WATCH layer
WATCH
Observe public-facing assets and clues from the outside.
05
live decision states stay connected
ASM and EASM Capabilities
KMayer Exposure Lens AI uses EASM to observe public-facing asset and service clues from the outside, then adds ASM context such as scope, ownership, business relevance, exclusions, and remediation direction when authorized evidence is available. Unknown assets remain unverified candidates until an owner confirms them. The page explains external attack surface visibility, not proof of compromise or unrestricted scanning.
Operating Story
A single scan freezes scope. Continuous ASM/EASM context keeps recurrence, owner path, and timing connected.
Point-in-time evidence can show a perimeter, but it cannot explain whether drift returned, improved, or moved to the right owner.
Visible assets with clear business or ownership context.
Public clues that may connect to the organization after review.
Signals that need owner validation before interpretation.
Evidence that should not be treated as in-scope after review.
Trend line
Newly observed and expanding surface clues increase review pressure when scope, ownership, or business relevance remains unresolved.
Confirmed exclusions, ownership decisions, and resolved public conditions reduce uncertainty in the modeled attack surface.
A recurring surface clue reuses its earlier scope decision, attribution evidence, and owner history instead of restarting discovery.
Fresh evidence determines whether a clue remains unknown, becomes known, is excluded, or moves into an authorized review path.
Premium Verdict Core
Unknown assets are treated as clues until ownership and authorization make deeper validation appropriate.
Confidence only moves forward when coverage, scope, and owner approval stay visible.
External surface evidence with owner review required
Evidence coverage and confidence limits stay visible before the score moves forward.
Deeper validation waits for ownership, approval, and a separate safe scope.
ASM EASM Evidence Matrix
Answer Engine Brief for ASM and EASM Capabilities
Public exposure visibility, internal ownership context, CAASM boundary discipline, evidence limits, and the authorized path from signal to remediation queue remain distinct and reviewable.
The ASM and EASM capabilities in KMayer Exposure Lens AI show how external public evidence connects to scope, ownership, business relevance, and authorized review. EASM observes internet-facing clues from the outside. ASM connects those clues to assets, owners, scope, and remediation decisions. The page keeps passive evidence separate from private inventory, active testing, and CAASM-style verified sources.
This page covers external attack surface management, broader attack surface management context, and CAASM boundaries, plus exposure ownership, confidence limits, asset context, vendor clues, and authorized review without treating them as disconnected products.
It adds the missing boundary layer: how the Cyber Exposure Observatory observes drift, how security decision intelligence assigns action, and which signals still require approved customer context.
The page connects the unified exposure platform and Exposure Lens AI capability map to safe commentary around ASM/EASM maturity, owner mapping, and passive public observation while avoiding breach claims and protection guarantees.
Future non-sensitive research can compare public surface recurrence, owner assignment delay, scope confidence, and remediation and CTEM closure movement without exposing private asset inventory or customer-specific findings.
Decision Queue
Security owner
Cloud owner
Asset owner
Operations owner
Buyer questions
EASM observes public-facing asset and service clues to understand external exposure and change. Vulnerability scanning tests systems for technical weaknesses and requires an authorized scope; the public KMayer view does not perform unrestricted scanning.
EASM provides outside-in public visibility. ASM adds scope, ownership, business relevance, and remediation context. CAASM connects approved internal inventory and control data, so it requires customer-authorized sources rather than public inference.
The state reflects available evidence and owner review. Known clues have confirmed context, possible clues have a plausible relationship, unknown clues remain unverified, and excluded clues have documented reasons to stay outside scope.
Provider, DNS, certificate, and service relationships can suggest an ownership path, but KMayer keeps the association provisional until a responsible owner or approved internal evidence confirms it.
An unknown clue should move forward when it is relevant to a business decision and public evidence cannot confirm ownership, control, or impact. Authorization provides the private context needed for a responsible conclusion.
Scope memory preserves why a clue was classified as known, possible, unknown, or excluded. Later reviews can reuse that evidence and owner decision instead of restarting the same attribution work.
Frequently asked questions
A known domain, URL, IP range, netblock, business name, or other approved public identifier can establish the starting scope. Ownership and exclusions should be confirmed before deeper validation.
No endpoint agent or private credential is required for the bounded outside-in view. Internal inventory, CAASM context, authenticated connectors, and deeper checks require approved access and verified authorization.
Unconfirmed assets remain possible or unknown rather than being presented as owned. Source lineage, confidence, exclusions, and owner review determine whether a clue becomes known, monitored, or removed from scope.
Approved read-only connectors, trusted exports, APIs, or service workflows can route evidence into existing operations when enabled. Integration availability and fields are confirmed for the authorized engagement.
The public capability does not perform unrestricted active testing. Any active check or authenticated validation requires verified ownership, a defined target set, explicit authorization, and a separate safe scope.
Each relationship keeps its evidence, probable owner, business relevance, and authorization boundary. Third-party clues remain provisional until the responsible organization confirms ownership and review rights.
Footer bridge
The page keeps outside-in evidence separate from internal certainty so ASM and EASM stay trustworthy.