Guide to 2026 ASM Web Scanning Update
In September 2026, the scanning architecture in Censys Attack Surface Management (ASM) will be upgraded to ensure consistency with the broader Censys Platform. This is part of Censys's broader initiative to bring ASM closer to the Platform experience. As part of this migration, you will see reduced false positive host counts and increased web entity counts due to the scanning improvements.
This change will also enable Censys to quickly deploy several important features to ASM over the coming months. These features include:
- Web screenshots
- Full redirect paths
- JavaScript library fingerprints
- JavaScript risks
This effort is part of the Censys plan to upgrade services to use new components of the Censys Internet Map that underlie the Censys Platform to provide a more consistent experience across all Censys applications and accelerate the migration of ASM functionality to the Censys Platform.
This document explains the changes and how they will impact ASM users.
Asset count changes
This architecture update will reduce some noise and redundancy in your attack surface. Rather than displaying every historical IP resolution in ASM, Censys will only show the most recent, active resolution in ASM.
In addition, this change removes some false-positive hosts that were previously present in your attack surface inventory. These false-positive hosts in ASM were due to bare IPs to persisting in an attack surface even if they were not seen in the last 24 hours. As a result of the fixes that a part of this migration, you can expect to see between a 2 to 15% drop in host counts in your inventory.
This migration will also lead to an increase in web entity counts. This is because the new scanning infrastructure relies on ActiveDNS resolution, which is able to detect and confirm a greater number of web entities in your attack surface. As a result, you can expect to see between a 0 to 10% increase in web entity counts.
Web entity instance and risk counts
After this migration, you will see a reduction in the number of web entity instances for each web entity asset in your inventory.
After this change, web entities will have a maximum of one instance. As there will be a maximum of one instance on each web entity, you will see a corresponding decrease in the overall number of risks in your inventory. This is due to the reduction in the overall instance count and not indicative of a reduced risk profile.
For example, prior to this change, the web entity docs.censys.com:443 could have multiple instances listed on its asset page. These instances represent recent and historical resolutions to IP addresses for the web entity. After the change, docs.censys.com:443 will have a maximum of one instance based on the IP address that it most recently resolved to. This is more aligned with how web properties are represented in the Censys Platform.
Data impact
No data fields are being deprecated and no fields are changing their name as a result of this change. Any saved queries you have that target web entities will continue to function. However, certain web entity fields, like web_entity.instance_count, will have significantly reduced values. No new fields are being introduced as part of this change.
How this change improves ASM
Censys plans to rapidly release several new features that depend on this change to web scanning. These features include:
-
Web screenshots
- Censys will automatically capture screenshots for every web entity in your inventory.
- Screenshots will feature exact timestamps on each capture, building a historical view of the page over time.
- These screenshots empower you to identify exposed assets like login pages and admin panels, as well as potentially compromised infrastructure, much quicker.
-
Full redirect paths
- Comprehensive redirect chains identify whether a website has been taken over by an attacker, or redirects to the user the incorrect destination.
-
JavaScript library fingerprints
- Track JavaScript libraries and web components using a large number of software fingerprints to surfaces unknown or unauthorized dependencies that can introduce risk to your web assets.
-
JavaScript risks
- Prevent exploitation by detecting and remediating web vulnerabilities, including those on EOL libraries. Respond to JS-related incidents, like React2Shell, with greater accuracy with expanded rapid response.
Additionally, this change provides greater parity between how web services are represented in ASM and how web services are represented in the Censys Platform, in the short term making it easier to pivot between the two and in the long term a smoother deployment of ASM on the Platform frontend. The risk and asset reduction also removes duplicates that previously existed on the same web entity. This ensures cleaner and less noisy data.
