FortiRecon External Attack Surface Management (EASM) gives organizations an adversary-oriented view of public-facing digital assets, exposures, vulnerabilities, leaked credentials, and related risks that may exist outside the neatly documented internal asset inventory. Current FortiRecon 26.1 documentation describes EASM as part of the broader Attack Surface Management module alongside Internal Attack Surface Management, with scheduled scans plus continuous monitoring for selected public IP ranges and independent web-application assessment capabilities.
Within Fortinet Security Operations, EASM should be operated as an ownership and remediation workflow. Discovering unknown assets matters only when the organization can decide whether the asset is legitimate, who owns it, what exposure is risky, and how to fix or remove it.
Attack Surface Discovery provides the broader lesson: enumeration has cost and noise, so discovery should lead to decisions rather than ever-growing inventories.
Seed assets define the starting point
FortiRecon uses organization-provided seed information to discover related external assets.
Choose company domains, public IP ranges, cloud presence, subsidiaries, acquired brands, and other anchors that represent the real organization.
If seeds omit a new brand or regional domain, the EASM program can miss precisely the assets created outside central IT governance.
Scheduled discovery finds known and unknown external assets
Current EASM documentation states scheduled scans discover assets related to configured seeds and assess those assets for exposures and risks.
Frequency depends on the subscription; current 26.1 guidance describes monthly scans for some EASM subscriptions and weekly scans when combined with additional FortiRecon modules.
Use continuous IP monitoring where faster visibility into exposed ports on critical address ranges is needed between full scans.
Asset inventory should distinguish owned, managed, and third-party
A hostname or IP associated with the brand may be operated by your team, a SaaS vendor, a marketing agency, CDN, MSP, acquisition, or an abandoned project.
Tag every discovered asset with ownership confidence and business relationship.
Do not demand internal engineering patch a vendor-managed service; instead route the issue through vendor/supplier risk with the evidence FortiRecon provides.
Unknown assets deserve rapid classification
Shadow cloud instances, forgotten test sites, stale VPN gateways, legacy DNS records, and acquisition infrastructure are often more dangerous because nobody maintains them.
Create a service-level objective for classifying unknown external assets and escalating those with open admin ports, old certificates, vulnerable software, or exposed data.
Unknown ownership should increase priority rather than delaying action indefinitely.
External exposure is broader than CVEs
EASM surfaces potential weaknesses such as open services, misconfiguration, software vulnerabilities, web application issues, leaked credentials, certificates, DNS/domain risks, and other public-facing indicators depending on module capability.
Prioritize based on exploit path and business value rather than vulnerability count.
An unpatched test server behind no authentication may be riskier than a heavily patched production site with one lower-severity finding.
Leaked credentials connect external intelligence to identity response
Current FortiRecon EASM includes leaked credential visibility.
When organization credentials appear in breached datasets, validate whether the account still exists, enforce password reset/session revocation where appropriate, check MFA/passkey posture, and investigate suspicious authentication.
Do not simply close the finding because the password is old; compromised usernames can still inform targeted phishing or password-spray campaigns.
MITRE mapping can help explain the attacker view
FortiRecon maps discovered issues to relevant MITRE ATT&CK techniques/sub-techniques in current portal views.
Use this to communicate why an exposed service or leaked credential matters in a plausible attack path.
Coverage mapping should not replace remediation priority; the asset’s real exposure and business context remain the primary decision factors.
Cloud integrations improve attribution
Current FortiRecon supports integrations with major cloud providers and Fortinet products so externally discovered assets can be linked back to internal cloud/account context.
This helps answer “which AWS/Azure/GCP team owns this public IP or hostname?” faster.
Reconcile FortiRecon discoveries with CMDB, DNS, cloud inventory, and certificates so ownership metadata gets better over time.
Takedown and remediation need separate workflows
Some exposures are yours to patch; others are malicious lookalike sites, rogue domains, or third-party assets requiring takedown, vendor action, or legal escalation.
FortiRecon’s broader Brand Protection and intelligence modules can complement EASM for impersonation and malicious external presence.
Keep remediation type in the finding so security does not send a phishing-domain takedown request to a web-platform patch team.
Discovery changes should feed architecture governance
If EASM repeatedly finds public databases, admin panels, expired certificates, or unmanaged cloud hosts, fix the provisioning process that creates them.
