Attackers don't stop at the firewall. Neither should you.
Internal ASM is the inside-the-firewall module of Helios by Isaphia. Lightweight collectors map the assets, services, and dangerous legacy systems attackers pivot to once they're inside — each tied automatically to the CVE that explains it.
Request a DemoThe inside of your network is its own attack surface
Lateral movement, flat unpatched networks, and legacy systems nobody has mapped.
A firewall isn't a wall — it's a door, and doors get opened. Once an attacker has a foothold, they don't go straight for the crown jewels. They look around, find the old server nobody patches and the file share running weak protocols, and use them to move from one machine to the next until they reach something valuable. Security teams call this lateral movement. The trouble is that most organizations have no map of their own internal network — and you can't defend what you can't see behind the firewall.
In plain terms: Internal ASM works from inside your network, so it's not agentless the way External ASM is. You deploy one or more lightweight collectors — small, safe agents — inside your environment. They quietly map what's actually there and report it back to the same Helios dashboard as the rest of the platform. Add more collectors to cover more offices, data centers, or segments.
What Helios Internal ASM Covers
The same outside-in discipline of attack surface management — pointed at the half of your surface that lives behind the firewall.
Every device, server, and workstation the collectors can see on your internal network — inventoried automatically.
What each machine is actually running, and on which ports — so nothing is left as an unknown.
Deploy collectors across offices, data centers, and network segments — and see coverage for every site in one place.
The killers attackers count on — EternalBlue, BlueKeep, SMBv1, and plaintext Telnet — surfaced the moment a collector sees them.
Every finding is tied automatically to the public vulnerability (CVE) that explains it — so your team knows exactly what it is.
The paths a single compromised machine opens up — the flat, unpatched routes attackers use to spread across your network.
Findings ranked Critical and High first, so your team fixes the handful of issues that actually turn an incident into a disaster.
Services that send logins in the clear — like Telnet — so anyone already inside can read the password as it goes by.
Forgotten devices, a contractor's laptop, a server spun up "just for testing" — the unmanaged assets nobody put on the list.
Networks change every day. Collectors rescan on a continuous cycle so the internal map stays honest instead of going stale.
The findings attackers are counting on
None of these ever show up on an external scan — they live inside the network. But to an attacker who's already in, they're the difference between being stuck on one machine and owning the whole environment. Internal ASM finds them first, labels each Critical or High, and correlates it to the known CVE.
The wormable flaw behind WannaCry. Still alive on unpatched legacy systems years later — and enough to spread ransomware machine-to-machine on its own.
A "wormable" Remote Desktop vulnerability that lets an attacker take over a machine with no password at all.
An ancient file-sharing protocol that should have been retired long ago — a favorite highway for ransomware spreading from machine to machine.
Logins sent across the network with no encryption, so anyone already inside can simply read the password as it goes by.
How It Works
Deploy once, discover everything, and keep the map current — with findings routed into the tools your team already uses.
Drop one or more small, safe collectors inside your environment. Add more to cover additional offices, data centers, or network segments.
Collectors quietly map every device, server, and workstation they can see, along with the services and ports each one is running — and report it all to the Helios dashboard.
Dangerous, exploitable problems are surfaced, tied automatically to the public CVE that explains them, and ranked Critical or High first.
The internal map is refreshed on a continuous cycle, and findings are pushed into Jira, ServiceNow, Splunk, Slack, Teams, or any webhook.
Two Ways to Run It
Same platform, same coverage — choose how much you want to operate yourself. In both, the collectors are lightweight and safe.
Run it yourself
Deploy your own collectors, then work directly in the Helios dashboard. Configure sites, review internal findings, and export reports. Full RBAC and unlimited users. Ideal for in-house security teams that want hands-on control.
We monitor for you
Our team triages internal findings and escalates only what matters. Monthly executive briefings, a direct line to security analysts, and quarterly business reviews. Ideal for organizations without a dedicated cybersecurity team.
Built to Fit Your Stack
Findings go where your team already works — no parallel inbox to babysit.
One picture, four modules
Internal ASM is one of the four modules of Helios by Isaphia — the unified exposure-management platform.
An attack is rarely a single event — it's a chain. A leaked password surfaced by CTI, used against an exposed login portal found by External ASM, gives an attacker a foothold. From there they pivot across a flat, unpatched internal network — the ground Internal ASM maps — while CSPM covers the cloud side of the same surface. Seeing only one link leaves you guessing about the rest; seeing all four in one dashboard is what lets you break the chain before it reaches anything that matters.
Frequently Asked Questions
Plain-English answers to the questions we hear most often.
What is Internal ASM, in plain English?
It's the module of Helios by Isaphia that maps the inside of your network the way an attacker would once they're past the firewall. It shows you every device and server on your internal network, what each one is running, and the dangerous legacy weaknesses attackers use to spread from one machine to the next — each tied to the known vulnerability (CVE) that explains it.
Do I need to install anything?
Yes. Unlike External ASM, which is fully agentless, Internal ASM works from inside your network — so you deploy one or more lightweight collectors: small, safe agents that quietly map what's there and report back to the same Helios dashboard. A collector observes its network segment rather than touching every machine, and you add more collectors to cover more offices, data centers, or segments.
What does it find?
Four things: assets (every device, server, and workstation the collectors can see), services (what each machine is running and on which ports), coverage (which sites and segments your collectors reach), and findings — the dangerous problems attackers count on, such as EternalBlue (MS17-010), BlueKeep (CVE-2019-0708), SMBv1 still enabled, and plaintext services like Telnet. Every finding is ranked by severity and tied automatically to its public CVE.
How is this different from External ASM?
External ASM looks at your organization from the outside-in — the attacker's way in — and is fully agentless. Internal ASM looks at what's reachable once an attacker is already inside — the attacker's way around — and uses lightweight collectors to see behind the firewall. The legacy weaknesses that enable lateral movement never appear on an external scan, because they live inside the network.
Is it part of the same platform?
Yes. Internal ASM is one of the four modules of Helios by Isaphia, alongside External ASM, CTI, and CSPM. Findings from every module land in the same Helios dashboard, so you can follow an attack across the whole chain instead of stitching together separate tools.
Who is it for?
Any organization with an internal network — multiple offices, data centers, or segments — that has no reliable map of what's actually running inside it. You do not need a dedicated cybersecurity team; many customers choose the Managed Service so the Isaphia team triages internal findings for them.
How does pricing work?
Pricing scales with the size of your internal environment — the number of assets, sites, and collectors — and whether you choose Self-Service SaaS or the Managed Service. Users are unlimited within your tenant, with no per-seat fees. Contact us for a scoped quote.
Assume the perimeter will be breached
Modern security planning doesn't assume the firewall holds — it asks how far an attacker gets once they're in. Internal ASM answers that with evidence instead of hope. Get a walkthrough scoped to your environment.
Talk to Us About Helios Internal ASM