Managing Domains and IPs
Primary and secondary assets
Hexiosec ASM uses 'primary' and 'secondary' to describe the relationships back to seed domains and IP addresses. Since everything on the internet is connected, we need to ensure the results of a Hexiosec ASM scan are appropriately focussed.

A domain (or IP) will be a 'primary' asset if it is connected back to one of the seed nodes via a valid path. A subdomain (or child) of a seed domain will be a 'primary' asset. However, the domain of a 3rd-party service aliased (DNS CNAME'd) from a primary domain, or a subdomain for a different website found in a certificate would both be 'secondary' assets.
For example, if an organisation uses Microsoft for emails it would have an 'autodiscover' subdomain such as 'autodiscover.example.com', which has an alias to 'autodiscover.outlook.com'. Hexiosec ASM would mark these domains as:
- 'autodiscover.example.com' - Primary
- 'autodiscover.outlook.com' - Secondary
If an asset is 'primary', Hexiosec ASM has determined that the risks associated with the asset are directly related to the seeds domains and IPs. If an asset is 'secondary' then Hexiosec ASM will still include the asset as it is key to understanding deployments and interconnected services, but risks will not be shown against this asset. You can choose to add secondary assets as seeds to get Hexiosec ASM to inspect them further.
To view the secondary assets, click on 'Secondary' on the left menu, under 'Asset Management'. From there, you can add a secondary asset as a seed, or unmark assets that have previously been marked as secondary. Note, this will depend on user permissions.
CSV file export
To enable you to extract information related to 'primary' domains found in a scan, including DNS data, risks, ASNs, cloud hosting and certificates, Hexiosec ASM provides an export button on the Domains page. The same functionality is available for the IP Addresses page.
Data is exported as a CSV (comma separated values) file, which uses , as the cell separator. The file includes an initial heading row.
The exported data will match the data you currently have filtered in the app. To export a selection of the domains, e.g. domains related to a certain ASN, simply apply the filter before using the export button.
For domains, the generated CSV file outputs the following columns:
- id: "<domain_id>"
- the domain ID
- domain: "<domain>"
- the domain name
- stale: "<yes|no>"
- if the domain is stale (see Report Terminology)
- name_server: "<yes|no>"
- if the domain is a DNS name server
- seed: "<yes|no>"
- if the domain is a seed
- dns_destination: "<ip|domain>,<ip|domain>,..."
- [0 or more values] either:
- IP addresses for DNS A records associated with the domain
- domains for DNS CNAMEs associated with the domain
- services: "<domain:port>,<domain:port>,..."
- [0 or more values] services on the domain
- certificates: "<certificate>,<certificate>,..."
- [0 or more values] certificates used by the domain
- cloud_regions: "<cloud_region>,<cloud_region>,..."
- [0 or more values] cloud regions for any associated cloud providers
- asns: "<asn>,<asn>,..."
- [0 or more values] ASN (autonomous system number) network names
- entities: "<entity>|<entity>,..."
- [0 or more values] names of entities responsible for the ASNs
- critical_risks: "<risk_count>"
- count of critical risks associated with the domain
- high_risks: "<risk_count>"
- count of high risks associated with the domain
- medium_risks: "<risk_count>"
- count of medium risks associated with the domain
- low_risks: "<risk_count>"
- count of low risks associated with the domain