Use cloud policy, DNS/domain registration controls, certificate lifecycle, landing zones, IaC checks, and ownership tags to reduce recurrence.
Measure how many unknown assets are newly created each month rather than celebrating a large one-time discovery inventory.
FortiRecon EASM succeeds when the adversary’s map becomes an owned remediation map
The mature program keeps seeds current, classifies unknown assets quickly, links public exposure to internal owners, prioritizes exploitable paths, responds to leaked credentials, and fixes provisioning systems that recreate the same risks.
External attack surface management is valuable when security can continuously answer which public assets exist, which are expected, and which must disappear or be hardened.
Asset confidence should be tracked. FortiRecon may discover related assets through DNS, certificates, hosting relationships, or other external evidence. Some will be clearly yours, some likely yours, and some unrelated shared infrastructure. Use ownership confidence to prioritize validation so security does not waste remediation effort on a CDN host or shared provider asset it cannot control.
Continuous IP monitoring should be reserved for address space where rapid port-change visibility matters. Scheduled discovery is useful for broad asset mapping; continuous monitoring of critical ranges can catch a newly exposed admin service faster. Align scan frequency with change velocity and business criticality rather than applying the most expensive monitoring mode to every address equally.
Certificates are valuable ownership and exposure clues. Unexpected certificate subjects/SANs, expired certificates, or certificates referencing old brands can reveal forgotten internet services. Integrate EASM findings with certificate lifecycle management so the same discovery that finds an exposed host can also identify which team owns its TLS identity.
DNS hygiene should be part of EASM remediation. Dangling CNAMEs, stale A records, forgotten subdomains, wildcard records, and misconfigured mail records can create takeovers or confusing public exposure. When FortiRecon identifies a domain issue, route it to the DNS/domain owner with an explicit record-change action rather than treating it only as an application vulnerability.
Web application assessment should be scheduled with the application owner where deeper testing could affect production. External scanners can trigger rate limits, WAF rules, alerts, or application load. Maintain a known scanner source and maintenance/testing agreement while preserving the adversary-style perspective of the assessment.
Acquisitions should trigger a new seed/import cycle immediately. Newly acquired domains and public ranges are often the least standardized and may contain unsupported VPNs, old websites, exposed admin consoles, or leaked credentials. EASM is particularly valuable during the period before the acquired estate is fully integrated into central CMDB and cloud governance.
External findings should be deduplicated against internal scanners without discarding perspective. An internal vulnerability scanner may already know about a CVE on a server, while FortiRecon proves the service is publicly discoverable. Combine the records so the remediation ticket reflects both vulnerability and attacker-visible exposure instead of closing one as duplicate noise.
Takedown workflow should preserve evidence before requesting removal. Capture screenshots, DNS, certificate, hosting, URLs, timestamps, and brand indicators for phishing or rogue assets. This helps legal, registrar, hosting provider, and incident teams prove why the asset is malicious and preserves evidence after the site changes or disappears.
Attack-surface KPIs should include unknown assets over time, mean time to owner assignment, exposed critical services, leaked active credentials, repeated findings, and remediation age. A discovery platform is effective when unknown/exposed inventory shrinks and stays controlled—not when the platform simply reports more assets every quarter.
External exposure should be linked to patch and lifecycle data. An internet-facing product that is end-of-support or running obsolete firmware may deserve replacement rather than a one-off vulnerability fix. EASM should feed technology-refresh decisions when recurring findings show the asset cannot be maintained safely.
Domain and brand ownership should be centralized enough that security can act quickly. If marketing agencies can register campaign domains independently, EASM will repeatedly find assets without an owner. Use registrar/DNS governance, approved providers, and expiry/renewal records so public digital presence remains accountable.
Executive reporting should show attack-surface change, not just total asset count. Track new unknown assets, exposures closed, high-risk ports removed, leaked active credentials remediated, stale domains retired, and mean time to owner assignment. Growth in legitimate assets should not be misreported as worsening security.
EASM should be part of incident scoping after a breach. If attackers register lookalike infrastructure, expose stolen data, or use forgotten internet-facing assets, FortiRecon can provide external context the internal incident team may not see. Preserve discovered asset history around the incident timeline.
Security teams should close the loop by updating seeds when new subsidiaries, domains, netblocks, cloud accounts, and brands are discovered. Otherwise the program gradually drifts away from the organization it is meant to map and misses the exact shadow assets created by business change.