defender-easm
Installation
SKILL.md
Microsoft Defender EASM
Defender External Attack Surface Management (EASM) builds and maintains a continuous, outside-in inventory of an organization's internet-facing footprint and surfaces risks on those assets — expired SSL certs, exposed admin interfaces, end-of-life web tech, and known CVEs — without any agent or credentials.
When to use
- You don't have a complete list of internet-facing assets (most orgs don't).
- M&A: rapid discovery of an acquired company's internet footprint before integration.
- Subsidiary / shadow IT discovery — assets registered to anyone, deployed anywhere.
- Continuous monitoring of certificate expiration, exposed services, deprecated software.
Do not use this skill for internal asset posture (defender-for-cloud-hardening),
endpoint vulnerability management (defender-for-endpoint), or generic SOC hunting
(sentinel-detection-engineering).