Attack Surface Management

Beginner

Learn Attack Surface Management (ASM) as an operational discipline, not a scanner report. You will discover an organisation's external footprint through DNS, WHOIS, certificate transparency and cloud storage, verify what a scan actually proves versus what it merely returns, enumerate subdomains passively and actively, spot subdomain takeovers and shadow IT before an attacker does, and turn a raw asset list into a prioritised, owner-assigned remediation queue. The curriculum was reviewed against a detailed sample of roughly 54 EASM and exposure-management job descriptions inside a wider 1,000 job-market scan, then checked against real reconnaissance and exposure workflows. Four sections, 63 lessons, and four case-based missions.

By CTI Academy Team67 steps4 sections~13 hoursCertificate

Curriculum

67 steps across 4 sections. Sections unlock in order as you complete them.

10 more steps behind a free account

Free account

Ready to start Attack Surface Management?

Create a free account to open the remaining 10 steps, track every one you finish and earn your certificate.

  • Free to start
  • Progress saved on every step
  • Certificate on completion
Sign up with email

About this path

Most attack surface work does not fail at the scanning step. It fails after: a tool returns a thousand assets and nobody can say which ones are actually owned by the company, which are actually reachable, and which single finding should move first. This path starts with that gap, not with the scanner, but with the question a scanner cannot answer on its own: whose is this, is it really exposed, and does anyone need to act on it today.

The curriculum was reviewed against a detailed sample of roughly 54 EASM and exposure-management job descriptions drawn from a wider 1,000 job-market scan. Exposure metrics and reporting, remediation workflow, and vulnerability validation or prioritisation appeared in every single listing sampled. Roughly three in four also asked for asset discovery, DNS/TLS/web fundamentals, EASM tooling, recon and enumeration, and shadow IT or asset attribution. Those market signals were used as a scope check, not as a keyword list, and the lessons stay grounded in what a real discovery pipeline has to prove at each step.

The first section defines what an attack surface actually is versus a CAASM inventory, then builds the DNS and email-authentication foundation, A/AAAA/CNAME/MX/TXT records, SPF, DKIM and DMARC, that almost everything downstream reads off of. The second section moves into ownership intelligence: WHOIS and RDAP, BGP/ASN correlation, reverse WHOIS pivoting on an email or organisation name, and favicon hashing and archived-page mining for assets that no longer advertise themselves. The third section is the largest: passive and active subdomain enumeration, certificate transparency logs, cloud storage discovery across AWS, Azure and GCP, indirect discovery through JavaScript and CSP analysis, and subdomain takeover, recognising a dangling CNAME before someone else claims it. The fourth section closes on verification: port scanning and service fingerprinting, and the harder question of what an "open" port actually proves about the service really answering it.

It assumes the same baseline as Open Source Intelligence (OSINT): comfort with a browser, files, and reading a technical record without a tool doing the reasoning for you. If DNS records and WHOIS lookups are new territory, Open Source Intelligence (OSINT) covers research fundamentals this path builds on, though it is not a hard requirement. You do not need an existing bug bounty or pentest background; the missions are built around public, disposable targets and archived data, not systems you would need special access to reach.

What you will learn

  • Tell an inventory from an attack surface. Separate what a CAASM tool lists from what is actually reachable, owned and exposed right now, and explain why EASM and CAASM answer different questions.
  • Read DNS and email authentication as evidence. Pull A/AAAA/CNAME/MX/TXT records, SPF, DKIM, DMARC and modern disclosure mechanisms apart, and use them to map real infrastructure rather than a resolved IP.
  • Trace ownership across a domain portfolio. Use WHOIS/RDAP, BGP/ASN correlation and reverse WHOIS pivots to connect scattered domains back to one organisation, including the pre-GDPR record layer.
  • Enumerate subdomains the way a real discovery pipeline does. Combine certificate transparency, search engine dorking, passive tools such as Subfinder, Amass, Shodan and Censys, and active brute-force or permutation scanning, and know when each is the right one to reach for.
  • Recognise a subdomain takeover before an attacker does. Spot a dangling CNAME or orphaned NS delegation and its service-specific fingerprint, and explain what makes it actually exploitable rather than just stale.
  • Find what indirect discovery surfaces. Pull assets out of JavaScript files, CSP headers and cloud storage buckets across AWS, Azure and GCP that active scanning alone would miss.
  • Verify a service instead of trusting the scan. Explain what an "open" port actually proves, make a service prove its own identity, and read the network layer and TLS/HTTP evidence rather than the banner alone.
  • Turn an asset list into a remediation queue. Prioritise findings the way the market data shows employers actually grade this work: validated risk and a named owner, not a raw count of open findings.

Who this path is for

  • Security analysts and SOC staff who want to move into exposure management or vulnerability management without starting from a generic pentesting course.
  • Students and career changers who have finished Open Source Intelligence (OSINT) and want to apply the same research discipline to an organisation's own infrastructure.
  • Bug bounty hunters and pentesters who already run the tools but want the ownership, verification and remediation reasoning that turns a finding into something a company actually fixes.
  • Security leads standing up an exposure management or EASM program who want to know what a good discovery-to-remediation workflow looks like before buying a platform.

Guides for this path

  • Attack Surface Management (ASM) GuideAttack Surface Management (ASM) is the continuous process of discovering, cataloging, and securing all internet-facing assets that an attacker could target. Unlike traditional vulnerability management that focuses on known assets, ASM starts from the attacker's perspective, identifying assets your organization may not even realize are exposed.

Frequently asked questions

Open Source Intelligence (OSINT) is not required but is a good warm-up: this path assumes the same comfort reading a technical record, a DNS answer, a WHOIS entry, a certificate, without a tool doing the interpretation for you. Nothing else is assumed.

No. Every lesson closes with an exercise, and the missions are built around public, disposable domains and archived data, not systems that require special access.

No. Finding a subdomain or an open port is the easy half. This path spends more time on ownership (whose is it), verification (does the scan output actually hold up) and remediation (who owns the fix and how you confirm it closed) than on exploitation.

You will use Shodan, Censys, Subfinder, Amass and standard DNS/WHOIS tooling because the market data shows these are what the role actually uses, but the reasoning, what to trust, what to verify, how to prioritise, holds regardless of which platform an employer standardises on.

Cases worked through real-looking artifacts, a DNS record set, a WHOIS record, an nmap scan output, where you have to reach a specific, defensible conclusion rather than pick from a list.

The curriculum was reviewed against a detailed sample of roughly 54 EASM and exposure-management job descriptions inside a wider 1,000 job-market scan. Exposure metrics and reporting, remediation workflow, and vulnerability validation or prioritisation appeared in every listing sampled; asset discovery, DNS/TLS fundamentals, EASM tooling, recon and enumeration, and shadow IT or asset attribution appeared in roughly three of every four. The full data, including the entry-to-advanced skill shift and salary ranges, is published as "The CTI & EASM Job Market in 2026: What 1,000 Job Postings Actually Show" on the CTI Academy blog. Those signals were used to check coverage and priority, not to write lessons around keywords.