CrowdStrike Falcon Surface (EASM)
Falcon Surface: External Attack Surface Management. Automatic discovery and monitoring of external assets - domains, IPs, applications, credential leaks.

Key Features
- Asset discovery - automatic external asset discovery
- Vulnerability assessment - exposed services vulnerability assessment
- Credential monitoring - leaked credentials detection
- Brand protection - phishing sites, fake domains
- Third-party risk - vendor monitoring
Table of Contents
What is Falcon Surface?
Falcon Surface (formerly Recon) is an External Attack Surface Management (EASM) solution - allows you to see your organization through attacker’s eyes. Automatically discovers external assets, monitors credential leaks and detects brand abuse.
Why EASM:
- You can’t protect what you don’t know about
- Shadow IT and forgotten assets are easy targets
- Attackers do recon - you should too
- Credentials leak in breaches - need to find them first
What does Falcon Surface discover?
1. External Assets
Domains and subdomains:
example.com
├── www.example.com
├── mail.example.com
├── vpn.example.com
├── dev.example.com [UNKNOWN - Shadow IT?]
├── staging.example.com [UNKNOWN - Shadow IT?]
└── api-test.example.com [UNKNOWN - Shadow IT?]
IP Ranges:
- Public IPs belonging to organization
- Cloud infrastructure (AWS, Azure, GCP)
- Third-party hosting
Exposed Services:
- Web applications
- Email servers
- VPN gateways
- Remote access
- APIs
2. Vulnerability Assessment
For each discovered asset:
Vulnerabilities:
- CVEs on exposed services
- Misconfigurations
- Outdated software
- Weak encryption
Risk Scoring:
Asset: vpn.example.com
Risk Score: CRITICAL
Reasons:
- CVE-2023-XXXX (RCE) detected
- Weak TLS configuration
- Exposed to internet
3. Credential Monitoring
Monitoring dark web and breach dumps:
What it monitors:
- Email/password combinations
- API keys
- Access tokens
- Private keys
- Internal documents
Alert:
CREDENTIAL LEAK DETECTED
Email: john.smith@example.com
Source: Recent breach dump
Action: Force password reset recommended
4. Brand Protection
Detecting brand abuse:
Phishing Sites:
- Fake login pages
- Lookalike domains
- Spoofed emails
Typosquatting:
Legitimate: example.com
Suspicious:
- examp1e.com (typosquat)
- example-login.com (phishing)
- examplecorp.com (impersonation)
Takedown Assistance:
- Automatic alerts
- Evidence collection
- Takedown request support
5. Third-party Risk
Monitoring vendors and partners:
Vendor Assessment:
- External security posture
- Exposed vulnerabilities
- Breach history
- Credential leaks
How does Falcon Surface work?
