EASM
The External Attack Surface Management (EASM) module provides information about your digital assets, potential security issues, and leaked credentials. You can use the EASM module to identify exposed known and unknown assets, learn about associated vulnerabilities, and prioritize the remediation of critical issues.
FortiRecon performs four types of scans on your external attack surface. Each scan type runs independently.
|
Scan type |
Description |
|---|---|
| Scheduled scan |
FortiRecon scans the seed assets you provide and discovers related assets. It then assesses those assets for security risks and exposures. Scans run on a weekly or monthly basis, depending on your subscription.
|
| Continuous IP monitoring |
FortiRecon monitors the IPv4 addresses and IP prefixes you have defined, focusing on open ports. The scan runs daily and detects the following changes:
When FortiRecon detects a change, it updates the asset record with new open ports, related security issues, service details, and relevant CVEs. FortiRecon records newly discovered open ports. It does not override existing open ports with a closed port state.
|
| Continuous cloud monitoring | For each active cloud integration, FortiRecon discovers all public-facing assets from your cloud environment. FortiRecon collects and scans assets that are not already in the EASM inventory. |
| Newly added asset scan | When you add assets through the portal that are not in the current inventory, FortiRecon scans them automatically. Scan results are available in the FortiRecon portal within 24 hours. |
You can analyze EASM scan results in the FortiRecon portal.