Defender External Attack Surface Management
Continuous discovery of your internet-facing attack surface from the outside in.
Microsoft Defender External Attack Surface Management (EASM) continuously discovers and maps your internet-facing assets from an attacker’s perspective — including the unknown, unmanaged, and shadow-IT assets that create exposure. It surfaces exposed services, vulnerabilities, and misconfigurations so you can reduce your external attack surface. Faltrox operates it as managed attack surface management.
Overview
What Defender External Attack Surface Management is
You cannot protect what you do not know you have, and internet-facing attack surfaces change constantly as assets are spun up, forgotten, or acquired. Microsoft Defender EASM continuously discovers and maps your external attack surface from the outside in — seeing what an attacker sees.
It discovers and attributes internet-facing assets (domains, hosts, IPs, certificates, cloud resources) to your organisation, including unknown, unmanaged, and shadow-IT assets, and surfaces their exposed services, vulnerabilities, and misconfigurations. It builds a continuously updated inventory of your external footprint and prioritises the exposures that matter, integrating with Defender and Sentinel. Faltrox operates it — discovering the attack surface, triaging exposures, and driving remediation as managed attack surface management.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Internet-Facing Assets
Discovers domains, hosts, IPs, certificates, and cloud resources exposed to the internet.
Unknown & Shadow IT
Finds unknown, unmanaged, and shadow-IT assets you did not know were exposed.
Exposed Services
Surfaces exposed services, ports, and misconfigurations on external assets.
External Vulnerabilities
Identifies vulnerabilities on internet-facing assets attackers can reach.
Changing Attack Surface
Continuously updates as the external footprint changes.
Exposure Prioritisation
Prioritises the exposures that pose real risk.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Discover
It continuously scans the internet to discover your external assets from an attacker’s perspective.
- 02
Attribute
It attributes discovered assets to your organisation, including unknown and unmanaged ones.
- 03
Assess
It surfaces exposed services, vulnerabilities, and misconfigurations on those assets.
- 04
Prioritise
It prioritises the exposures that pose real risk, integrated with Defender and Sentinel.
- 05
Operate
Faltrox discovers the attack surface, triages exposures, and drives remediation.
Capabilities
Key capabilities
Continuous External Discovery
Continuously discovers internet-facing assets from an attacker’s perspective.
Unknown-Asset Attribution
Finds and attributes unknown, unmanaged, and shadow-IT assets to your organisation.
Exposure Assessment
Surfaces exposed services, ports, vulnerabilities, and misconfigurations.
External Footprint Inventory
Builds a continuously updated inventory of your external attack surface.
Change Tracking
Tracks changes to the external footprint as assets appear and disappear.
Exposure Prioritisation
Prioritises the exposures that pose real risk to focus remediation.
Defender & Sentinel Integration
Integrates with Defender and Sentinel so exposures feed detection and response.
Attacker’s-Eye View
Shows what attackers can actually see and reach, not just what you think is exposed.
Works with
Part of the platform
Microsoft products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Microsoft Defender External Attack Surface Management for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01What is external attack surface management?
The continuous discovery and monitoring of your internet-facing assets from an attacker’s perspective — finding the exposed infrastructure, including unknown and unmanaged assets, that attackers can reach. You cannot protect what you do not know you have, and external attack surfaces change constantly.
02How does it find assets we don’t know about?
It scans the internet and attributes discovered assets back to your organisation, surfacing shadow IT, forgotten systems, and exposures you did not know existed — the assets that never make it into an internal inventory but are exactly what attackers probe.
03How is it different from Defender Vulnerability Management?
Vulnerability Management assesses assets you manage from the inside; EASM discovers your external footprint from the outside in, including assets you did not know were exposed. Together they cover both the known internal estate and the unknown external one.
04Does it integrate with the rest of Microsoft security?
Yes — it integrates with Microsoft Defender and Sentinel so external exposures feed detection, prioritisation, and response, turning attack-surface findings into action rather than a standalone report.
05How does Faltrox operate it?
We run continuous external discovery, triage and prioritise the exposures, and drive remediation with your teams — operating attack surface management as part of the managed defence and exposure reduction we deliver.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us