Attack surface management (ASM) tools find the internet-facing assets your organisation owns, including ones nobody listed: forgotten subdomains, test servers, cloud storage and acquired companies’ sites. They then watch those assets for exposures attackers could use. Enterprise options include Cortex Xpanse, Microsoft Defender EASM, CrowdStrike, Tenable and Google’s Mandiant ASM; Intruder and Detectify publish prices for smaller teams.
We checked every product on its vendor’s website on 6 October 2026. Several tools that still appear on other lists, including the previous version of this page, are end-of-sale, withdrawn, or were never ASM tools. They are listed at the end with the reason.
| Tool | Discovery method | Best for | Pricing (checked 6 Oct 2026) |
|---|---|---|---|
| Palo Alto Networks Cortex Xpanse | Outside-in, internet-wide indexing | Large enterprises, M&A due diligence | Quote-based |
| Microsoft Defender EASM | Outside-in from seeds | Azure and Microsoft security customers | US$0.011 per billable asset on Azure; 30-day trial |
| CrowdStrike EASM (Falcon Exposure Management) | Outside-in, continuous internet scanning | CrowdStrike Falcon customers | Quote-based |
| Tenable One Attack Surface Management | Outside-in, feeds Tenable One | Tenable vulnerability management customers | Quote-based |
| Mandiant Attack Surface Management (Google Cloud) | Outside-in with active checks | Teams wanting threat-intel-led validation | Quote-based, by employee count plus base fee |
| Qualys EASM (CSAM) | Inside-out agents plus outside-in | Qualys customers wanting internal and external in one view | Quote-based; 30-day CSAM trial |
| Rapid7 Surface Command | Outside-in scanning plus API integrations | Teams wanting EASM and CAASM together | Quote-based |
| Censys ASM | First-party internet scanning | Teams that value scan data depth | Quote-based; free Censys account for search |
| CyCognito | Seedless attribution plus active testing | Large groups with many subsidiaries | Quote-based, by asset volume; free scan |
| Hadrian | Agentic discovery with exploit validation | Teams wanting validated findings | Quote-based, by asset count |
| Detectify | Domain-based web monitoring | Web-heavy companies, AppSec teams | Platform from €2,500 a year plus per-domain fee |
| Intruder | Cloud sync plus scanning | Small and mid-sized teams | From $239 a month; free plan for 5 targets |

How we chose and evaluated these tools
TIKAJ runs external attack surface monitoring and takedowns for enterprise customers, so we look at ASM tools the way a security team inheriting one would. We kept a product on this list only if it meets all of these:
- Outside-in discovery. It finds internet-facing assets you did not give it, starting from a domain or company name, not just the IP ranges you already know.
- Continuous, not one-off. It re-checks the attack surface on a schedule and tells you what changed.
- Risk context. It ranks findings by exposure and exploitability, not just by CVSS score.
- Still sold today. We checked every vendor’s site on 6 October 2026 and removed products that are end-of-sale, discontinued, or were really vulnerability scanners or third-party risk tools rather than ASM.
Strengths and limitations below come from vendor documentation and our own experience of what customers ask about; we did not run scored lab tests, so we do not publish scores. Pricing is what each vendor shows publicly today. Most enterprise ASM is quote-based.
What to look for in an ASM platform
- Seed-based discovery from a domain, brand or company name, including subsidiaries and acquired companies.
- Coverage beyond IPs: subdomains, certificates, cloud storage, exposed APIs, login pages and forgotten marketing sites.
- Validation: does it confirm that an exposure is real (for example by safe checks against the service), or only flag it?
- Ownership mapping: can it tie an asset to a business unit or owner so the finding reaches someone who can fix it?
- Integrations: ticketing, SIEM and your vulnerability management tool, so ASM findings join the normal remediation queue.
- Pricing unit: per asset, per domain or per organisation. Per-asset pricing can grow quickly as discovery finds more.
ASM vs vulnerability scanning vs CAASM
A vulnerability scanner tests the assets you point it at. External ASM finds the assets you did not know about, then watches them. CAASM does something different again: it merges the asset lists your internal tools already hold. Most organisations need a scanner and ASM; CAASM matters once you have many tools that disagree about what you own. For the basics of the outside view, see what is external attack surface management.
Our product: TIKAJ external attack surface management, powered by Hunto.ai
This is our own product, so it is not ranked in the list. It fits one use case well: organisations, especially in India, that want their external attack surface and brand impersonation watched by one team, with takedowns included.

