Application Security Platform
Overview

Introduction to Discovery

This document is for:
Invicti Platform

The discovery service enables you to become aware of your web assets, web applications, and online services. With this information, you can conduct a comprehensive security audit and better secure your online presence, continually reducing security threats.

This document explains how discovery service works.

Discovery overview

The discovery service works independently from Invicti Platform. As soon as you activate your Invicti license, the system begins the discovery process with the master user's email address, immediately suggesting URLs that might also belong to you. It continually scans the entire internet, and once you start adding targets, the system makes new suggestions based on those targets. Invicti also analyzes your configuration and data to then suggest further websites that might also belong to you.

The Discovery Service will show a maximum of 5000 websites.

The Discovery list

As you use Invicti, the Website discovery page builds a list of candidate websites that you might want to add to your list of targets. This list is updated every time you:

  • Add (or remove) a Target
  • Change one of the flags on the Discovery > Configuration page
  • Add an Inclusion to one of the inclusion lists (IP Addresses, Organizations, or Second Level Domains)
  • Add an Exclusion to one of the exclusion lists (IP Addresses, Organizations, Top Level Domains, or Second Level Domains)

The list of Discovered websites is updated periodically, with a maximum delay of about 1 hour.

For more information about configuring the settings used by the Discovery service, refer to the Adjust Discovery configuration document.

Share This Article