ASM enrichment of cloud assets provides visibility into all the assets in your cloud infrastructure that are exposed to the internet.
Attack Surface Management (ASM) enrichment of cloud assets brings ASM capabilities to cloud security posture management, providing visibility into all the assets in your cloud infrastructure that are exposed to the internet.
ASM enrichment of cloud assets includes the following capabilities:
Discovery of unmanaged cloud services: Identify internet-exposed cloud services that are unmanaged, so you can onboard them into Cortex XDR for comprehensive cloud security and policy enforcement.
Confirmation of internet exposure: ASM internet scan data is used to reinforce CNA detections to provide high-confidence detections of inadvertent internet exposure. This joint approach combines inside-out and outside-in assessments to reduce false-positives.
Monitoring of managed and unmanaged cloud services: Gain ongoing visibility into the risks on cloud services through regular ASM scans and issues and findings for cloud-related attack surface detections.
Review your unmanaged cloud services
Review your unmanaged cloud services in your External Surface inventory.
Review your unmanaged cloud services in your External Surface inventory. Unmanaged cloud services are cloud services that were discovered in an ASM scan and cannot be correlated with cloud assets that were previously onboarded into your inventory.
Navigate to → → → → .
On the Service Inventory page, filter the list of services using the filter Partially Onboarded = Yes.
Review unmanaged cloud issues
View your unmanaged cloud issues, including service details.
The attack surface rule Unmanaged Cloud Service creates findings when ASM scans detect unmanaged cloud services. This rule is enabled by default, which means it will also create issues. Perform these steps to view your unmanaged cloud issues:
Navigate to → .
Filter the Issues table using the filter Attack Surface Rule ID = UnmanagedCloudService.
Click on an issue to display the issue details, including the unmanaged cloud service information.