Attack Surface Management


Solutions Based on Threat Intelligence

Criminal IP ASM’s Attack Surface Management

Provides dashboard access to auto-monitored assets exposed to attack surfaces.

Automatic Asset Detection ASM

An attack surface management solution that automatically detects not only known assets, but also unrecognized IT assets and vulnerabilities with the registration of just one domain of a company or organization.

Request Free Demo

ASM Trial

By subscribing to the Pro plan of Criminal IP, you can manually register owned IP ranges and domains to monitor them through the attack surface management dashboard.

Subscribe to Criminal IP's Pro Plan

Criminal IP ASM's ComprehensiveAttack Surface Management Services

  • New Assets

    Enterprise

    Auto-detects added or changed assets.

  • IP Assets

    Scans open port information provided by registered IP addresses.

  • Domain / Certificate

    Provides information on the subdomains of registered domains and the applied certificate information.

  • OSINT / Dark Web

    It identifies sensitive information, servers, files, and account details exposed on Google, the Dark Web, and Telegram.

  • Risk

    Detects vulnerabilities in all assets such as domain, IP addresses, SSL certificates, applications etc.

  • Intelligence Search Result

    View details regarding a particular asset's attack surface exposure levels and vulnerabilities.

  • Dashboard

    Provides a dashboard containing statistics, location, vulnerability status, and graphs for all registered assets.

  • Report

    Auto-generates Attack Surface Management status for new assets and vulnerabilities.

Dashboard

Visualizes the threat intelligence information of automatically detected assets on the dashboard. By dividing them into three levels according to the severity of the risk (High, Medium, Low), you will be able to quickly identify assets that require urgent security measures.

IP Assets (Application)

View information regarding registered IP Assets (categorized by risk score, AS Name, location information, vulnerability). Clicking on the provided IP address will direct you to the results page of Criminal IP Asset Search.

Risks

Detected threat vectors in registered IT assets (IP, Domain) are automatically added to the Risk page for easy access.

Domain /Certificate

Provides comprehensive threat intelligence of registered IP addresses and domains from Criminal IP's systems in visuals.

Criminal IP ASM employs a comprehensive method of analyzing all attack surfaces regardless of complexity.

There's no need to busy yourself with looking for scattered assets. Criminal IP ASM employs real-time detection, all displayed on our comprehensive web-access dashboard. Assets on attack surfaces and vulnerabilities can now be easily detected and countered according to the latest cybersecurity trends.

Threat Intelligence Search Engine as Add-on

Access additional features in Criminal IP CTI (Cyber Threat Intelligence), with integrated API functions and added Search Intelligence services.

Stay on top of the latest trends with our rich analysis reports and thorough statistics data on global cybersecurity threats.

Auto-detect online assets

One of the key aspects of attack surface management is identifying known and unknown asset vulnerabilities.

Criminal IP ASM scans the entire internet for all assets belonging to the user, even those that were previously unknown, by detecting all running applications and domains.

SaaS Platform

Criminal IP ASM is a Software as a Service (Saas) platform.

We provide Attack Surface Management solutions made easy to access through a web interface.

Enterprise

You’re one step away from implementing Criminal IP ASM

All you need is a single domain address of a particular company asset, and our services can automatically identify all corporate assets distributed across the world wide web. From there on, your IT assets can be viewed through Criminal IP ASM's superior automated attack surface management.

Register a primary domain, Search for associated domains, Search for Complex Amplifications, Match feature information classifications, Automatic Extraction of IPs and Domains in Possession

ATTACK SURFACE MANAGEMENT

What is Attack Surface Management (ASM)?

Companies employ a myriad of network equipment, databases, servers, and applications necessary to run a business. Attack Surface Management is a proactive approach to detecting possible attack vectors from malicious hackers through identifying open ports, server vulnerabilities, phishing attempts, malicious code distribution, etc.

Criminal IP BlogAttack Surface Management: Monitoring Unknown Assets and Vulnerabilities

Check out our Best Practice articles to learn more about managing attack surfaces based on threat intelligence, as well as the available range of detectable attack surfaces.

FAQ for Criminal IP ASM'sAttack Surface Management services

Q.
How do I gain access to Criminal IP ASM?
A.

If you would like to purchase Automatic Asset Detection ASM, please inquire the Sales team through Contact us. If you have purchased and are using the Pro plan for Criminal IP, you can also use Manual Asset Registration ASM.

Q.
What kind of assets can Criminal IP ASM detect automatically?
A.

It scans the open ports of the registered IP addresses to detect all connected applications. The detected hosts include domains, SSL certificates, IoT, MySQL, printers, and more. The detected assets are classified by those such as geographic information, cloud information, ASN, and APP information, and visualized on the dashboard. In addition, it automatically detects assets exposed on the Google search engine using the OSINT(Google Hacking) function.

Q.
How are asset vulnerabilities mapped automatically?
A.

Criminal IP scans IP address ports around the world in real-time. If an exploitable port or a vulnerability is detected, they are classified as a dangerous element on the attack surface and displayed as such on the Criminal IP ASM dashboard. More information about detected vulnerabilities can be found by clicking the Search Analysis Data Results page on Criminal IP.

Q.
What is the difference between Manual Asset Registration ASM and Automatic Asset Detection ASM?
A.

The biggest difference is whether the assets are automatically detected.
Manual Asset Registration ASM Manual Asset Registration ASM requires the user to manually register the IP address ranges and domains they want to scan. You can view the scanned data for the registered assets on the Criminal IP ASM dashboard. However, any additional assets, unregistered IP ranges, and parent domain assets are not automatically detected.Automatic Asset Detection ASMAutomatic Asset Detection ASM automatically detects all associated IP addresses and subdomains after initially entering one single ownership domain. Any additional assets are also automatically detected thereafter. Assets that are not known beyond those discovered can be found through Criminal IP ASM.

Q.
How many assets in total can I monitor on my Criminal IP ASM dashboard?
A.

If you are subscribed to the Criminal IP Pro plan, you can manually register and monitor up to 128 IP addresses and domains. When you purchase Automatic Asset Detection ASM, you can monitor all assets that you own by default. Please Contact us for more information.

Q.
Can I manually add assets to my Attack Surface Management?
A.

When using Manual Asset Registration ASM, assets can only be added manually. Customers using Automatic Asset Detection ASM have automatically detected assets and therefore may not require manual registration. However, there may be some occasions where manual registration is necessary. For example, new IP ranges and assets such as domains can be manually added due to reasons such as mergers and acquisitions (M&A), or security audits of a separated subsidiary company.

Q.
Is there anything I need to install or set up after purchasing Criminal IP ASM?
A.

No, there isn’t. Once the purchase of Criminal IP ASM is complete, customers can log in to the Criminal IP ASM website and immediately use all ASM features. Customers using Manual Asset Registration ASM need to manually register all IP addresses and domain assets they own to scan the desired assets. Customers using Automatic Asset Detection ASM only need to enter a single domain or IP address, and all assets they own will be automatically detected and registered on the dashboard within 2-3 days.

Q.
Is there a trial version of the Criminal IP Attack Surface Management?
A.

User can access Manual Asset Registration ASM through an account with a subscription to the Criminal IP Pro plan. Alternatively, you can request a free Demo to purchase Automatic Asset Detection ASM. Please Contact us for more information.