defender-easm

Installation
SKILL.md

Microsoft Defender EASM

Defender External Attack Surface Management (EASM) builds and maintains a continuous, outside-in inventory of an organization's internet-facing footprint and surfaces risks on those assets — expired SSL certs, exposed admin interfaces, end-of-life web tech, and known CVEs — without any agent or credentials.

When to use

  • You don't have a complete list of internet-facing assets (most orgs don't).
  • M&A: rapid discovery of an acquired company's internet footprint before integration.
  • Subsidiary / shadow IT discovery — assets registered to anyone, deployed anywhere.
  • Continuous monitoring of certificate expiration, exposed services, deprecated software.

Do not use this skill for internal asset posture (defender-for-cloud-hardening), endpoint vulnerability management (defender-for-endpoint), or generic SOC hunting (sentinel-detection-engineering).

How discovery works

Installs
34
GitHub Stars
173
First Seen
Jun 20, 2026
defender-easm — vinayaklatthe/microsoft-security-skills