Guides

Articles

Projects
In Mandiant Advantage Attack Surface Management (MA-ASM), a Project is a workspace where you can organize your Collections and the Members that have access to them. Projects may be private even within your organization as they do not default to be...
 Manage Project Membership
Project membership A Project is essentially a workspace that contains Collections along with Owners and Members authorized to view the contents of those Collections. There can be multiple Projects in an organization, each with different Owners, dif...
Account Settings Overview
Mandiant Advantage Attack Surface Management (MA-ASM) Account Settings include both user- and project-specific settings. This is where you can generate API keys, add integrations, and manage project membership.  Account Settings are available u...
 Notifications
Mandiant Advantage Attack Surface Management (MA-ASM) offers email and chat-based alerting to ensure you can easily monitor changes in your Collections and quickly investigate new assets and exposures. Member-specific email alerts To enable ...
Reviewing Entities
An Entity is an external asset belonging to an organization such as a domain name, email address, or URL. Every Entity that is found serves as a pivot point for additional data gathering.  For a list of available Entities in , see Entity types . ...
Search Summary
The Search Summary feature in Mandiant Advantage Attack Surface Management (MA-ASM) provides a high-level summary of the current search, helping you to understand the scope of the search. This is significant, especially if you are searching within a...
Discovery Context Visualizer
Mandiant Advantage Attack Surface Management (MA-ASM) collection engines carry out unique discovery tasks for each type of discoverable asset or entity. These tasks gather information and assist in determining whether these assets belong to your or...
Scan History
This feature lets you visualize changes to an Entity over time. Some use cases include: Identifying Issues that have gone inactive. Identifying Technologies that have changed. To access Scan History information, select an Entity and navigate t...
Inferred Vulnerabilities
An inferred vulnerability, or CVE, is a vulnerability identified through a passive check that recognizes a technology known to have a vulnerability associated with it.  From the Mandiant Advantage Attack Surface Management (MA-ASM) Entities ...
 Reviewing Issues
Issues are respective to the entity type, and different entity types warrant their own issue checks. The most common issue checks are for URI entities. Issue checks are selected based on the technology and version (as captured) that is fingerpri...
Analyzing SSL/TLS Issues
For SSL/TLS vulnerability analysis in Mandiant Advantage Attack Surface Management (MA-ASM), two Issues are available: Deprecated SSL/TLS Protocol Configured : A vulnerability results when a server is configured to allow a deprecated SSL/TLS prot...
Bulk Select
Bulk Select in Mandiant Advantage Attack Surface Management (MA-ASM) lets you select multiple Issues or Entities and perform specific actions on your selection. The following bulk actions are available: Issues Add Tags Set Status E...
Understanding Technologies
With our robust fingerprinting engine, we focus on popular technologies commonly found across enterprise systems. When a new vulnerability comes out, we add it to our fingerprinting engine if the technology is not already in there. Technologi...
Search Syntax for Attack Surface Management
The Mandiant Advantage Attack Surface Management (MA-ASM) search syntax operates under a few simple rules: Queries of different keywords are AND'd For example: acme.com port_tcp:80 Read this as "any Entity with acme.com in the n...
 Export Search Results
Exported search results in Mandiant Advantage Attack Surface Management (MA-ASM) contain raw data used for the platform to display related content such as the list of Issues , Entities , and Technologies . Some fields are intentionally left bla...
ASM Organization Switcher
In Mandiant Advantage Attack Surface Management (MA-ASM), an organization is used to manage both users and Projects . It's possible for a user to be a member of multiple organizations.  For more information about organization membership, see Man...
Opt Out of Attack Surface Management Scanning
See Scan Ranges for source IP addresses – which can be allow-listed to ignore these alerts. If you would like to be excluded from active probes, let us know by contacting .  ...
Insights Overview
Insights is a Mandiant Advantage Attack Surface Management (MA-ASM) reporting feature. The data reflected in this dashboard is related to the Collections that are selected. You can select specific Collections to modify the data presented to suit y...