Skip to content

Assets ​

The Assets tab displays all hosts and subdomains discovered on your attack surface. Each asset is enriched with probe data collected automatically during EASM scans.

EASM assets list

Screenshots use fictional demonstration data.

Asset List ​

Assets are displayed in a paginated table:

ColumnDescription
AssetThe hostname, IP address, or domain
TypeDomain, IP, wildcard, or CIDR
TitleHTML page title extracted during probing
Status CodeHTTP response status code (200, 301, 403, etc.)
TechnologiesDetected technologies via Wappalyzer (frameworks, CMS, libraries, languages)
Web ServerWeb server software (nginx, Apache, Cloudflare, etc.)
CDNCDN provider detected, if any
AvailabilityWhether the asset is currently reachable

Probe Data ​

Every web-facing asset is automatically probed using HTTPX. The probe collects:

  • HTTP status code and response headers
  • Page title extracted from the HTML
  • Content length and body hash (for change detection)
  • Favicon hash for identifying known applications
  • JARM hash (TLS fingerprint for server identification)
  • Technologies via Wappalyzer
  • Web server identification from response headers
  • CDN detection
  • IP addresses resolved for the hostname
  • Word and line count (basic content metrics)
  • Screenshots via headless browser

Screenshots ​

Hashiro captures a screenshot of every web asset during probing. Screenshots appear as thumbnails in the asset list and can be viewed full-size in the asset detail view. They help you quickly identify login pages, API endpoints, default server pages, or applications.

Filter assets by:

  • Search: free-text search across asset names
  • Type: domain, IP, wildcard, CIDR
  • Availability: available or unavailable assets
  • Scope: in-scope or out-of-scope

Actions ​

  • Copy to clipboard: copy asset names for use in external tools
  • Delete: remove assets from the inventory
  • Download: export the asset list as PDF or CSV
  • Restart probe: trigger a re-probe of selected assets to refresh metadata

Asset Detail ​

Click an asset to open its detail view:

  • Full screenshot preview
  • Complete HTTP response details (headers, status, content)
  • Technology stack breakdown
  • IP address resolution
  • Associated URL paths
  • Associated services (ports)
  • Related issues found on this asset

Asset detail view

TIP

Assets are automatically re-probed on each scan cycle. You can also manually trigger a re-probe for specific assets to get fresh data immediately.

Hashiro. Continuous Threat Exposure Management.