Scan subdomains

By default we try to crawl the subdomains that we identify under your scope, using various methods such as DNS records and attempting standard lists of common subdomains. We do this to extend the coverage of your scan as much as possible.

If there are specific subdomains that you always want us to scan, you can add these as separate scan profiles. You will find more information about how to do so further down in this article. You can adjust the subdomain preferences by clicking on your scan profile and then navigating to Application Scan Profile Settings -> Scan Settings.

Under Scan Settings, you can choose to enable or disable the scanner's ability to crawl subdomains and specify which subdomains we shouldn't include in Detectify scans.

Asset Catalogue

Clicking on one of your domains in your Asset Catalogue will bring you to the Asset Overview page. 

Go to the "Scan Profiles" tab to see all the scan profiles that have already been added for your domain.

Here you can click the profile name to access the scan overview (in the same way as in the dashboard). 

In Subdomains view, you’ll find the actual Autodiscovery feature. A list of the subdomains that we have discovered will be listed and searchable. Have a look through it to see if there are assets you wish to scan or if there are legacy assets lying around which you no longer want to be accessible to the public. Please note that the list of subdomains will only populate for verified top domains (without www.) 

To add a new profile from the auto discovered subdomains, simply click “+ scan profile” to the right:

Some of the subdomains from the list will be crawled during the scan but we can't guarantee which or that the same ones will be crawled during each scan. Therefore we recommend that you identify your most important assets and add them as separate scan profiles to ensure that they always get scanned. To see which URLs we have crawled during our scan scroll down to "Crawled URL's" in your findings (appearing in green) and navigate your way to the downloadable csv file. For additional information visit Crawled URLs in our knowledge base. For more information about why you may see inconsistencies in the crawled URLs from scan to scan, please see this article.

Some of the common subdomains we look for are:

