Skip to main content
Cloud / Google Cloud / Products / Mandiant Attack Surface Management - Monitor the External Attack Surface

Mandiant Attack Surface Management - Monitor the External Attack Surface

Mandiant Attack Surface Management discovers and analyzes internet assets and continually monitors the external ecosystem for exploitable exposures.

Security
Pricing Model Based on the number of employees at your organization; all paid subscriptions include a base fee (price on request)
Availability SaaS offering from Google Cloud Security
Data Sovereignty Per provider / see official documentation
Reliability SLA per provider / see official documentation SLA

Mandiant Attack Surface Management (ASM) shows your organization through the eyes of the adversary: it discovers and analyzes your internet assets and continually monitors the external ecosystem for exploitable exposures.

What Is Mandiant Attack Surface Management?

Mandiant Attack Surface Management offers the adversary’s view of your organization’s attack surface. Starting with simple information about the organization — such as a domain, known networks, or SaaS accounts — it collects asset and exposure information like an attacker would.

Google Cloud defines external attack surface management as the automated and continuous discovery of internet-facing assets and cloud resources, assessed for technology relationships and the identification of vulnerabilities, misconfigurations, or exposures.

Core Features

  • Continuous monitoring: Control how often asset discovery and analysis run with daily, weekly, or on-demand scans
  • Technology and service identification: Inventory of applications and services running in the external ecosystem
  • Outcome-based asset discovery: Choose the discovery workflow based on specific outcomes or use cases
  • Active asset checks: Benign payloads and scripts designed from Mandiant IOCs and frontline intelligence validate whether an asset is susceptible to exploitation
  • Infrastructure integrations: Connections to cloud and DNS providers
  • Role-based access controls (RBAC): Independent management per organization with centralized visibility

Typical Use Cases

Assess High-Velocity Exploit Impact

Active checks show when and where external assets are impacted, allowing security teams to prioritize remediation.

Identify Shadow IT

Continuous monitoring surfaces unmanaged or unknown assets. Security teams receive daily summaries of new assets and technologies added.

Multicloud Asset Discovery

A centralized view of hybrid and multicloud environments supports the assessment of cloud-hosted external assets for exposures.

Due Diligence and Subsidiary Oversight

Before and after a transaction, you gain visibility into the acquisition’s unknown systems. For subsidiaries, role-based access controls let each organization independently monitor and manage its own attack surface scope while centralizing visibility for the parent organization.

Benefits

  • Adversary perspective: Assets are discovered the way an attacker would find them
  • Intelligence-informed checks: Active and passive checks based on Mandiant IOCs and frontline intelligence
  • Low barrier to entry: Onboarding with a domain, IP address, URL, or netblock
  • Fits existing tooling: Integrations and API access for SIEM, SOAR, and ticketing systems

Integration with innFactory

As a certified Google Cloud partner, innFactory supports you with Mandiant Attack Surface Management: onboarding your asset scope, prioritizing findings, and connecting results to your existing SIEM and ticketing processes.

Typical Use Cases

Continuous external asset discovery
Shadow IT identification
Mergers and acquisitions due diligence
Subsidiary monitoring

Technical Specifications

Checks Active and passive checks based on Mandiant IOCs and frontline intelligence
Integrations Chronicle Security Operations, Cortex XSOAR, Splunk Enterprise, ServiceNow, and API access
Onboarding A domain, IP address, URL, or netblock is enough to get started
Scan frequency Daily, weekly, or on-demand scans

Frequently Asked Questions

What is attack surface management?

Google Cloud describes attack surface management as an approach to cyber defense that assesses and monitors external and internal assets for vulnerabilities as well as risks that can potentially impact an organization. An attack surface management solution continuously discovers and assesses an organization's assets for vulnerabilities, misconfigurations, and exposures.

What is the difference between an attack surface and an attack vector?

According to Google Cloud, an attack vector is an exploitable asset in the attack surface. An attack vector can be used by a threat actor for initial compromise.

What is required to get started?

Google Cloud states that onboarding requires only a domain, IP address, URL, or netblock.

Which integrations are supported?

Mandiant Attack Surface Management supports integrations with Chronicle Security Operations, Cortex XSOAR, Splunk Enterprise, and ServiceNow. Customers also often use the API to send data from Mandiant Attack Surface Management to their preferred SIEM, SOAR, or ticketing system.

How does pricing work?

Google Cloud states that Mandiant Attack Surface Management pricing is based on the number of employees at your organization and that all paid subscriptions include a base fee. For a concrete quote, Google refers to sales.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.

Google Cloud Partner

innFactory is a certified Google Cloud Partner. We provide expert consulting, implementation, and managed services.

Google Cloud Partner

Ready to start with Mandiant Attack Surface Management - Monitor the External Attack Surface?

Our certified Google Cloud experts help you with architecture, integration, and optimization.

Schedule Consultation