HailBytes ASM vs Mandiant ASM
A self-hosted EASM alternative for teams that want continuous external recon without committing to the Mandiant Advantage / Google Cloud Security stack.
TL;DR
Mandiant Attack Surface Management (the rebranded Intrigue acquisition, now sold under Google Cloud Security) layers external discovery onto Mandiant’s threat-intel and incident-response heritage. HailBytes ASM is a self-hosted alternative that runs the recon pipeline inside your own AWS or Azure account, priced on infrastructure rather than as a Mandiant Advantage module.
- Pick HailBytes ASM if you don’t want a Mandiant Advantage / Google Cloud commitment, need white-label client deliverables, or want unlimited scans at flat VM cost.
- Stay with Mandiant ASM if you’re standardized on Mandiant Threat Intelligence / Chronicle and want EASM correlated with adversary-tracking data inside the same platform.
Pricing & Cost Model
| Dimension | HailBytes ASM | Mandiant ASM |
|---|---|---|
| Pricing axis | Infrastructure ($0.24/vCPU/hour) | Per asset / Mandiant Advantage subscription tier |
| Annual cost (small surface) | $5,880 (4 vCPU, ASM’s documented minimum; $8,400 list), all-in $8,520 committed and $11,040 at list | ~$25,000+ (Advantage floor) |
| Annual cost (mid surface) | $11,760–$23,520 (8–16 vCPU; $16,800–$33,600 list) | $60,000–$150,000 |
| Standalone purchase | ✅ | 🟡 Often bundled with Mandiant TI |
| Free trial | 30 days via AWS / Azure Marketplace | Sales-led demo |
| Procurement path | Cloud marketplace (counts toward EDP / MACC) | Direct Google Cloud / Mandiant contract |
HailBytes figures are the 1-year commitment price (delivered as an AWS or Azure private offer, not a discount on the published meter) with list alongside, so the comparison sits on the same annual-contract basis as the competitor column. The meter covers software only; the VM, storage, and networking run in your own cloud account and are billed separately at roughly $35/vCPU/month, $220/month at 4 vCPU, $280 at 8, $560 at 16, and $1,120 at 32, so scale that line to the size on the row you are reading.
Our cost steps with the size of the surface rather than scaling per asset, so every comparison on this page is calculated all-in against the rung that fits. 4 vCPU is ASM’s documented minimum and suits a small, stable surface (about $8,520/year all-in on a 1-year commitment, $11,040 at list). 8 vCPU is the size ASM’s own hardening guide names Production (recommended) and covers 10 to 50 scheduled scans a day ($15,120 / $20,160). 16 vCPU covers 50+ scans a day ($30,240 / $40,320). Quote 4 vCPU only where the surface genuinely is small and stable; 8 vCPU is the size we recommend for production. Full pricing.
Sizing above 8 vCPU: ASM sizes its scan worker from the host, so a larger instance scans proportionally faster: a 16 vCPU deployment gives the scan engine twice the cores an 8 vCPU one does. Instances deployed before August 2026 pick this up on the next update, when the installer rewrites the worker limits to match the machine.
Architecture & Control
| Dimension | HailBytes ASM | Mandiant ASM |
|---|---|---|
| Deployment | Self-hosted in your AWS / Azure account | SaaS (Google Cloud-hosted) |
| Source code access | Ships with the deployment; auditable under NDA | Closed source |
| Cloud freedom | AWS, Azure, GovCloud, Azure Gov | Google Cloud-resident |
| Custom scan logic / wordlists | ✅ Full control | 🟡 Module-level |
| Per-tenant isolation | One VM per tenant | Multi-tenant SaaS |
Capability Comparison
| Capability | HailBytes ASM | Mandiant ASM |
|---|---|---|
| Subdomain enumeration | ✅ Multi-source | ✅ (Intrigue heritage) |
| Active port & service scanning | ✅ Built-in | ✅ |
| CVE matching | ✅ | ✅ |
| Adversary infrastructure / threat-intel pivots | ❌ | ✅ Mandiant TI is the moat |
| Chronicle / SecOps correlation | 🟡 Bring your own SIEM | ✅ Native |
| Unlimited scans | ✅ | 🟡 Tier-based |
| Custom wordlists | ✅ Unlimited | ❌ |
| AI-powered analysis | ✅ OpenAI + Ollama (local GPU) | ✅ Gemini-powered |
| MCP server / AI-agent tooling | ✅ Built-in (Claude / Cursor / Windsurf) | ❌ |
| SIEM integration | ✅ Splunk, Sentinel, Elastic, Chronicle | ✅ Chronicle-first |
| Government cloud (GovCloud / Azure Gov) | ✅ Both | 🟡 Google Cloud Gov |
| White-label for client deliverables | ✅ Built-in | ❌ |
See It in the Product
Mandiant ASM is delivered as a service. These are the operator-facing screens you get when the platform is yours.
Captured from a running instance. See all 48 screens →
When HailBytes ASM Wins
- You don’t want a Mandiant Advantage / Google Cloud commitment. Mandiant ASM’s real value is correlation with Mandiant TI and Chronicle; standalone, the math is hard.
- MSSPs and pen-test firms. White-label deliverables and per-instance cost make resold continuous monitoring viable.
- AWS-first or multi-cloud orgs. Mandiant ASM lives inside Google Cloud; HailBytes runs anywhere.
- AI-agent recon workflows. The built-in MCP server lets Claude, Cursor, and Windsurf drive scans and triage findings.
When Mandiant ASM Wins
- You’re a Mandiant TI customer. Adversary-infrastructure pivots from Mandiant’s frontline-incident corpus is a real differentiator pure recon-tooling can’t match.
- Chronicle / Google SecOps shops. Native correlation across ASM and SIEM data is a meaningful win.
- Existing Google Cloud / Mandiant contract spend that absorbs the ASM module at marginal cost.
Try HailBytes ASM
30-day free trial through AWS Marketplace and Azure Marketplace, including the underlying VM.
See HailBytes ASM in Action
Skip the slide deck. Watch the product run end-to-end before you book a call.
Try HailBytes ASM Free
Get a free trial deployment on AWS or Azure. Our team walks you through setup and your first steps, whether that’s a single organization or a multi-client rollout.
- ✓ 30-day free trial on AWS or Azure
- ✓ Guided onboarding from our security team
- ✓ No credit card required to start
- ✓ 40+ security tools pre-configured

