Attack Surface Testing
Attack Surface Testing runs benign exploits against your externally facing assets to confirm the presence of vulnerabilities.
Cortex Xpanse Attack Surface Testing confirms the presence of a vulnerability on your external attack surface, enabling you to quickly and confidently prioritize risks. With your approval, Cortex Xpanse runs benign exploits against externally facing assets to confirm the presence of vulnerabilities. Rather than manually verifying inferred CVEs yourself, Cortex Xpanse Attack Surface Testing runs daily scans based on your preferences.
When you set up Attack Surface Testing, you select the targets for the testing, either all or a subset of your directly-discovered services (services that are definitively associated with an asset that belongs to your organization). Once you've selected targets, Cortex Xpanse runs attack surface scans daily. Attack surface test results are displayed on the Services tab in the Inventory, so you can review the data as part of your existing attack surface management (ASM) workflow. All attack surface tests are enabled by default, but you can view information about the tests and disable tests if needed from the Attack Surface Tests page.
Attack surface test results can generate alerts and impact an incident's risk score.
Last updated
Was this helpful?
