ASM Integrations
ASM integrations enable automatic discovery of APIs, services, and applications across cloud infrastructure and source code repositories. Scheduled pulls refresh the discovered Assets in Escape's ASM.
Integration Categories¶
Cloud Infrastructure¶
Cloud provider integrations allow APIs and services deployed on major platforms to be discovered automatically:
- AWS - Cross-account IAM role (AssumeRole, recommended)
- AWS Account (Legacy) - IAM access keys
- Azure - Azure API Management instances
- GCP - API Gateway, serverless endpoints, DNS, and load balancer frontends
- Cloudflare - DNS zones and API Gateway schemas
- Akamai - Edge configurations and API definitions
- Kubernetes - Services, Ingresses, and Istio resources
Source Code Repositories¶
Repository integrations enable API discovery from code by scanning for OpenAPI specifications, GraphQL schemas, and other API definition files:
- GitHub - Organization repositories and API schemas
- GitLab - Group and project repositories
- Bitbucket - Workspace repositories
API Documentation Platforms¶
- Postman - Collections and API definitions
Security Platforms¶
- Wiz - Network exposures and cloud resources with bi-directional enrichment (assets from Wiz, issues back to Wiz)
Domains and Custom Sources¶
- Top Level Domains: Domain discovery and implicit scope allowlist rules
- Custom Integration: Custom discovery sources configured with the Escape team
How Discovery Works¶
- Connection - Credentials are configured for the target platform
- Enumeration - Resources are discovered through platform APIs
- Classification - Discovered endpoints are classified as Assets in Escape's ASM
- Scheduled Sync - Escape periodically refreshes discovered Assets while ASM scanning is enabled
Private Networks¶
For internal infrastructure not accessible from the public internet, a Private Location can be configured to enable secure connectivity between Escape and private resources.