Authorize scope
Confirm customer-owned domains, IPs, CIDRs, exclusions, timing, safety prerequisites, and the approved discovery method.
External Attack Surface Management
Threat Foundry EASM combines authorized discovery or imported evidence with asset, service, KEV, identity, business, ownership, due-date, remediation, change, and retest context.
Confirm customer-owned domains, IPs, CIDRs, exclusions, timing, safety prerequisites, and the approved discovery method.
Use saved scans, approved discovery plans, scanner integrations, or bounded files to build the evidence-backed exposure inventory.
Connect services, KEVs, EPSS, identity signals, business criticality, owners, recurrence, and evidence confidence.
Assign owners and due dates, track finding state, suppression, tickets, cases, and the documented response.
Run focused authorized retests, preserve recurrence and delta history, and publish the approved customer exposure view.
Discovery boundary
Active discovery runs only against explicitly approved customer-owned scope with current runner and safety prerequisites. The service does not promise exhaustive discovery, exploitability, or proof of compromise.
Discuss the operating boundaryCustomer outcome
The service retains the agreed scope, review state, ownership, limitations, and follow-through instead of ending at an isolated deliverable.
Approved assets, observed services, posture evidence, changes, and current context.
Risk, owner, due date, workflow state, suppression rationale, and next action together.
Focused verification, recurrence history, executive summaries, exports, and customer-safe publication.
Start with the workflow
Bring the approved discovery scope, current asset sources, ownership model, remediation process, and reporting needs. We will map the first exposure outcome.