Most security tools were built to monitor what is inside your perimeter. Attackers start from the outside. They search public DNS records, certificate logs and registration history to build a complete picture of what you own, what you forgot and what you never knew was exposed.
Now you can see it first.
We’re excited to announce External Attack Surface Management (EASM), the newest capability in Infoblox Exposure Management. Alongside External Attack Surface Management, we're also introducing Supply Chain Intelligence, a new addition to Infoblox Exposure Management that extends outside-in visibility and threat monitoring to the internet-facing assets of your critical vendors.
What External Attack Surface Management Delivers
External Attack Surface Management gives security teams the same outside-in view of their internet-facing infrastructure that attackers have always had. With no agents, no credentials and no prior asset inventory required, you can:
- Discover your full external footprint, including domains, subdomains, IPs, certificates and services, using passive DNS and certificate transparency
- Surface DNS hygiene exposures that most tools never classify as findings, such as dangling CNAMEs, weak email authentication and lame delegations
- Prioritize by what matters: every finding is scored by exploit feasibility and business impact, then grouped by root cause so one misconfiguration becomes one ticket rather than twenty
- Get a first prioritized exposure view in hours, then monitor continuously as your attack surface changes
- Receive owner-attributed remediation guidance with step-by-step instructions for each finding
Supply Chain Intelligence: Your Vendors, Same Outside-In View
Your attack surface doesn’t end at your own infrastructure. Supply Chain Intelligence extends the same discovery model to your named critical vendors, delivering:
- Continuous vendor exposure monitoring (CVEs, misconfigurations, credential leaks)
- Deep and dark web signals indicating early-stage compromise
- Cyber threat intelligence bulletins with indicators of compromise (IoCs) your analysts can pivot directly into threat hunting or Infoblox Threat Defense™ enforcement
This is built for your SOC, not procurement. It answers the question defenders actually need answered: is this vendor being used against us right now?
Why It Matters
In our early access program with over 30 enterprise customers, nearly one in three dangling CNAMEs identified were easy or trivial for an attacker to take over. A Fortune 100 retailer discovered a forgotten subdomain that had already been compromised, a finding their existing attack surface tool never surfaced.
The exposures were always there. The difference now is that you can find them before attackers use them.
How It Fits with Infoblox Exposure Management
External Attack Surface Management and Supply Chain Intelligence join Digital Risk Protection Services (DRPS) within the Infoblox Exposure Management portfolio. Together, they cover both sides of the external threat boundary:
- External Attack Surface Management discovers exposures in assets you own
- Digital Risk Protection Services takes down illegitimate infrastructure you don’t own.
- Supply Chain Intelligence monitors your critical vendors.
- When External Attack Surface Management surfaces malicious infrastructure, findings can connect to Threat Defense for DNS-layer blocking, on average 68 days before traditional defenses recognize the threat.
Discovery, prioritization, takedown and protection in a single portfolio.
Learn More
Check out the launch blog for a deeper look at how External Attack Surface Management and Supply Chain Intelligence work and what early access customers discovered.
👇️Let us know your thoughts and questions below.