ASM, Vulnerability Assessment, and Penetration Testing: What Differs

PentaTrail Editorial···12 min read
Contents

Request quotes and ASM, vulnerability assessment, and penetration testing arrive side by side under the heading of "security testing". The pricing basis differs, the ranges differ, and so do the reports.

They are not competing with each other; each confirms something different. Settling which one is being bought is what makes the numbers comparable.

01 / Depth and cadence separate the three, not breadth

In the shapes these are usually sold in, ASM watches the externally visible surface continuously, a vulnerability assessment works a fixed scope systematically inside a time-boxed engagement, and a penetration test presses through to whether exploitation actually succeeds. The word on the quote is the same; the stopping point is not.

Three bars showing how far each service reaches and how often it runs, in their usual operating models. ASM covers what is externally visible and runs continuously; a vulnerability assessment covers an agreed scope systematically within a time-boxed engagement; a penetration test presses through to actual exploitation, also time-boxed

Figure 1: Depth and cadence, compared across the usual operating models

02 / Only ASM starts by building the inventory

Assessments and penetration tests both begin with "test this", while ASM takes the seed domains you register and expands outward through externally visible relationships. A subdomain a team stood up on its own, a staging server still reachable, a domain inherited through an acquisition — whatever is missing from the register is exactly what this step picks up.

Two ways of setting scope side by side. An assessment or penetration test receives a scope the customer sets and looks only inside it. ASM starts from seed domains and adds a team-made subdomain, a staging server left reachable, and an acquired domain to the inventory

Figure 2: Setting the scope — receive a fixed range, or expand from seeds into an inventory

Deep dive: what ASM does not see

The seeds themselves still have to be supplied, and a separate domain with no externally visible relationship to them will not be discovered automatically, so it has to be added by hand.

It trades depth on any single target for breadth and continuity across the external surface. Up to the login wall, within non-destructive actions, and in exchange it runs every day. The number and state of entry points shift daily, which is what continuous observation is good at.

More detail in ASM (Attack Surface Management) — A Beginner's Guide.

03 / What an assessment delivers is the findings and the coverage behind them

Being able to show "this scope was examined against these criteria" is the deliverable itself, which is what a customer's security questionnaire or an audit actually needs. Because the work is time-boxed, it cannot prove that no vulnerabilities exist.

Table 1: What an assessment report carries

What the report carries Contents
The scope examined Which assets were looked at, against which criteria
What was found The defects, and the grounds for calling them that
What could not be confirmed Ground the time box or the granted access did not reach
Deep dive: why the same word carries a tenfold price difference

Depth varies with how the work is commissioned — anonymous surface only, or test accounts and the authenticated screens; a person probing business-specific rules, or tool output organised into a report.

Line up the numbers before those choices are settled and the range looks inexplicable, so scope and criteria come first (what a vulnerability assessment costs).

The report states the coverage achieved, what was found, and the conditions that could not be exercised.

04 / A penetration test shows the path that chains the weaknesses

Settings that look harmless one at a time combine into a route to the objective. Establishing that, and reporting the path taken, is what a penetration test is for.

Small weaknesses chained into a path. An old admin console, a reused password, and a route inward connect by arrows and reach the customer database

Figure 3: Individually minor weaknesses chaining into a reachable objective

Deep dive: what "no intrusion achieved" does not mean

Comprehensiveness is not the goal, so the result reads as no route to the objective having been found within that window and under those conditions. It does not mean no flaws exist.

When the objective is not reached, what was attempted and how far it got are still reported. An assessment returns coverage and a list of findings; a penetration test returns where entry happened, what it passed through, and what it reached.

05 / Sequence the three instead of choosing between them

When the target is already clear, an assessment or a penetration test can be commissioned directly, and ASM earns its place in the other case — when the intent is to cover everything the organisation exposes and no such inventory exists. With the inventory in hand and the important surfaces identified, an assessment can be aimed at them, and a penetration test answers the remaining question of whether an attacker really reaches what matters.

Sequencing diagram. Whether an inventory of exposed assets exists is the branch point: without one, build the list with ASM; with one, hand over the target directly. Both paths continue into aiming an assessment at what matters, and then into proving reachability with a penetration test

Figure 4: The inventory decides the entry point; the order after it is the same

06 / PentaTrail covers discovery and non-destructive reproduction

Discovery expands outward from registered seeds, the result is monitored daily, and changes and vulnerability candidates are reported. On the CTEM plan, candidates that qualify are reproduced remotely and non-destructively, and "not reproduced" does not mean "safe".

A line dividing what PentaTrail reaches from what it does not. Externally visible assets are watched daily and replayed non-destructively, while screens behind a login, steps that write data, and multi-step flows sit past the login wall and belong to a vulnerability assessment or a penetration test

Figure 5: Where PentaTrail stops, and who covers what lies beyond

It does not go past a login, and never takes routes that would write data. No specification is handed over, so operations forbidden only by a particular business cannot be judged either. Confirming what sits behind authentication calls for an assessment; demonstrating reachability to a target calls for a penetration test.

Appendix: the six-dimension comparison, and red teaming

Table 2: ASM, vulnerability assessment, and penetration testing compared

Dimension ASM Vulnerability assessment Penetration testing
How scope is set Seeds supplied, expanded automatically Supplied by the customer A supplied range, or a target to reach
Common operating model Ongoing observation (e.g. daily) Time-boxed engagement Time-boxed engagement
Depth What is visible externally Systematic across scope, by agreed criteria Presses through to actual exploitation
Deliverable Asset inventory and changes Coverage achieved and findings What was exploited, and the path taken
Coverage Broad across assets High within the agreed criteria Comprehensiveness is not the goal
Common pricing basis Monthly Per engagement Per engagement

The table lists common shapes, not definitions. Assessments are often contracted as recurring runs, and penetration testing is sold on retainers and subscriptions too.

Red teaming and TLPT

Red team exercises attack too, but their character differs. Threat intelligence shapes a realistic adversary scenario, the work stays deliberately quiet, the scope includes people and processes across the organisation, and the defenders' detection and response are exercised.

Threat-led penetration testing (TLPT) belongs to that red team family. Frameworks such as TIBER-EU in Europe define how threat intelligence drives an engagement that tests prevention, detection, and response; the practice spread from heavily regulated sectors and is now used across industries. What separates a scoped penetration test from red teaming is the use of threat intelligence, the demand for stealth, the inclusion of people and process, and whether the defending side is exercised.

Visualize your attack surface with PentaTrail CTEM/ASM

From discovery to vulnerability validation and remediation — all powered by the CTEM framework.

Get Started

See pricing/Compare and choose