FAQs
What is out of scope?
1min
question hexiosec asm has a concept of assets being in and out of scope what does this mean and how is it determined what's in and what's out? answer hexiosec asm uses 'in scope' and 'out of scope' to determine the relationships back to seed domains and ip addresses since everything on the internet is connected, we need to ensure the results of a hexiosec asm scan are appropriately focussed example of in scope node on the explore page of a scan 'in scope' nodes, be they domains, ip addresses, components, etc , are connected back to one of the seed nodes via a valid path a subdomain (or child) of a seed domain will be in scope however, the domain of a 3rd party script used on the seed domain's website will be 'out of scope' simply put, if it is 'in scope', then hexiosec asm has determined that the risks associated with the asset are your responsibility if it is out of scope, then hexiosec asm can't be sure it is yours, and you will need to add it as a seed to get hexiosec asm to inspect it further to view the 'out of scope' nodes, go to the 'out of scope' page on a scan, and you can add nodes to scope as seeds note, this will depend on permissions add out of scope nodes to sope as seed using the out of scope page on a sca