- Strengths: continuous discovery of domains, subdomains and internet-facing services, alongside monitoring for phishing sites, lookalike domains, fake apps and dark web leaks; takedowns handled by our team.
- Limitations: it covers the external view only and does not inventory internal assets, and it is not a replacement for an authenticated vulnerability scanner. Pricing is not published (annual plans, quote after a demo).
- More: external attack surface management.
The 12 best attack surface management tools
1. Palo Alto Networks Cortex Xpanse
Palo Alto bought Expanse in 2020 and sells it as Cortex Xpanse. It is agentless SaaS that, in Palo Alto’s words, indexes all IPv4 addresses multiple times a day and attributes what it finds to your organisation with machine learning.
- Who it’s for: large enterprises, and buyers assessing an acquisition target’s exposure.
- Strengths: breadth of internet indexing, attribution, optional Active Response playbooks that remediate common exposures automatically.
- Limitations: outside-in only; Active Response is an add-on; no public pricing.
- Pricing: quote-based.
- India relevance: none stated.
2. Microsoft Defender External Attack Surface Management

Defender EASM starts from “seeds” you provide (domains, IP blocks, organisation names) and recursively discovers connected domains, hosts, ASNs and contacts. It feeds Microsoft Security Exposure Management. We found no retirement notice on Microsoft’s product, pricing or documentation pages on 6 October 2026.
- Who it’s for: organisations already on Azure and Microsoft security.
- Strengths: low, published usage-based price; integration with Microsoft’s exposure management; data stored in the Azure region you choose, including Central India.
- Limitations: external view only; needs an Azure subscription; discovery quality depends on good seeds.
- Pricing: the Azure price list shows US$0.011 per billable asset for Defender EASM Standard, with a 30-day free trial on the first resource (pricing page).
- India relevance: available in the Central India Azure region.
3. CrowdStrike EASM (Falcon Exposure Management)
CrowdStrike’s former Falcon Surface is now CrowdStrike EASM within Falcon Exposure Management, which also covers endpoint, cloud and OT exposure.
- Who it’s for: organisations already using CrowdStrike Falcon.
- Strengths: continuous internet scanning, adversary intelligence for prioritisation, one console with endpoint data.
- Limitations: sold as part of the Falcon platform; not on CrowdStrike’s public price list.
- Pricing: quote-based.
- India relevance: none stated.
4. Tenable One Attack Surface Management

Tenable One Attack Surface Management maps internet-facing assets with over 200 metadata fields per asset and feeds them into Tenable One for exposure and attack path analysis.
- Who it’s for: teams already running Tenable vulnerability management.
- Strengths: ASM findings join vulnerability data in one exposure view; large existing asset map.
- Limitations: most value comes with Tenable One; ASM itself is quote-only. Nessus Expert includes basic external discovery scanning for a published $6,790 a year, which suits small teams.
- Pricing: quote-based (buy page).
- India relevance: Tenable lists a Mumbai office.
5. Mandiant Attack Surface Management (Google Cloud)

