Skip to main content

Asset Discovery

Organizations: Automatically discover and track your external assets with Asset Discovery

Updated today

Asset Discovery identifies externally accessible infrastructure and enriches it with metadata. You can use Asset Discovery to maintain a more complete and up-to-date inventory without relying on manual tracking.

It discovers:

  • Subdomains, including multi-level subdomains

  • Open ports and associated protocols

  • Detected technologies such as servers, frameworks, and cloud providers

  • HTTP and HTTPS service details, including SSL/TLS metadata

Scans run on a fixed weekly schedule. After each scan, results are validated, deduplicated, and used to create or update assets in your inventory.

Asset Discovery is available to customers with CTEM platform entitlement.

Permissions

Action

Permission

View Discovery

Any organization member

Enable or disable scanners

Assets Manager (organization-level)

To check permissions, go to Organization settings → Members → Your account.

Get Started

Add a Root Domain

  1. Go to Assets → Inventory.

  2. Click Add Asset → Create new → Domain.

  3. Enter a root domain (for example, example.com).

    • Use root domains only.

    • Do not enter subdomains such as api.example.com.

  4. Complete the required fields, then click Save.

Enable Asset Discovery

  1. Go to Assets → Discovery.

  2. Find your domain in the list.

  3. Turn on Scanner enabled.

Scanning runs automatically on a weekly schedule and adds any discovered assets to your asset inventory.

Use Asset Discovery

View Domains and Scan Status

The Discovery table shows one row per root domain.

  • Domain: The root domain being scanned

  • Assets discovered (cumulative): Total number of assets created or updated by the scanner

  • Last scan: When the scanner last ran

  • Last scan status: Success, Failed, or Pending

    • Tip: Use Last scan status to quickly identify failed or incomplete scans.

  • Scanner enabled: Whether scanning is active

Enable or Disable Scanning

To enable scanning:

  1. Find the domain in Assets → Discovery.

  2. Turn on Scanner enabled.

To disable scanning:

  1. Find the domain.

  2. Turn off Scanner enabled.

When scanning is disabled, no new data is collected. Existing assets remain in your inventory.

View Discovered Assets

  1. Go to Assets → Inventory.

  2. Apply the following filters:

    • discovery_source: asset_discovery

    • scanner_domain: <your domain>

  3. Select an asset to view details such as ports, technologies, and timestamps.

You can also filter by:

  • scanner_ports or protocol

  • technology_fingerprintHow Asset Discovery Works

Troubleshooting

Common Issues

No root domains found

Add a domain as a Domain-type asset in Assets → Inventory.

Scanner toggle unavailable

Verify that you have Assets Manager permissions.

Scanner not running

Confirm that scanning is enabled and wait for the next weekly run. Check the status page if needed.

No assets discovered

Verify that the domain is publicly accessible and not blocked by DNS or firewall restrictions.

If issues persist, submit a ticket at support.hackerone.com.

FAQs

Is the scanning intrusive?

No. Asset Discovery uses passive techniques and light port scanning. It does not attempt exploitation.

Where is the data stored?

Data is stored within HackerOne infrastructure and is visible only to your organization.

Can I export discovered assets?

Yes. You can export data from Asset Inventory as CSV or via the HackerOne API.

Can I delete assets?

Assets cannot be deleted, but you can archive them.

Did this answer your question?