Platform

What is Discovery?

Discovery is Hunto's outside-in investigation tool. You give it a target, such as your company domain, and it runs a set of checks against public sources to find what an outsider can see and use. You can run it once, or repeat it on a schedule.

What Discovery finds

Area Examples of what it looks for
Attack surface Subdomains, hosts, IP addresses, open services, certificates, technologies, and weaknesses on them
Email and DNS security Whether someone can send mail as your domain (SPF, DKIM and DMARC policy), and DNS hygiene
Brand abuse Lookalike domains, phishing pages, impersonation, exposed code
Leaks Credentials in breaches, stealer logs and leak dumps, and other exposed data
Rating A grade for the domain, computed the way a vendor assessment would see it

What runs depends on the detective you pick. See Detectives.

Who uses it, and for what

  • Security teams map the attack surface, watch for brand abuse and turn findings into detections and tasks.
  • Risk and compliance owners watch a rating over time and report on it.
  • Vendor-risk owners run the passive Outside-in rating on a supplier's domain to see how it looks from outside.
  • Onboarding teams start with a baseline of a new domain.

What Discovery does not do

  • It does not install anything on your systems. It looks from the outside.
  • It does not connect to a target you do not own. Checks that do so are refused on other people's domains.
  • It does not decide for you what is a real threat. Findings arrive as potential detections and you accept or dismiss them.
  • It does not treat "could not look" as "all clear". Areas that could not be measured are shown as Not measured.

Discovery, detections and your score

Discovery produces findings. A finding starts as a potential detection. When you accept it, it becomes a detection, which is the record you work: assign it, track it to closure and include it in reports.

A domain's rating is separate. It is computed from the run itself and feeds your security score. Accepting or dismissing a finding does not change the rating of the run it came from.

See Findings, potential detections and triage.

What you need

  • Access to Discoveries in the menu. If you see an activation message, ask your Hunto contact to enable it.
  • Credits. Each run uses credits and the price is shown before you start. See Credits and limits for Discovery.
  • To see the Detectives tab and pick individual checks, your role needs the flow library permission. Ask your workspace admin.

Where to go next

  1. Run a discovery to try it on your own domain.
  2. Read a discovery run report to understand the result.
  3. Schedules and repeating discoveries to keep it running.

Use cases and wiring tips

  • Onboard a domain baseline. Run Outside-in rating on each domain you own. Rate new domains as you add them. Automatic rating of newly added root domains is on by default and each rating uses credits. Your admin can turn it off in the scoring sharing settings.
  • Weekly brand-abuse sweep. Run Brand & leaks weekly and review the new potential detections.
  • Vendor check. Run Outside-in rating on a supplier. It only reads public sources.
  • Wiring. Assets provide the targets. Detections, tasks and reports take the findings. The security score takes the rating. For the full picture see Discovery use cases and wiring tips.