What is out of scope?
Question
Hexiosec ASM has a concept of assets being in and out of scope. What does this mean and how is it determined what's in and what's out?
Answer
Hexiosec ASM uses 'in scope' and 'out of scope' to determine the relationships back to seed domains and IP addresses. Since everything on the internet is connected, we need to ensure the results of a Hexiosec ASM scan are appropriately focussed.
'In scope' nodes, be they Domains, IP addresses, Components, etc., are connected back to one of the seed nodes via a valid path. A subdomain (or child) of a seed domain will be in scope. However, the domain of a 3rd-party script used on the seed domain's website will be 'out of scope'.
Simply put, if it is 'in scope', then Hexiosec ASM has determined that the risks associated with the asset are your responsibility. If it is out of scope, then Hexiosec ASM can't be sure it is yours, and you will need to add it as a seed to get Hexiosec ASM to inspect it further.
To view the 'out of scope' nodes, go to the 'Out of Scope' page on a scan, and you can add nodes to scope as seeds. Note, this will depend on permissions.