External discovery
External attack surface management (EASM)
Build a reviewable inventory of what an organization exposes to the internet and catch changes before forgotten assets fall outside normal controls.
You cannot protect what the inventory does not know
Migrations, acquisitions, and experiments leave subdomains and services outside the CMDB. External exposure changes between penetration tests.
Discovery
Relate subdomains and public signals to tenant-authorized domains.
Validation
Reduce noise by checking resolution, service, and available evidence.
Prioritization
Group findings so teams investigate meaningful exposure first.
Discovery is not exploitation
LuminaKite uses controlled sources and checks for authorized assets. The purpose is inventory and exposure monitoring, not service exploitation or private-network scanning.
Authorized seeds
Scope begins with domains tied to the tenant.
Minimal evidence
DNS, certificate, and web metadata needed to explain relationships.
Change tracking
Compare assets and findings between runs.
A snapshot versus a changing surface
Manual enumeration provides a useful snapshot. Monitoring repeats discovery and preserves context, while asset owners still validate ownership and remediate exposure.
Frequently asked questions
Does EASM exploit vulnerabilities?
No. The module focuses on controlled external discovery and evidence, not exploitation.
Can it find every asset?
No source is complete. Combining signals and repeating discovery improves coverage but still has limits.
Does it scan private networks?
No. Scope is tied to authorized assets and private destinations are blocked.
Observe your external surface
Start with authorized domains and review assets that need ownership or remediation.
Start freeRelated content
Technical guide
How to find forgotten subdomains
Combine DNS, Certificate Transparency, and internal inventory to find forgotten subdomains, validate ownership, and prioritize exposure.
Technical guide
What is external attack surface management?
Learn how EASM discovers, validates, and monitors internet-exposed assets and how it differs from a point-in-time scan.
Team solution
Exposure monitoring for cybersecurity teams
Connect external surface, brand, identity, DNS, and TLS signals with prioritized findings, cases, and remediation evidence.
Free tool
Basic domain security checker
Run a point-in-time SSL, DNS, SPF, and DMARC review with clear explanations and limits; this is not a vulnerability scanner.