Scan Settings
The control centre for scanning — runs, schedules, and collection toggles
The control centre for scanning. Three tabs, plus the Run Scan Now button in the header.
Run Scan Now
Choose a scan type and launch immediately:
- Asset Discovery — discover subdomains, IPs, and certificates.
- Security Scan — DNS, HTTP alive, SSL/TLS, port scan, and everything else enabled in Settings.
The run appears in the Scan Runs tab straight away.
Scan Runs tab
Monitor every scan: summary cards for Running / Queued / Completed / Failed (click to filter), a refreshable list with scan type, status, start time, live duration for in-progress runs, and source (manual ▶ or scheduled 📅). Click a run for its details.
Schedules tab
Automate scanning. Create schedules with:
- Scan Type — Asset Discovery or Security Scan.
- Frequency — Daily / Weekly (pick a day) / Monthly.
- Time of Day (IST).
Schedules can be edited, disabled, or deleted at any time. The next scheduled run also shows on the Dashboard.
Settings tab
Fine-grained toggles for what each scan actually does. Enable a group with its master switch, then pick individual checks, and click Save Settings.
Discovery Options (Asset Discovery scan): Similar Domain Discovery, Subdomain Enumeration, DNS Resolution, IP Resolution, and more.
Scan Types (Security Scan): DNS Resolves, HTTP Alive, Ping Alive, Port Scanning, SSL/TLS Checks, HTTP Security Headers, Technology Fingerprint, and the Attack Surface collectors below. (Vulnerability Scanning is a Pro feature.)
Several toggles directly power the Attack Surface pages:
| Toggle | Feeds |
|---|---|
| WHOIS Lookup | Attack Surface → WHOIS |
| DNS Records | Attack Surface → DNS |
| SSL/TLS Checks | Attack Surface → Certificates (served cert) |
| Certificate Transparency | Attack Surface → Certificates (CT history) |
| Infrastructure | Attack Surface → Infrastructure |
| Port Scanning | Attack Surface → Services |
| HTTP Alive / Security Headers / Technology Fingerprint | Attack Surface → Web |
| Email Security | Attack Surface → Email |
Subdomains come from the Asset Discovery scan rather than a toggle.
After changing toggles, run a Security Scan — settings control what future scans collect, they don't backfill.