Fortinet black logo

User Guide

IASM

IASM

Internal Attack Surface Management (IASM) provides comprehensive internal asset discovery, vulnerability assessment, and web application analysis for attack surface management.

IASM allows you to scan multiple subnets and deploy the IASM Agent across multiple sites to ensure complete visibility into your internal attack surface. IASM Agent is a Docker container deployed within your network, responsible for executing scans and relaying discovered data to the FortiRecon.

To get started with IASM, follow these steps:
  1. Configure IASM settings in Asset Management > IASM Configuration and download the configuration file (.yml). See IASM Configuration.

  2. Use the configuration file to deploy the IASM Agent on a device within your internal network. See IASM Agent.

  3. Access and analyze IASM scan results in the FortiRecon portal.

IASM

Internal Attack Surface Management (IASM) provides comprehensive internal asset discovery, vulnerability assessment, and web application analysis for attack surface management.

IASM allows you to scan multiple subnets and deploy the IASM Agent across multiple sites to ensure complete visibility into your internal attack surface. IASM Agent is a Docker container deployed within your network, responsible for executing scans and relaying discovered data to the FortiRecon.

To get started with IASM, follow these steps:
  1. Configure IASM settings in Asset Management > IASM Configuration and download the configuration file (.yml). See IASM Configuration.

  2. Use the configuration file to deploy the IASM Agent on a device within your internal network. See IASM Agent.

  3. Access and analyze IASM scan results in the FortiRecon portal.