About Attack Surface Management (ASM)
Last updated: July 24, 2026
Overview
Attack Surface Management (ASM) continuously discovers everything you have exposed to the internet — domains, subdomains, servers, open ports, web apps, certificates — and checks it for security issues, the same way an outside attacker would. It gives you a live inventory of your external footprint and flags weaknesses before someone else finds them.
How scanning works
Scanning runs from Oneleet's infrastructure against the domains you tell us to monitor, in two stages:
Discovery — We map your external footprint by finding subdomains and hosts, scanning for open ports and the services on them, probing web apps to detect technologies and configuration, collecting TLS/SSL certificates and DNS records, and cataloging the JavaScript your sites load. This builds your asset inventory.
Vulnerability scanning — We test the web services you've chosen to monitor against a large, continuously updated library of checks: known CVEs, default/weak logins, exposed admin panels, misconfigurations, data exposures, subdomain takeovers, and more. Anything we find becomes a finding in your dashboard.
Both stages run automatically on a recurring schedule, and you can also trigger a scan on demand.
Scanning is passive and non-intrusive — designed to observe, not attack. Disruptive and denial-of-service style checks are excluded.
Recognizing and allowlisting our scans
Every request our scanner makes carries a single identifying HTTP header:
X-Oneleet-Scan: <your unique scan token>
The token is unique to your organization and is shown in your ASM scanner settings.
If you run a WAF, firewall, or rate limiter, allowlist requests carrying this header (with your token) so scans aren't blocked or throttled — this gives the most accurate results.
Our scanner does not use a fixed User-Agent, so allowlist by the X-Oneleet-Scan header + token, not by User-Agent.
Choosing what gets scanned
Add/remove domains (targets): Scanning only runs against domains you've designated as targets. The domain must first be a verified root domain; removing it stops future scans from using it.
Scanner settings: Turn automatic scanning on/off, adjust how often discovery and vulnerability scans run, and choose whether newly discovered services are monitored automatically or require your review first.
Monitor vs. exclude: As assets are discovered, you decide — Monitored (actively scanned) or Excluded (kept for visibility, not scanned). Review new items in bulk or change any single asset/service anytime.
Ignoring assets and findings
1. Exclude an asset or service — stays in your inventory but drops out of scanning.
2. Dismiss a finding — mark it False positive, Accepted risk, or Resolved (with notes and an owner). False-positive and accepted-risk findings are not re-tested, so they won't keep reappearing.
3. Ignore an entire issue type — suppress all current and future findings of a given check with a reason; reversible.