Discovery

The Discoveries page

Discoveries is where you start checks, see what is repeating, and open the results. Find it under Investigate in the menu.

The subtitle reads: "Check any domain, host, IP or email. Repeat it to keep it fresh."

Control What it does
Run discovery Opens the run window. See Run a discovery.
Menu: Go to Assets Opens your asset list. A target you keep is saved as an asset.
Menu: Import findings Opens a pane to upload findings from another tool. See Import findings.
Menu: Refresh Reloads the tables.
see them in Assets A link in the header to the asset list.

After you start a run, a message appears under the header with a link such as Open the run. Close it with the x.

The tabs

Tab Shows Who sees it
Schedules (default) Every schedule: what is being watched and how often Everyone with access to Discoveries
Runs Every run that has happened Everyone with access to Discoveries
Detectives The named sets of checks Users with the flow library permission

The selected tab is kept in the page address, for example #tab=runs, so you can bookmark it or share it.

Schedules tab

One row per schedule. Search with Search targets or schedule id, and narrow with the Repeat filter: Any, Repeating, Once, Daily, Weekly, Monthly.

Column Meaning
Target What is being checked. "All your assets" means the schedule covers your whole asset list.
Checks The detective name, for example Outside-in rating.
Repeat Once, Daily, Weekly, Monthly (and Hourly on some schedules).
Status Active, Inactive, Running, Completed, Completed with errors, Failed, Stuck, Paused, Timed Out or Terminated.
Last run When it last ran and how many findings it produced, or Not run yet.
Runs How many runs it has made.
Next run When it fires next: a time such as "in 24h", Overdue, Due now, or a dash if it does not repeat.

Select a row to open the Schedule pane. It shows the target, checks and status, the repeat, next run, run count and creation date, and the list of its runs. Select a run to open its report.

Note: A schedule may show Removed detective if the detective it used has since been retired. It keeps its history.

Runs tab

One row per run, newest first. By default it covers the last 90 days.

Column Meaning
Detective The set of checks used.
Targets What the run covered.
Status See the status table in How a discovery run works.
Outcome Findings produced, checks that worked ("N ok") and, in red, checks that failed.
Duration How long the run took.
Started When it began. Sortable.

Select a row to open the run report. Select a red failure count to open it on the failures.

Create a report from runs

  1. Tick the finished runs you want. One report covers up to 10 runs, and they must belong to one domain.
  2. Select Create report (N).
  3. Choose Preview or Generate report.

The report is a digital risk and exposure assessment: an executive summary, where the risk is, findings by category, what changed since the last assessment, and what was checked with nothing found.

Remove a run

Workspace admins see Delete discovery, which permanently deletes the run and its findings and cannot be undone. Other users see Archive discovery, which hides it and can be restored.

Detectives tab

Shown only with the flow library permission. Columns are Detective, Kind, Checks, Takes (the target types it accepts) and Last run. Filter with Kind. Select Create your own to build one. Select a row to open its profile, which has a Run button. See Detectives.

Some links open the page ready to go:

Link Result
?target=example.com Opens the run window with that target
?preset= followed by lookup, asm, bp, all, email, leaks or lookalikes Opens the run window on that detective
?detective= followed by a detective id Opens the run window on that detective
?tab=schedules, ?tab=runs or ?tab=detectives Opens that tab

Permissions

You need For
Access to Discoveries (the monitoring module) The page, both main tabs and running discoveries
Flow library permission The Detectives tab, and choosing individual checks
Active scanning permission Checks that actively probe a target, where your plan uses it
Deep scanning permission Deeper analysis checks, where your plan uses it
Workspace admin Delete discovery and rating all root domains at once

A check locked by a missing permission or plan shows Needs ... rather than being hidden.

Use cases and wiring tips

  • See what is being watched. Filter Schedules by Repeating and scan the Next run column.
  • Find why a schedule stopped. Look for Failed, Stuck or Timed Out in Status, then open the row.
  • Share a view. Copy the address after choosing a tab.
  • Wiring. Targets tie to Assets. Findings tie to the Potential Detections queue. Ratings tie to the Security Posture page.