An asset inventory shows what is exposed. An attack path shows what that exposure makes possible. Security teams buy attack surface management to answer the first question and are then surprised when it cannot answer the second. The two disciplines share vocabulary, sit next to each other in vendor decks, and do different jobs.
This guide separates them, shows where each one stops, and lays out how inventory, exposure discovery, relationship analysis, and validation fit together.
What CodeAnt AI solves here: CodeAnt AI runs both layers on one model. CodeAnt External continuously maps domains, ports, services, endpoints, and leaked credentials. CodeAnt Internal connects those exposures to code, secrets, cloud configuration, and identity, and agents test which connections reach critical data.
The Short Answer
Attack surface management (ASM) finds and tracks what an attacker could interact with. Attack path analysis (APA) determines which of those exposures connect to something valuable, and how.
Attribute | Attack surface management | Attack path analysis |
|---|---|---|
Core question | What is exposed? | What does this exposure enable? |
Primary output | An inventory of assets and their exposures | Routes from entry points to critical assets |
Unit of analysis | A single asset or exposure | A connection between assets, identities, and permissions |
Data sources | Internet scanning, DNS, certificates, cloud APIs | Inventory plus code, cloud configuration, identity, and network data |
Typical cadence | Continuous discovery | On change, or continuous with a living model |
What it proves | That something is reachable | That a route to impact exists, once validated |
Main blind spot | Impact of what it finds | Assets it was never told about |
ASM without path analysis produces a long, flat list. Path analysis without ASM works on an incomplete map. Each needs the other.
What Attack Surface Management Does
Attack surface management is the continuous discovery, inventory, and monitoring of the assets an attacker can reach. External attack surface management (EASM) narrows that to what is visible from the internet.
A mature ASM program tracks domains and subdomains, IP ranges, open ports and services, certificates, cloud resources, exposed APIs, third-party assets, and leaked credentials. It flags new exposures and known vulnerabilities on them.
Its strength is coverage. Teams routinely discover hosts that no one owns, staging environments that outlived their projects, and services that were never meant to be public.
Its limit is context. ASM sees a host and a version string. It cannot see which workload identity runs behind that host, what that identity can read, or whether the version's vulnerable code path is even reachable.
What Attack Path Analysis Does
Attack path analysis takes exposures as starting points and asks where each one leads. It connects them to identities, permissions, secrets, network routes, and data stores, then ranks the routes by what they reach.
Its strength is prioritization. A forgotten preview app with no sensitive data becomes urgent when its identity can read a production secret.
Its limit is the map it receives. A graph built on an incomplete inventory produces an incomplete set of paths, and "no path found" says nothing about assets that were never discovered.
Where Each One Stops
The clearest way to see the boundary is to look at the questions each discipline answers.
Question | ASM | Attack path analysis |
|---|---|---|
Which subdomains do we own? | Answers it | Consumes the answer |
Is this service exposed to the internet? | Answers it | Consumes the answer |
Does this host run a version affected by a CVE? | Answers it, by version match | Asks whether the exploit conditions hold |
Which identity runs behind this application? | Usually cannot see it | Answers it with internal context |
Can this exposure reach customer data? | Cannot answer it | Answers it |
Which single fix cuts the most routes? | Cannot answer it | Answers it through choke points |
Does the route actually work? | Cannot answer it | Answers it once validated |
Four Layers, One Pipeline
ASM and attack path analysis are two parts of a four-layer pipeline. Each layer answers a different question and hands its output to the next.
Layer | Question it answers | Output | Typical source |
|---|---|---|---|
1. Inventory | What do we have? | Assets, owners, environments | ASM, CMDB, cloud APIs |
2. Exposure discovery | What can an attacker touch? | Reachable services, endpoints, leaked secrets | ASM, EASM, external testing |
3. Relationship analysis | What does each exposure connect to? | Modeled attack paths and choke points | Attack path analysis with internal context |
4. Validation | Which routes actually work? | Proven paths with evidence | Penetration testing, attack path validation |
Skipping a layer shows up quickly. Without layer 3, every exposure looks equally urgent. Without layer 4, every modeled route looks equally real.
External penetration testing spans layers 2 and 4 from the outside. The external penetration testing methodology shows how reconnaissance feeds exploitation.
Where CTEM and Exposure Management Fit
Continuous threat exposure management (CTEM) is Gartner's framework for running these layers as a repeating program. Its five stages are scoping, discovery, prioritization, validation, and mobilization.
ASM does most of the work in discovery. Attack path analysis does most of the work in prioritization. Validation is a separate stage, so a modeled path stays a hypothesis until someone tests it. "Exposure management" is the broader product category that bundles these capabilities. When a vendor uses the term, ask which of the four layers it actually performs and which it imports from other tools.
Attack Surface, Attack Vector, and Attack Path
Three related terms cause most of the confusion. They describe different scales of the same problem.
Term | Definition | Example |
|---|---|---|
Attack surface | Every point where an attacker can interact with your systems | All public hosts, APIs, login pages, and exposed credentials |
Attack vector | A specific method used to exploit one point on the surface | A vulnerable image-processing library on the upload endpoint |
Attack path | The full route from an entry point to a target | Upload endpoint, to workload role, to production secret, to database |
The surface is where an attacker can start. The vector is how they get in. The path is where they can go after that.
Which One Do You Need?
The answer depends on what your team cannot currently see.
Your situation | Start with | Why |
|---|---|---|
You cannot list your internet-facing assets with confidence | ASM | Path analysis on an unknown surface misses entry points |
You have an inventory but too many findings to act on | Attack path analysis | It ranks findings by what they reach |
Leadership or auditors want proof of real risk | Validation | Modeled paths are hypotheses until demonstrated |
Your environment changes on every deploy | A continuous model covering all four layers | Point-in-time results go stale within weeks |
Most teams already own some ASM. The usual gap is the connection from an exposure to the identity, permission, and data behind it.
Where This Leaves You
ASM tells you where an attacker can start. Attack path analysis tells you where they can go. Validation tells you which of those routes are real. The full route from exposure to data is in the attack path analysis guide. The founder's account of running both views as one model is in Autonomous Preventive Security.
See your external exposure and the paths behind it in one report. Book an attack-path assessment.


