Skip to content
Cybersecurity CrowdStrike

CrowdStrike Falcon Surface (EASM)

Falcon Surface: External Attack Surface Management. Automatic discovery and monitoring of external assets - domains, IPs, applications, credential leaks.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Key Features

  • Asset discovery - automatic external asset discovery
  • Vulnerability assessment - exposed services vulnerability assessment
  • Credential monitoring - leaked credentials detection
  • Brand protection - phishing sites, fake domains
  • Third-party risk - vendor monitoring
Available now
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Send inquiry
Table of Contents

What is Falcon Surface?

Falcon Surface (formerly Recon) is an External Attack Surface Management (EASM) solution - allows you to see your organization through attacker’s eyes. Automatically discovers external assets, monitors credential leaks and detects brand abuse.

Why EASM:

  • You can’t protect what you don’t know about
  • Shadow IT and forgotten assets are easy targets
  • Attackers do recon - you should too
  • Credentials leak in breaches - need to find them first

What does Falcon Surface discover?

1. External Assets

Domains and subdomains:

example.com
├── www.example.com
├── mail.example.com
├── vpn.example.com
├── dev.example.com        [UNKNOWN - Shadow IT?]
├── staging.example.com    [UNKNOWN - Shadow IT?]
└── api-test.example.com   [UNKNOWN - Shadow IT?]

IP Ranges:

  • Public IPs belonging to organization
  • Cloud infrastructure (AWS, Azure, GCP)
  • Third-party hosting

Exposed Services:

  • Web applications
  • Email servers
  • VPN gateways
  • Remote access
  • APIs

2. Vulnerability Assessment

For each discovered asset:

Vulnerabilities:

  • CVEs on exposed services
  • Misconfigurations
  • Outdated software
  • Weak encryption

Risk Scoring:

Asset: vpn.example.com
Risk Score: CRITICAL
Reasons:
- CVE-2023-XXXX (RCE) detected
- Weak TLS configuration
- Exposed to internet

3. Credential Monitoring

Monitoring dark web and breach dumps:

What it monitors:

  • Email/password combinations
  • API keys
  • Access tokens
  • Private keys
  • Internal documents

Alert:

CREDENTIAL LEAK DETECTED
Email: john.smith@example.com
Source: Recent breach dump
Action: Force password reset recommended

4. Brand Protection

Detecting brand abuse:

Phishing Sites:

  • Fake login pages
  • Lookalike domains
  • Spoofed emails

Typosquatting:

Legitimate: example.com
Suspicious:
- examp1e.com (typosquat)
- example-login.com (phishing)
- examplecorp.com (impersonation)

Takedown Assistance:

  • Automatic alerts
  • Evidence collection
  • Takedown request support

5. Third-party Risk

Monitoring vendors and partners:

Vendor Assessment:

  • External security posture
  • Exposed vulnerabilities
  • Breach history
  • Credential leaks

How does Falcon Surface work?

Discovery Process

[Seed Data] --> [Passive Recon] --> [Active Scanning] --> [Correlation]
     |               |                    |                    |
  Domain names    DNS records        Port scanning        Asset mapping
  IP ranges       Certificate         Service              Attribution
  Company name    transparency        identification       Ownership

Continuous Monitoring

Scanning:

  • Daily scanning for changes
  • New asset discovery
  • Vulnerability re-assessment
  • Credential monitoring 24/7

Alerting:

  • New critical asset discovered
  • New vulnerability on existing asset
  • Credential leak detected
  • Phishing site detected

Dashboard and Reporting

Attack Surface Overview

  • Total external assets
  • Assets by type (domains, IPs, services)
  • Risk distribution (critical/high/medium/low)
  • Trend over time

Asset Details

For each asset:

  • Technical details (IP, ports, services)
  • Vulnerabilities
  • Risk score
  • Ownership (if known)
  • Change history

Executive Reports

  • Attack surface summary
  • Risk trends
  • Comparison with industry peers
  • Recommendations

Use Cases

Shadow IT Discovery

Finding unknown assets:

  • Forgotten test servers
  • Unauthorized cloud instances
  • Development environments
  • Marketing microsites

M&A Due Diligence

Before acquisition:

  • External security posture assessment
  • Hidden risk detection
  • Credential exposure check
  • Brand/reputation issues

Vendor Risk Management

Monitoring third-party risk:

  • Vendor security posture
  • Supply chain exposure
  • Incident impact assessment

Incident Response

After incident:

  • Credential leak verification
  • Extent of exposure
  • Additional compromised assets

Integrations

Falcon Platform

  • Native integration with Insight XDR
  • Correlation with endpoint threats
  • Unified investigation

SIEM/SOAR

  • Alert forwarding
  • Automated response
  • Ticket creation

Vulnerability Management

  • Integration with Qualys, Tenable
  • Unified vulnerability view

Falcon Surface vs Competition

FeatureFalcon SurfaceRecorded FutureMandiant ASM
Asset discovery
Vulnerability scanningLimited
Credential monitoring
Brand protectionLimited
XDR IntegrationNativeNoNo
Threat intelCrowdStrikeStrongStrong

Implementation

Onboarding

  1. Seed data collection - domains, IP ranges, brand names
  2. Initial discovery - full attack surface scan
  3. Verification - ownership confirmation
  4. Baseline - establishing normal state
  5. Monitoring - continuous scanning

Timeline

  • Initial discovery: 24-48 hours
  • Full onboarding: 1-2 weeks
  • Continuous value: from day 1

No deployment - it’s a SaaS service, zero installation.

Inquire about CrowdStrike Falcon Surface (EASM)

Contact your product specialist and get a custom quote.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free technical consultation
Custom quote and configuration

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist