Skip to content

Attack Surface (ASM)

Audience: Client users whose organization holds an External Network license (the same license that covers external pentests also enables Attack Surface monitoring) · Where: Attack Surface in the sidebar (/attack-surface).

Licensed feature

If your org doesn't have the External Network license, the Attack Surface item won't appear in your nav. The same license that covers external pentests enables Attack Surface monitoring — see Licenses & Credits.

Overview

Attack Surface Management (ASM) is Canima's continuous, outside-in monitoring of everything your organization exposes to the internet — domains, subdomains, IPs, services, and the risks attached to them. Unlike a point-in-time assessment, ASM runs on a schedule and alerts you when things change (a new host appears, a DNS record moves, a credential leaks).

The tabs at a glance

ASM is organized into ten tabs across the top:

  •   Dashboard


    Your external-risk overview — KPI tiles, severity distribution, monitors, and recent alerts.

  •   Discovery


    A visual topology / tree map of how your external estate connects.

  •   Monitoring


    A live overview of what ASM is currently watching.

  •   Alerts


    The change feed — acknowledge alerts to keep it meaningful.

  •   Breaches


    Leaked credentials for your domains found in breaches and dark-web dumps.

  •   Phishing Domains


    Look-alike / typo-squat domains flagged as phishing candidates.

  •   Vulnerabilities


    Externally-detected vulnerabilities in a filterable, exportable table.

  •   Assets


    The ASM-discovered external asset inventory.

  •   History


    The Activity Log of ASM events plus an Average Time to Fix trend.

  •   ASM Config


    Defines what ASM monitors — scope, blacklists, and breach settings.

Dashboard

Your external-risk overview. KPI tiles show Attack Surface Assets, Attack Surface Vulnerabilities, Unacknowledged Alerts, and an ASM Security Score (with trend). Below:

  • Vulnerability Severity Distribution and Risk & Compliance (aging findings by SLA threshold, same idea as the main Dashboard).
  • Monitors — the scheduled scanners and their cadence: Vulnerability Scanning, Google Dorks, Phishing Domains, Breach Data, CVE Alerts, Port Scanning, DNS — each showing when it runs and whether it's actively Monitoring.
  • Asset Growth Trend, Top Risk Assets, and Recent Alerts.

The tabs in detail

A visual topology / tree map of your external estate: how domains, subdomains, and IP ranges connect. Toggle Topology vs Tree, search assets, fit to view, and export the graph as an image. When new assets turn up, a banner counts those awaiting acceptance into monitoring and a Review worklist lets you accept them.

A live overview of what ASM is watching: tiles for Monitored assets, Awaiting approval, and Services discovered, the monitor-coverage list, a feed of recently discovered services, and any sensitive-content (Google-dork) findings.

The change feed: DNS-record changes, new/changed device fingerprints, newly exposed services, etc. Each alert explains what changed and why it matters. Filter by search, severity, type, and acknowledged state, acknowledge alerts to clear them from the unacknowledged count, or mark all as acknowledged.

The Breaches & Dark Web view: credentials belonging to your domains found in known third-party breaches and dark-web dumps (see Breach Monitoring under ASM Config for how this is filtered). Tiles highlight Total Breaches, Employee Passwords Exposed, and the Most Recent Breach, and you can filter by classification, source, and password status.

Look-alike/typo-squat domains flagged as potential phishing candidates against your watched TLDs, filterable by source (DNS-confirmed vs threat-intel).

Externally-detected vulnerabilities in a filterable, exportable table (severity/status/category/search), with a detail page per issue.

The ASM-discovered external asset inventory (feeds the main Asset Library); expand a row to accept, stop, or ignore monitoring for that asset.

The Activity Log of ASM events (scans, asset/service changes, new vulnerabilities, breach-data updates) plus an Average Time to Fix trend.

ASM Config

Defines what ASM monitors. Under Scope Configuration you set the Top-Level Domains (TLDs) to watch (required), plus optional IP Addresses and CIDR Ranges. Blacklists exclude domains, subdomains, IPs, or CIDR ranges from monitoring. Breach Monitoring controls how leaked-credential intel is ingested — by default only credentials on your own domains appear; toggle Include consumer credentials to also surface personal-email breaches (useful when executives reuse personal accounts). Click Update Configuration to save.

Scope changes apply going forward only

Removing a TLD, IP, or CIDR does not delete already-discovered assets — they keep being monitored. To stop monitoring one, deactivate it from the Asset Library.

Tips

Working ASM effectively

  • Start on the Dashboard, then work the Alerts tab regularly — acknowledging alerts keeps the feed meaningful so real changes stand out.
  • Set your TLDs accurately in ASM Config — everything ASM discovers flows from that scope.
  • Breaches and Phishing Domains are early-warning signals; act on them before they turn into an incident.
  • ASM does not produce a formal PDF report; its findings live in these dashboards. For a formal deliverable, run an assessment.

Related: Asset Library · Home Dashboard · Findings · Licenses & Credits