Asset Discovery identifies externally accessible infrastructure and enriches it with metadata. You can use Asset Discovery to maintain a more complete and up-to-date inventory without relying on manual tracking.
It discovers:
Subdomains, including multi-level subdomains
Open ports and associated protocols
Detected technologies such as servers, frameworks, and cloud providers
HTTP and HTTPS service details, including SSL/TLS metadata
Scans run on a fixed weekly schedule. After each scan, results are validated, deduplicated, and used to create or update assets in your inventory.
Asset Discovery is available to customers with CTEM platform entitlement.
Permissions
Action | Permission |
View Discovery | Any organization member |
Enable or disable scanners | Assets Manager (organization-level) |
To check permissions, go to Organization settings → Members → Your account.
Get Started
Add a Root Domain
Go to Assets → Inventory.
Click Add Asset → Create new → Domain.
Enter a root domain (for example, example.com).
Use root domains only.
Do not enter subdomains such as api.example.com.
Complete the required fields, then click Save.
Enable Asset Discovery
Go to Assets → Discovery.
Find your domain in the list.
Turn on Scanner enabled.
Scanning runs automatically on a weekly schedule and adds any discovered assets to your asset inventory.
Use Asset Discovery
View Domains and Scan Status
The Discovery table shows one row per root domain.
Domain: The root domain being scanned
Assets discovered (cumulative): Total number of assets created or updated by the scanner
Last scan: When the scanner last ran
Last scan status: Success, Failed, or Pending
Tip: Use Last scan status to quickly identify failed or incomplete scans.
Scanner enabled: Whether scanning is active
Enable or Disable Scanning
To enable scanning:
Find the domain in Assets → Discovery.
Turn on Scanner enabled.
To disable scanning:
Find the domain.
Turn off Scanner enabled.
When scanning is disabled, no new data is collected. Existing assets remain in your inventory.
View Discovered Assets
Go to Assets → Inventory.
Apply the following filters:
discovery_source: asset_discovery
scanner_domain: <your domain>
Select an asset to view details such as ports, technologies, and timestamps.
You can also filter by:
scanner_ports or protocol
technology_fingerprintHow Asset Discovery Works
Troubleshooting
Common Issues
No root domains found
Add a domain as a Domain-type asset in Assets → Inventory.
Scanner toggle unavailable
Verify that you have Assets Manager permissions.
Scanner not running
Confirm that scanning is enabled and wait for the next weekly run. Check the status page if needed.
No assets discovered
Verify that the domain is publicly accessible and not blocked by DNS or firewall restrictions.
If issues persist, submit a ticket at support.hackerone.com.
FAQs
Is the scanning intrusive?
No. Asset Discovery uses passive techniques and light port scanning. It does not attempt exploitation.
Where is the data stored?
Data is stored within HackerOne infrastructure and is visible only to your organization.
Can I export discovered assets?
Yes. You can export data from Asset Inventory as CSV or via the HackerOne API.
Can I delete assets?
Assets cannot be deleted, but you can archive them.
