVERVIEW** tab.
8. [Change the state of issues and vulnerabilities](/guide/easm/change-issue-state/).
9. [Prioritize vulnerabilities](/guide/easm/vulnerabilities/): the **VULNERABILITIES LIST** and its
   **OVERVIEW** tab.

Then, as you need them:

- Assets: [Tag, weight and configure assets](/guide/easm/asset-settings/),
  [Remove and restore assets](/guide/easm/remove-and-restore-assets/),
  [Asset insights](/guide/easm/asset-insights/).
- Discovery: [Tune smart discovery](/guide/easm/discovery-settings/),
  [Create custom discovery rules](/guide/easm/custom-discovery-rules/).
- Issues: [Issue type details](/guide/easm/issue-types/), [Issue insights](/guide/easm/issue-insights/).
- Vulnerabilities: [Vulnerability details](/guide/easm/vulnerability-details/),
  [Vulnerability insights](/guide/easm/vulnerability-insights/).
- Technologies: [Review detected technologies](/guide/easm/technologies/),
  [Technology details](/guide/easm/technology-details/),
  [Technology insights](/guide/easm/technology-insights/).

## Do This With the API

- Your assets and their risk signals: [Asset Search](/reference/easm/asset-search/)
