Cymulate Attack Surface Management (ASM) identifies assets exposed to unauthorized access, exploits and other attacks. The platform manages organizational attack surfaces by combining scanning capabilities, insights and mitigation strategies to enhance security posture. Cymulate ASM automates the attacker's view of on-premises, cloud and hybrid environments by scanning autonomous system numbers, domains, subdomains, IP addresses, ports, services, applications and cloud platforms to identify all assets within an organization's IT infrastructure. The platform includes asset discovery scans and monthly comprehensive scans. Asset discovery scans are weekly, non-intrusive scans that identify assets within an organization's IT infrastructure and provide assessment of vulnerabilities, misconfigurations and over-provisioning. Monthly full scans provide comprehensive assessment of an organization's IT infrastructure, identifying all assets and performing vulnerability scanning on domains, subdomains, applications, and infrastructure. Full scans detect vulnerabilities, web misconfigurations, open ports and other security issues. The platform scans the dark web for sensitive information and indicators of data leaks and cyber attacks. After providing primary assets such as web domains, Cymulate ASM maps the external attack surface by emulating reconnaissance and probing methods of threat actors to identify digital assets and assess their exploitability. Findings are mapped to the MITRE ATT&CK framework's tactics, techniques and procedures. Results include detailed reports of discovered assets, vulnerability findings, and risk scores to help organizations prioritize mitigation efforts. Cymulate ASM assesses and monitors an organization's external digital footprint, including exposed web servers, applications, and services from the perspective of an external attacker looking for publicly accessible systems and vulnerabilities.