FAQs

What is out of scope?

1min

Question

Hexiosec ASM has a concept of assets being in and out of scope. What does this mean and how is it determined what's in and what's out?

Answer

Hexiosec ASM uses 'in scope' and 'out of scope' to determine the relationships back to seed domains and IP addresses. Since everything on the internet is connected, we need to ensure the results of a Hexiosec ASM scan are appropriately focussed.

Example of in scope node on the explore page of a scan.
Explore page


'In scope' nodes, be they Domains, IP addresses, Components, etc., are connected back to one of the seed nodes via a valid path. A subdomain (or child) of a seed domain will be in scope. However, the domain of a 3rd-party script used on the seed domain's website will be 'out of scope'.

Simply put, if it is 'in scope', then Hexiosec ASM has determined that the risks associated with the asset are your responsibility. If it is out of scope, then Hexiosec ASM can't be sure it is yours, and you will need to add it as a seed to get Hexiosec ASM to inspect it further.

To view the 'out of scope' nodes, go to the 'Out of Scope' page on a scan, and you can add nodes to scope as seeds. Note, this will depend on permissions.

Add out of scope nodes to sope as seed using the out of scope page on a sca
Out of Scope page