Skip to content

Scope Management ​

Scope defines the boundaries of a security assessment: what is authorized to test and what is off-limits. A well-defined scope is the foundation for asset discovery, vulnerability scanning, and manual testing.

Scope configuration panel

Screenshots use fictional demonstration data.

Defining Scope ​

Every project has two scope lists:

  • In-scope: targets authorized for testing
  • Out-of-scope: targets that must not be tested, even if discovered during enumeration

Scope entries are validated on creation to ensure they match the expected format for their asset type.

Asset Types ​

TypeExampleDescription
Wildcard*.example.comAll subdomains under a domain
Domainapp.example.comA specific hostname
IP192.168.1.1A single IP address
CIDR10.0.0.0/24An IP address range
iOS Appcom.example.appAn iOS application bundle identifier
Android Appcom.example.appAn Android application package name
Source Codegithub.com/org/repoA source code repository

Credentials and Context ​

Beyond target definitions, the scope section supports additional context:

  • Credentials: test accounts, API keys, and authentication material needed for grey-box and white-box assessments
  • Context: markdown-formatted notes describing the target environment, architecture, technology stack, and testing guidelines

TIP

Adding detailed context helps AI assessments and team members understand the environment without separate onboarding.

Importing Scope ​

Scope entries can be imported in bulk. This is useful when onboarding a large engagement or syncing scope from a bug bounty platform.

Scope and Asset Discovery ​

Scope entries serve as seeds for asset discovery:

  1. Wildcard entries trigger subdomain enumeration to discover hosts
  2. Domain entries are probed directly for HTTP responses, technologies, and services
  3. IP and CIDR entries are scanned for open ports and running services

Assets discovered through enumeration are validated against the scope. Only in-scope assets are tracked and tested. Out-of-scope matches are flagged and excluded from automated scanning.

Hashiro. Continuous Threat Exposure Management.