Skip to main content

How to scan a domain for Asset Discovery

Learn how to add a domain for Snyk API & Web’s Asset Discovery to identify assets from its attack surface.

Written by Ana Pascoal

Oftentimes, people are not aware of all the assets (web apps and APIs) their organization has, which leads them to overlook their vulnerabilities and inadvertently have them (and the organization) exposed to potential cyber-attacks. With Snyk API & Web’s Asset Discovery, you have a way of identifying your company’s assets so that you can effectively protect them before becoming a liability.

In order to scan a domain for asset discovery, you can follow these steps:

  1. Add a domain

  2. Verify the domain

This article describes these steps in detail.

Step 1: Add a domain

In the Snyk API & Web app, add a domain for asset discovery as follows:

  1. Select the Discovery menu entry.

  2. Click the Add source button to open the configuration modal.

  3. Select the Add a domain option and click Next.

  4. On the next screen, fill in the hostname and click Add.

Step 2: Verify the domain

After adding a domain, you must verify it so that the scan is complete by following the instructions on the screen. For more information, read thie article on Why do we require you to verify the ownership of a domain.

Once the domain is added and verified, Snyk API & Web will start running regular Discovery scans automatically on your account.

In the Snyk API & Web app, check the DISCOVERY tab and, once the asset discovery is finished, you should have all the newly found assets added to the list. At the top of the page, you have information on the number of newly found assets, which you can click on to filter them in the list.

Did this answer your question?