Skip to main content
Cyber Health Score
Get started

Get started

External Attack Surface Management

What Argus EASM includes, how confidence works, and what remains out of scope.

Audience
All users
Plan availability
All plans
Last reviewed

Cyber Health Score provides bounded External Attack Surface Management (EASM) for organisations that verify the domains they control.

What ships today

From verified seed domains, Cyber Health Score can:

  1. run passive discovery and bounded recursive passive discovery
  2. record discovery provenance and discovery chains that explain why an asset appears
  3. maintain an asset inventory with ownership attribution and confidence
  4. observe DNS, certificates, services, technologies, IPv4/IPv6, and ASN / hosting context
  5. classify cloud, CDN, SaaS, and other third-party relationships without treating them as first-party owned assets
  6. surface shadow / unmanaged asset candidates carefully when evidence supports it
  7. enrich vulnerability intelligence with CVE correlation, CISA KEV, and FIRST.org EPSS
  8. rank remediation with explainable Exposure Priority
  9. show Change Intelligence, Graph relationships, Alerts, remediation, and reports
  10. answer organisation-scoped read-only questions through the Tenant Agent

Continuous Assessment remains a separate, consent-gated active path. Passive discovery never silently grants active authority.

Confidence and wording

Vulnerability correlations use confidence-aware customer wording such as potentially affected. Weak fingerprints without meaningful version evidence do not expand into every published CVE for a product family.

CPE correlation is partial. Do not treat it as comprehensive NVD coverage.

Supplier EASM linkage is foundation-only. Declared monitored supplier domains may appear in inventory context, but full Supplier Assurance is not shipped as a complete product.

Explicitly out of scope

Cyber Health Score Argus does not provide:

  • intrusive validation or exploit verification
  • authenticated vulnerability scanning
  • internet-wide or full-ASN scanning
  • email or webhook Alert delivery unless separately enabled later
  • Brand / Impersonation expansion beyond existing foundations
  • complete asset discovery or complete vulnerability detection as absolute outcomes
  • security certification

Return to the documentation home to browse all topics.

Back to documentation