Discovery Process
[Seed Data] --> [Passive Recon] --> [Active Scanning] --> [Correlation]
| | | |
Domain names DNS records Port scanning Asset mapping
IP ranges Certificate Service Attribution
Company name transparency identification Ownership
Continuous Monitoring
Scanning:
- Daily scanning for changes
- New asset discovery
- Vulnerability re-assessment
- Credential monitoring 24/7
Alerting:
- New critical asset discovered
- New vulnerability on existing asset
- Credential leak detected
- Phishing site detected
Dashboard and Reporting
Attack Surface Overview
- Total external assets
- Assets by type (domains, IPs, services)
- Risk distribution (critical/high/medium/low)
- Trend over time
Asset Details
For each asset:
- Technical details (IP, ports, services)
- Vulnerabilities
- Risk score
- Ownership (if known)
- Change history
Executive Reports
- Attack surface summary
- Risk trends
- Comparison with industry peers
- Recommendations
Use Cases
Shadow IT Discovery
Finding unknown assets:
- Forgotten test servers
- Unauthorized cloud instances
- Development environments
- Marketing microsites
M&A Due Diligence
Before acquisition:
- External security posture assessment
- Hidden risk detection
- Credential exposure check
- Brand/reputation issues
Vendor Risk Management
Monitoring third-party risk:
- Vendor security posture
- Supply chain exposure
- Incident impact assessment
Incident Response
After incident:
- Credential leak verification
- Extent of exposure
- Additional compromised assets
Integrations
Falcon Platform
- Native integration with Insight XDR
- Correlation with endpoint threats
- Unified investigation
SIEM/SOAR
- Alert forwarding
- Automated response
- Ticket creation
Vulnerability Management
- Integration with Qualys, Tenable
- Unified vulnerability view
Falcon Surface vs Competition
| Feature | Falcon Surface | Recorded Future | Mandiant ASM |
|---|---|---|---|
| Asset discovery | ✓ | ✓ | ✓ |
| Vulnerability scanning | ✓ | Limited | ✓ |
| Credential monitoring | ✓ | ✓ | ✓ |
| Brand protection | ✓ | ✓ | Limited |
| XDR Integration | Native | No | No |
| Threat intel | CrowdStrike | Strong | Strong |
Implementation
Onboarding
- Seed data collection - domains, IP ranges, brand names
- Initial discovery - full attack surface scan
- Verification - ownership confirmation
- Baseline - establishing normal state
- Monitoring - continuous scanning
Timeline
- Initial discovery: 24-48 hours
- Full onboarding: 1-2 weeks
- Continuous value: from day 1
No deployment - it’s a SaaS service, zero installation.
Inquire about CrowdStrike Falcon Surface (EASM)
Contact your product specialist and get a custom quote.

Related Services
Our services supporting the implementation and management of this solution
Managed Detection & Response (MDR)
Cybersecurity
24/7 protection by experts, without building your own SOC.
Managed Endpoint Protection (EDR/XDR)
Cybersecurity
Every endpoint protected. Every alert analyzed. Ransomware blocked in 15 minutes.
Active Directory Security Audit
Cybersecurity
We find paths to Domain Admin before attackers do.
CIS Security Audit
Cybersecurity
Harden system configurations with CIS Benchmarks. Block 85% of common attacks.
From Our Knowledge Base
Articles related to this solution
Blocking the Device Code Flow in Microsoft Entra ID with Conditional Access
How to reduce the risk of Device Code Phishing? A practical guide to blocking the Device Code Flow in Microsoft Entra ID with Conditional Access — step by step, with pitfalls and validation.
Cyber threat landscape 2026: a report for Polish companies in the NIS2 era
Poland is the most digitally attacked EU country. Explore the 2026 cyber threat landscape in numbers, the three most dangerous attack vectors and the NIS2/KSC obligations for Polish companies.
Deepfake, vishing and CEO fraud: how to protect your company from AI-powered scams
A deepfake on a video call, voice cloning and AI-powered CEO fraud mean real losses in the millions. Learn how these scams work and the proven defenses, including second-channel verification.
Related Products
Other solutions you might be interested in
Aruba ClearPass
Aruba Networks
Aruba ClearPass: NAC platform with profiling of 70+ thousand device types. Zero Trust access control for users, BYOD, and IoT.
Barracuda CloudGen Firewall
Barracuda Networks
Barracuda CloudGen Firewall: next-gen firewall with SD-WAN. IPS, application control, VPN, threat protection. Appliance, virtual, cloud.
Barracuda Email Protection
Barracuda Networks
Barracuda Email Protection: AI-powered email security against phishing, ransomware, BEC and account takeover. Gateway + API for Microsoft 365 and Google.
Barracuda SecureEdge
Barracuda Networks
Barracuda SecureEdge: SASE platform combining SD-WAN with cloud security. Zero Trust, SWG, CASB, FWaaS. Protection for distributed workforce.
Want to Reduce IT Risk and Costs?
Book a free consultation - we respond within 24h
Or download free guide:
Download NIS2 Checklist