Package: Invicti AppSec Core (on-demand)
Introduction to Website discovery
Invicti AppSec Core's Website discovery service automatically identifies web assets associated with your organization. It continuously scans the internet and surfaces URLs that may belong to you - including assets you haven't added to your Targets list yet.
This document explains how Website discovery works, what limits apply to the discovery list, and when the list updates.
Why this matters
Organizations often have more web assets than they're aware of - subdomains, legacy applications, acquired properties, and third-party hosted services that aren't tracked in any central inventory. Manually keeping up with these is time-consuming and error-prone.
Website discovery automates this process. It continuously surfaces assets associated with your organization so you can review them and add relevant ones to your Targets list for scanning. This helps you close visibility gaps and maintain accurate coverage across your full attack surface - without having to track down every URL yourself.
How Website discovery works
Website discovery runs independently in the background. It seeds the scan using your organization's details and generates URL suggestions based on:
- Targets you've already added to Invicti AppSec Core
- Your discovery configuration settings
- Data associated with your organization
The suggestions appear on the Discovery > Website discovery page. You can review them, filter out irrelevant results, and convert URLs into targets for scanning.
Discovery list limits
The discovery list displays a maximum of 5000 URLs at a time. URLs beyond this limit don't appear until you remove or dismiss others from the list.
When the list updates
The discovery list updates automatically when any of the following occur:
- You add or remove a target
- You change your discovery configuration settings
- You add or remove inclusions for IP addresses, organizations, or domains
- You add or remove exclusions for IP addresses, organizations, or domains
Updates aren't instant. The list can take up to approximately one hour to reflect changes.
Need help?
Invicti Support team is ready to provide you with technical help. Go to Help Center