Fortinet white logo
Fortinet white logo

User Guide

EASM

EASM

The External Attack Surface Management (EASM) module provides information about your digital assets, potential security issues, and leaked credentials. You can use the EASM module to identify exposed known and unknown assets, learn about associated vulnerabilities, and prioritize the remediation of critical issues.

FortiRecon performs four types of scans on your external attack surface. Each scan type runs independently.

Scan type

Description

Scheduled scan

FortiRecon scans the seed assets you provide and discovers related assets. It then assesses those assets for security risks and exposures.

Scans run on a weekly or monthly basis, depending on your subscription.

  • Monthly for External Attack Surface Management (EASM) and EASM and Brand Protection (BP) subscriptions.

  • Weekly for EASM, BP, and Adversary Centric Intelligence (ACI) subscriptions.

Continuous IP monitoring

FortiRecon monitors the IPv4 addresses and IP prefixes you have defined, focusing on open ports. The scan runs daily and detects the following changes:

  • Newly discovered open ports

  • Port state changes

  • Service discovery for open ports

  • Service banner changes for open ports

  • Security configuration changes

When FortiRecon detects a change, it updates the asset record with new open ports, related security issues, service details, and relevant CVEs.

FortiRecon records newly discovered open ports. It does not override existing open ports with a closed port state.
Continuous cloud monitoring For each active cloud integration, FortiRecon discovers all public-facing assets from your cloud environment. FortiRecon collects and scans assets that are not already in the EASM inventory.
Newly added asset scan When you add assets through the portal that are not in the current inventory, FortiRecon scans them automatically. Scan results are available in the FortiRecon portal within 24 hours.

You can analyze EASM scan results in the FortiRecon portal.

EASM

EASM

The External Attack Surface Management (EASM) module provides information about your digital assets, potential security issues, and leaked credentials. You can use the EASM module to identify exposed known and unknown assets, learn about associated vulnerabilities, and prioritize the remediation of critical issues.

FortiRecon performs four types of scans on your external attack surface. Each scan type runs independently.

Scan type

Description

Scheduled scan

FortiRecon scans the seed assets you provide and discovers related assets. It then assesses those assets for security risks and exposures.

Scans run on a weekly or monthly basis, depending on your subscription.

  • Monthly for External Attack Surface Management (EASM) and EASM and Brand Protection (BP) subscriptions.

  • Weekly for EASM, BP, and Adversary Centric Intelligence (ACI) subscriptions.

Continuous IP monitoring

FortiRecon monitors the IPv4 addresses and IP prefixes you have defined, focusing on open ports. The scan runs daily and detects the following changes:

  • Newly discovered open ports

  • Port state changes

  • Service discovery for open ports

  • Service banner changes for open ports

  • Security configuration changes

When FortiRecon detects a change, it updates the asset record with new open ports, related security issues, service details, and relevant CVEs.

FortiRecon records newly discovered open ports. It does not override existing open ports with a closed port state.
Continuous cloud monitoring For each active cloud integration, FortiRecon discovers all public-facing assets from your cloud environment. FortiRecon collects and scans assets that are not already in the EASM inventory.
Newly added asset scan When you add assets through the portal that are not in the current inventory, FortiRecon scans them automatically. Scan results are available in the FortiRecon portal within 24 hours.

You can analyze EASM scan results in the FortiRecon portal.