Skip to content

Getting Started With Escape's Attack-Surface Management (ASM)

Escape ASM discovers external and internal Assets from domains, cloud integrations, and source-code integrations, then runs surface security tests on monitored Assets.

The inventory is filterable, sortable, searchable, and groupable by asset type, class, status, and other attributes.

ASM + Business Logic Aware DAST: Coverage Meets Depth

ASM discovers Assets and runs surface tests. Business Logic Aware DAST adds authenticated testing for REST APIs, GraphQL APIs, and web applications. Use the inventory to choose which supported Assets to test in depth.

How It Works

  1. Input: Supply a domain such as example.com and any optional read-only integrations.
  2. Discovery: Escape discovers external and internal Assets from your domains and connected integrations.
  3. Surface Security Testing: For monitored Assets, ASM checks open ports, headers, TLS configuration, and unauthenticated endpoints to identify misconfigurations and exposures.
  4. Deep Testing (Optional): Select a REST API, GraphQL API, or web application for Business Logic Aware DAST.
  5. Workflows & Ticketing: Findings flow to your SIEM, ticketing, or chat tool through Workflows using Export and Notify actions.

A simplified version of how Escape ASM technically works

Discovery Sources and Configuration

Escape ASM discovers APIs and services through infrastructure integrations, network scanning, application crawling, and code analysis. Discovery uses provider APIs, scan responses, schemas, and public reconnaissance sources. It operates without installing traffic-capture agents in your applications or intercepting live user traffic.

Discovery methods:

  • Infrastructure integrations: Direct integration with cloud providers, orchestration platforms, and service registries
  • Network scanning: Active scanning to identify exposed services, open ports, and API endpoints
  • Application crawling: Analyzing responses, following links, and mapping accessible endpoints
  • Code and schema analysis: Parsing OpenAPI specifications, Swagger documentation, and introspection endpoints
  • Reconnaissance techniques: DNS enumeration, certificate transparency logs, and public data sources

Configure integrations with read-only access to the resources you want to discover. For active scans, use Network Configuration to set request rates that fit your infrastructure's capacity.

Discovery coverage:

ASM identifies services and APIs through infrastructure integrations and network scanning. Enrich endpoint mapping with routes, methods, and parameters through:

  • Exposing OpenAPI or Swagger specifications at standard paths
  • Enabling schema introspection for GraphQL endpoints
  • Configuring authentication for ASM to crawl protected endpoints
  • Integrating with CI/CD pipelines to provide schema definitions

Supported Application Assets

Category Description ASM Business Logic Aware DAST
Hosts DNS records, IPv4, IPv6 Discovery and surface testing No
REST and GraphQL APIs HTTP API services Discovery, endpoint extraction, surface testing Authenticated API security testing
Other API Services gRPC, WebSocket, SOAP, MCP Discovery and classification No
Web Apps MPAs, SPAs, frontend deployments Discovery, fingerprinting, surface testing Browser-driven security testing
Repositories GitHub, GitLab, and Bitbucket repositories Schema extraction, code owners, dependency analysis No

Fingerprinted Asset Characteristics

  • Reachability: Public or Private Locations that can reach the Asset
  • Status: Monitored, Out of Scope, False Positive, Deprecated, Third Party
  • Environment: Production, Staging, or Development
  • Technology Stack: Frameworks & runtimes
  • Cloud Hosting: AWS, Azure, GCP, OVH, Akamai
  • Edge / Firewall: Cloudflare, AWS ELB, Azure Front Door
  • Authentication Technology: Keycloak, Auth0, Cognito, Azure AD, AWS IAM; service access is Public or Authenticated when identified
  • Code Owners: Pulled from connected SCM to speed assignment

ASM Scanners

Escape ASM operates as a collection of specialized scanners that discover, validate, and monitor specific asset types across your environment. Here's how the ASM execution process works:

1. Asset Input and Validation

Each ASM scanner processes a single asset, either manually created or discovered automatically during the initial discovery phase. Upon receiving the asset, the scanner first performs a validation step. This validation checks the asset's status, reachability, and basic configurations, ensuring that the asset is legitimate and operational.

2. Asset Fingerprinting

Once an asset is validated, the scanner fingerprints metadata such as its environment, technology stack, cloud hosting, and authentication methods. This fingerprinting phase ensures that each asset is uniquely identified and categorized, which is critical for subsequent analysis and monitoring.

3. Asset Discovery and Exploration

Following validation and fingerprinting, the scanner enters the discovery phase, exploring the asset's connections and dependencies. This phase identifies related assets across the environment. For example, discovering a web application can reveal associated API services, databases, or other interconnected components. This cascading discovery adds related Assets to your inventory as they're found.

ASM Execution

Once an asset is discovered, Escape ASM handles it differently depending on whether it's new or existing:

  • New assets are scanned immediately to map the organization’s attack surface and identify any immediate risks. The scan also triggers the discovery of related or dependent assets, creating a cascading exploration across the environment.
  • Existing assets are scanned periodically at random intervals each week. These re-scans detect misconfigurations, environmental changes, deprecate legacy assets, and identify any new assets in the organization. This ensures that the attack surface remains continuously updated.

Discover Internet-Exposed Applications

Start With a Single Domain Name

The primary input required is your company's Domain name. This domain represents the minimal scope of discovery for the ASM process.

Escape employs advanced subdomain enumeration techniques combined with intelligent brute-force methods and crawling (including API Discovery from Frontend Code) to visit and inspect a comprehensive range of URLs. Each URL undergoes thorough fingerprinting analysis.

Escape fingerprints Assets using signals such as response headers, body content, and dependency manifests. See Technology Detection.

Add Additional Domains and Subdomains

Start with one domain or add several at once in ASM → Scope Management → Configure Scope by separating them with commas.

Scanning Internal Networks

Escape supports Private Locations: lightweight connectors that create a secure reverse SOCKS5 tunnel from your on-prem or VPC environment to Escape’s cloud.

Deploying a Private Location lets the ASM detect and fingerprint internal Assets that sit behind firewalls or VPNs, using the same mechanism available for Internal Application testing in Escape Business Logic Aware DAST.

For setup instructions, see the Private Location Documentation.

Private Location documentation