The Discoveries page
Discoveries is where you start checks, see what is repeating, and open the results. Find it under Investigate in the menu.
The subtitle reads: "Check any domain, host, IP or email. Repeat it to keep it fresh."
Page header
| Control | What it does |
|---|---|
| Run discovery | Opens the run window. See Run a discovery. |
| Menu: Go to Assets | Opens your asset list. A target you keep is saved as an asset. |
| Menu: Import findings | Opens a pane to upload findings from another tool. See Import findings. |
| Menu: Refresh | Reloads the tables. |
| see them in Assets | A link in the header to the asset list. |
After you start a run, a message appears under the header with a link such as Open the run. Close it with the x.
The tabs
| Tab | Shows | Who sees it |
|---|---|---|
| Schedules (default) | Every schedule: what is being watched and how often | Everyone with access to Discoveries |
| Runs | Every run that has happened | Everyone with access to Discoveries |
| Detectives | The named sets of checks | Users with the flow library permission |
The selected tab is kept in the page address, for example #tab=runs, so you can bookmark it or share it.
Schedules tab
One row per schedule. Search with Search targets or schedule id, and narrow with the Repeat filter: Any, Repeating, Once, Daily, Weekly, Monthly.
| Column | Meaning |
|---|---|
| Target | What is being checked. "All your assets" means the schedule covers your whole asset list. |
| Checks | The detective name, for example Outside-in rating. |
| Repeat | Once, Daily, Weekly, Monthly (and Hourly on some schedules). |
| Status | Active, Inactive, Running, Completed, Completed with errors, Failed, Stuck, Paused, Timed Out or Terminated. |
| Last run | When it last ran and how many findings it produced, or Not run yet. |
| Runs | How many runs it has made. |
| Next run | When it fires next: a time such as "in 24h", Overdue, Due now, or a dash if it does not repeat. |
Select a row to open the Schedule pane. It shows the target, checks and status, the repeat, next run, run count and creation date, and the list of its runs. Select a run to open its report.
Note: A schedule may show Removed detective if the detective it used has since been retired. It keeps its history.
Runs tab
One row per run, newest first. By default it covers the last 90 days.
| Column | Meaning |
|---|---|
| Detective | The set of checks used. |
| Targets | What the run covered. |
| Status | See the status table in How a discovery run works. |
| Outcome | Findings produced, checks that worked ("N ok") and, in red, checks that failed. |
| Duration | How long the run took. |
| Started | When it began. Sortable. |
Select a row to open the run report. Select a red failure count to open it on the failures.
Create a report from runs
- Tick the finished runs you want. One report covers up to 10 runs, and they must belong to one domain.
- Select Create report (N).
- Choose Preview or Generate report.
The report is a digital risk and exposure assessment: an executive summary, where the risk is, findings by category, what changed since the last assessment, and what was checked with nothing found.
Remove a run
Workspace admins see Delete discovery, which permanently deletes the run and its findings and cannot be undone. Other users see Archive discovery, which hides it and can be restored.
Detectives tab
Shown only with the flow library permission. Columns are Detective, Kind, Checks, Takes (the target types it accepts) and Last run. Filter with Kind. Select Create your own to build one. Select a row to open its profile, which has a Run button. See Detectives.
Links into the page
Some links open the page ready to go:
| Link | Result |
|---|---|
?target=example.com |
Opens the run window with that target |
?preset= followed by lookup, asm, bp, all, email, leaks or lookalikes |
Opens the run window on that detective |
?detective= followed by a detective id |
Opens the run window on that detective |
?tab=schedules, ?tab=runs or ?tab=detectives |
Opens that tab |
Permissions
| You need | For |
|---|---|
| Access to Discoveries (the monitoring module) | The page, both main tabs and running discoveries |
| Flow library permission | The Detectives tab, and choosing individual checks |
| Active scanning permission | Checks that actively probe a target, where your plan uses it |
| Deep scanning permission | Deeper analysis checks, where your plan uses it |
| Workspace admin | Delete discovery and rating all root domains at once |
A check locked by a missing permission or plan shows Needs ... rather than being hidden.
Use cases and wiring tips
- See what is being watched. Filter Schedules by Repeating and scan the Next run column.
- Find why a schedule stopped. Look for Failed, Stuck or Timed Out in Status, then open the row.
- Share a view. Copy the address after choosing a tab.
- Wiring. Targets tie to Assets. Findings tie to the Potential Detections queue. Ratings tie to the Security Posture page.