Google still sells this under the Mandiant name within Google Cloud. It discovers assets from a domain, networks or SaaS accounts and runs “active asset checks” that use Mandiant threat intelligence to test whether an exposure is exploitable.
- Who it’s for: teams that want discovery validated against current attacker behaviour.
- Strengths: active checks, threat intelligence context, role-based access for subsidiaries.
- Limitations: external focus; no published price.
- Pricing: based on employee count plus a base fee; quote via sales (product page).
- India relevance: none stated.
6. Qualys EASM (CyberSecurity Asset Management)
Qualys sells external attack surface management as part of CyberSecurity Asset Management (CSAM), combining its Cloud Agent and passive sensors (inside) with internet discovery (outside), plus CMDB sync.
- Who it’s for: existing Qualys customers who want internal and external inventory together.
- Strengths: inside-out and outside-in in one inventory, end-of-life software tracking, CMDB sync.
- Limitations: tied to the Qualys platform; no public price.
- Pricing: quote-based; 30-day CSAM trial.
- India relevance: Qualys lists an office in Pune.
7. Rapid7 Surface Command
Rapid7 bought Noetic Cyber in 2024 and combined its CAASM technology with Rapid7’s own external scanning in Surface Command, part of Exposure Command.
- Who it’s for: teams that want external discovery and internal asset correlation in one product.
- Strengths: EASM and CAASM together; feeds Rapid7’s exposure and vulnerability tools (InsightVM is still sold, now within Exposure Command).
- Limitations: best value inside Exposure Command; Surface Command price not public.
- Pricing: quote-based; trial or demo.
- India relevance: Rapid7 lists offices in Bengaluru and Pune.
8. Censys ASM
Censys runs its own internet-wide scanning, including non-standard ports, and builds attack surface views on that data with daily updates and cloud connectors.
- Who it’s for: security teams that care about scan depth and data quality.
- Strengths: first-party scan data, cloud connectors, automated seed refresh.
- Limitations: external only; ASM is quote-only.
- Pricing: ASM by quote; a free Censys account and credit packs exist for search (pricing).
- India relevance: none stated.
9. CyCognito
CyCognito discovers assets without seeds by building a graph of an organisation’s business structure, then actively tests them (including DAST) to show which exposures are exploitable.
- Who it’s for: large groups with many subsidiaries and brands.
- Strengths: subsidiary attribution, active testing, free scan of one subsidiary.
- Limitations: external focus; no published price.
- Pricing: quote-based, priced on total asset volume (pricing).
- India relevance: none stated.
10. Hadrian
Hadrian’s Atlas platform uses agent-based automation to discover external assets and validate exploitability with evidence, retesting when assets change.
- Who it’s for: teams overwhelmed by unvalidated findings.
- Strengths: exploit validation with evidence, event-driven retesting, free external scan.
- Limitations: external only; Atlas pricing not published.
- Pricing: quote-based, by total asset count (pricing).
- India relevance: none stated.
11. Detectify
Detectify’s Surface Monitoring watches every subdomain of a domain you add, using research from its community of ethical hackers, including subdomain takeover checks.
- Who it’s for: companies whose attack surface is mostly web applications.
- Strengths: web-focused tests, published platform prices, free Starter tier.
- Limitations: domain and web focused; Surface Monitoring costs extra per domain and that fee is not published.
- Pricing: annual platform fee from €2,500 (Standard), plus per-domain Surface Monitoring (pricing).
- India relevance: none stated.
12. Intruder
Intruder combines scanning (using engines including Tenable, OpenVAS and Nuclei) with cloud account sync, so new assets in AWS, Azure, Google Cloud or Cloudflare are scanned automatically.
- Who it’s for: small and mid-sized teams without a dedicated exposure team.
- Strengths: transparent pricing, free plan, quick setup, cloud sync.
- Limitations: shadow IT and unknown asset discovery are listed under the Enterprise plan; internal scanning starts on Pro.
- Pricing: Cloud from $239 a month ($2,870 a year), Pro $399 a month, free plan for 5 targets, 14-day trial (pricing).
- India relevance: none stated.
Tools we removed, and why
| Tool on the old list | Status on 6 Oct 2026 | Why it is not listed |
|---|---|---|
| Cisco Vulnerability Management (Kenna) | End of sale 10 March 2026; support ends 30 June 2028 | Cannot be bought |
| Cisco Attack Surface Management | End of life; support ended 30 November 2025 | Discontinued |
| IBM Randori Recon | Divested to Palo Alto Networks in 2024 and withdrawn from market | Cannot be bought |
| ProcessUnity (CyberGRX) | Now Global Risk Exchange | Third-party risk management, not ASM |
| UpGuard | Live | Security ratings and vendor risk first; outside-in monitoring without ASM workflows |
| Axonius | Live | CAASM (internal inventory through integrations), covered in our CAASM guide |
| Rapid7 InsightVM | Live, now in Exposure Command | Vulnerability scanner; Rapid7’s ASM product is Surface Command, listed above |

FAQ
What is an attack surface management tool?
An attack surface management tool finds the internet-facing assets an organisation owns, including ones its IT team does not know about, and monitors them for exposures. That covers domains, subdomains, IP addresses, cloud services, login pages and APIs. Unlike a vulnerability scanner, it starts from a domain or company name and discovers what to watch on its own.
Which attack surface management tool is best?
It depends on what you already run. Microsoft, CrowdStrike, Tenable, Qualys and Rapid7 customers usually get most value from their vendor’s ASM because findings join existing workflows. Cortex Xpanse, CyCognito and Censys suit large estates and subsidiaries. Intruder and Detectify publish prices and suit smaller teams. Run a trial against your own domains before choosing.
How much do attack surface management tools cost?
Most enterprise ASM is quote-based and priced by asset count, employee count or domain. Published prices we found on 6 October 2026: Microsoft Defender EASM at US$0.011 per billable asset on Azure, Intruder from $239 a month, and Detectify from €2,500 a year plus a per-domain fee. Free scans or trials are offered by Intruder, CyCognito, Hadrian and Qualys.
What is the difference between EASM and CAASM?
EASM looks from the outside in: it scans the internet for assets that belong to you, including unknown ones. CAASM looks from the inside: it pulls asset records from tools you already run, such as EDR, scanners and cloud consoles, and merges them to find gaps. EASM finds what you did not know about; CAASM reconciles what your tools already know.
