Mandiant Attack Surface Management (ASM) shows your organization through the eyes of the adversary: it discovers and analyzes your internet assets and continually monitors the external ecosystem for exploitable exposures.
What Is Mandiant Attack Surface Management?
Mandiant Attack Surface Management offers the adversary’s view of your organization’s attack surface. Starting with simple information about the organization — such as a domain, known networks, or SaaS accounts — it collects asset and exposure information like an attacker would.
Google Cloud defines external attack surface management as the automated and continuous discovery of internet-facing assets and cloud resources, assessed for technology relationships and the identification of vulnerabilities, misconfigurations, or exposures.
Core Features
- Continuous monitoring: Control how often asset discovery and analysis run with daily, weekly, or on-demand scans
- Technology and service identification: Inventory of applications and services running in the external ecosystem
- Outcome-based asset discovery: Choose the discovery workflow based on specific outcomes or use cases
- Active asset checks: Benign payloads and scripts designed from Mandiant IOCs and frontline intelligence validate whether an asset is susceptible to exploitation
- Infrastructure integrations: Connections to cloud and DNS providers
- Role-based access controls (RBAC): Independent management per organization with centralized visibility
Typical Use Cases
Assess High-Velocity Exploit Impact
Active checks show when and where external assets are impacted, allowing security teams to prioritize remediation.
Identify Shadow IT
Continuous monitoring surfaces unmanaged or unknown assets. Security teams receive daily summaries of new assets and technologies added.
Multicloud Asset Discovery
A centralized view of hybrid and multicloud environments supports the assessment of cloud-hosted external assets for exposures.
Due Diligence and Subsidiary Oversight
Before and after a transaction, you gain visibility into the acquisition’s unknown systems. For subsidiaries, role-based access controls let each organization independently monitor and manage its own attack surface scope while centralizing visibility for the parent organization.
Benefits
- Adversary perspective: Assets are discovered the way an attacker would find them
- Intelligence-informed checks: Active and passive checks based on Mandiant IOCs and frontline intelligence
- Low barrier to entry: Onboarding with a domain, IP address, URL, or netblock
- Fits existing tooling: Integrations and API access for SIEM, SOAR, and ticketing systems
Integration with innFactory
As a certified Google Cloud partner, innFactory supports you with Mandiant Attack Surface Management: onboarding your asset scope, prioritizing findings, and connecting results to your existing SIEM and ticketing processes.
Typical Use Cases
Technical Specifications
Frequently Asked Questions
What is attack surface management?
Google Cloud describes attack surface management as an approach to cyber defense that assesses and monitors external and internal assets for vulnerabilities as well as risks that can potentially impact an organization. An attack surface management solution continuously discovers and assesses an organization's assets for vulnerabilities, misconfigurations, and exposures.
What is the difference between an attack surface and an attack vector?
According to Google Cloud, an attack vector is an exploitable asset in the attack surface. An attack vector can be used by a threat actor for initial compromise.
What is required to get started?
Google Cloud states that onboarding requires only a domain, IP address, URL, or netblock.
Which integrations are supported?
Mandiant Attack Surface Management supports integrations with Chronicle Security Operations, Cortex XSOAR, Splunk Enterprise, and ServiceNow. Customers also often use the API to send data from Mandiant Attack Surface Management to their preferred SIEM, SOAR, or ticketing system.
How does pricing work?
Google Cloud states that Mandiant Attack Surface Management pricing is based on the number of employees at your organization and that all paid subscriptions include a base fee. For a concrete quote, Google refers to sales.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.
