How Attack Surface Monitoring works
Last updated: July 24, 2026
We provide a single, continuously updated source of truth for your entire external attack surface. We find what an attacker sees and validate the risks so you can focus on fixing what matters.
Inventory discovery
We begin by running Enumeration Scans on your target domains. This process maps your footprint by identifying all related Assets, like IPs and certificates, and the live Services, like app.oneleet.com:443, that we can test.
Issue detection
Once we identify services, our Vulnerability Scans automatically test them for known security issues. When an Issue is identified in a Service, we create a Finding for you to review.
Understanding results
ASM results use four core concepts:
Asset - The individual components discovered on your network, such as an IP address, domain, or certificate.
Service - A specific, scannable endpoint where vulnerabilities can be found, like
app.oneleet.com:443.Issue - The blueprint for a vulnerability, such as "SQL Injection" or "Outdated Web Server."
Finding - A specific issue detected on a specific service. This is the actionable result that you need to resolve.
Workflow
Once findings appear, we recommend this workflow:
Prioritize by triaging Critical and High-severity findings to focus on the most impactful issues.
Resolve by assigning owners, creating tickets, and validating fixes with automated re-testing.
Monitor for issues and regressions by enabling notifications.