Auto-EASM Activation
Managing protection settings for a large number of assets can be time-consuming, especially when new assets are created frequently. Auto-EASM helps simplify this workflow by automatically applying EASM protection to eligible assets as they are created.
🔩 How the setting works :
You can find this new setting in your Organization → Settings space, inside of Configurations appears a new Protection options menu.
When the setting is enabled, newly created assets are automatically assigned the protection level EASM instead of the default unprotected, provided that the organization still has available EASM credits.
This behavior applies to assets created by the members of your organization or discovered by Patrowl.
If the setting is disabled, asset protection remains fully manual.
ℹ️ Functional Rules
No credits available
If the organization has no remaining EASM credits, new assets stay unprotected.
If new EASM credits are added afterward, the system automatically upgrades the oldest unprotected assets to EASM.
During bulk imports or API batch creation, assets are assigned EASM until the credit limit is reached.
Protection lifecycle
Once an asset is set to EASM, protection cannot be disabled (standard EASM rule). When an asset is deleted, the consumed credit is freed.
Users may still upgrade protection to pentested.
📨 Notifications
To ensure visibility on credit usage when Auto-EASM is enabled:
An alert banner appears at 95% and 100% credit usage.
Email notifications are sent to organization admins at 95% and 100% credit consumption.
Feature Improvements
Assets : Bulk pentest desactivation is available again.
Asset groups - vulnerabilities : Bulk actions on vulnerabilities within an asset group are now supported.
CVE : The vendor name now appears in the product filter for clearer identification.
Design Improvements
Asset - IP : The IP type label has been refined from “Other” to “Other dynamic” for better consistency.
Tables : All empty-state messages have been reviewed and harmonized.
Date fields : The design of date inputs has been aligned for better visual consistency.
Bug Fixes
Asset - Risk insight : Removed an unnecessary asset filter from this tab.
Asset : The number of related domains and IPs displayed in the main information block has been corrected.
Technical Improvements
Upgraded Django to 4.2.26 (includes CVE-2025-64459, even though the application was not affected).



