Discovery runs rules that look for assets related to yours and puts what they find in the Discovery review list. Deepinfo manages the smart rules, and you can tune them: turn them on or off, tell them what not to start from, and let them approve what they find. You can also keep assets out of discovery altogether.

Before You Start

  • Package: External Attack Surface Management (EASM).
  • Role: Admin or Member.
  • These settings apply to discovery for your whole organization. To turn discovery on or off for a single asset, see Tag, weight and configure assets.

Where to Find It

Sidebar: EXTERNAL ATTACK SURFACE MANAGEMENT › ASSETS › DISCOVERY · Tab: SETTINGS · https://platform.deepinfo.com/app/easm/discoveries/settings/smart-discovery

The SETTINGS tab has its own menu on the left:

Concepts

  • Smart discovery rules and smart monitoring rules are run and maintained by Deepinfo. Both put the assets they find in the Discovery review list. In that list, a bulb icon on a rule badge marks a smart rule.
  • Seed asset: one of your assets that a rule starts from. An asset is used as a seed when discovery is enabled for it.
  • Seed value: the input a rule started from when it found an asset. On the Discovery list, hover over a rule badge to see it.
  • Auto approval: assets that a rule finds go straight into your inventory, without waiting for your review.

Read the Smart Discovery Page

Smart Discovery on the SMART DISCOVERY RULES tab with the tabs, the rules table and one expanded rule, numbered 1 to 3.

  1. Tabs: SMART DISCOVERY RULES and SMART MONITORING RULES.

  2. The rules table:

    Column What it shows
    STATUS A switch, and ACTIVE when the rule runs
    RULE NAME The rule
    DISCOVERED ASSETS How many assets the rule has discovered
    (chevron) Expands the rule's settings
  3. An expanded rule shows its excluded seed assets and seed values, Auto Approval and Global Blacklist, described below.

When this page was written, the smart rules were:

Smart discovery rules Smart monitoring rules
Same Whois Registrant Phone Rule DNS A Records Smart Rule
Same DNS A Record (IP Address) Rule SSL Certificate SANs Smart Rule
Same Whois Registrant Organization Rule HTTP Redirection Follow Smart Rule
Subdomain Rule DNS CNAME Record Smart Rule
Same SSL Certificate Rule IP CIDR Smart Monitoring Rule
Same DNS MX Record (Mail Server) Rule IP DNS PTR Record Smart Rule
Same DNS NS Record (Name Server) Rule
Same SSL Subject Organization Rule
Same Whois Name Server Rule
Same Whois Registrant Email Rule
Same Whois Registrant Apex Email Rule
Same Whois Registrant Email (Historical) Rule

Deepinfo maintains these rules, so your list can differ.

Change a Rule's Status

  1. Select the rule's STATUS switch.
  2. A Confirmation asks whether you want to activate or inactivate the rule. Select ACTIVATE or INACTIVATE.

The STATUS column then shows whether the rule is ACTIVE or INACTIVE.

Exclude Seed Assets

If a rule finds unrelated assets because it starts from one of your assets, exclude that asset from the rule.

  1. Expand the rule. Its excluded seed assets are listed under EXCLUED SEED ASSETS (the label is spelled this way on screen).
  2. Select MANAGE EXCLUDED SEED ASSETS.
  3. In Manage Excluded Seed Assets, find the asset under YOUR ASSETS (use Search in your assets) and move it to EXCLUDED SEED ASSETS. YOUR ASSETS lists your whole inventory.
  4. Select SAVE CHANGES and confirm.

To take an asset off the list, select × on its chip under EXCLUED SEED ASSETS and confirm with REMOVE.

In this dialog, internationalized names appear in their punycode form (starting with xn--), not as they appear in Inventory.

The Manage Excluded Seed Assets dialog with the YOUR ASSETS list, the EXCLUDED SEED ASSETS list and SAVE CHANGES.

Exclude Seed Values

If a rule finds unrelated assets because of one seed value, exclude that value. Smart discovery rules have this setting; smart monitoring rules do not.

  1. Expand the rule and find EXCLUED SEED VALUES.
  2. Select + MANAGE EXCLUDED SEED VALUES.
  3. In Manage Excluded Seed Values, enter the values, one per line.
  4. Select SAVE CHANGES.

To find a seed value, hover over the rule's badge on an asset in the Discovery list.

Approve a Rule's Findings Automatically

  1. Expand the rule and select the Auto Approval switch. Its description explains that assets in the review list that match the rule are approved automatically.
  2. The Confirmation asks whether you want to enable auto approval for the rule. Select YES, or DISCARD to leave it off.

Turning it off works the same way.

Caution

Auto-approved assets go into your inventory without a review, and an approval cannot be undone from Discovery. To take such an asset out again, remove it; see Remove and restore assets. To find auto-approved assets, filter Inventory by ASSET META › Creation Method.

Use the Global Blacklist

Deepinfo's data team maintains a global list of generic values and keeps it up to date. With it, a rule ignores those values, which reduces false-positive discoveries.

  1. Expand the rule and select the Global Blacklist switch.
  2. Confirm with YES, or select DISCARD.

Keep Assets Out of Discovery for Good

The Ignored Assets list on Other Settings holds domains, subdomains and IP addresses that never appear in the discovered-asset lists, even when a rule finds them.

  1. In the SETTINGS tab menu, select Other Settings.
  2. Under Ignored Assets, enter the assets, one per line. Each line must be a domain, a subdomain or a public IPv4 address.
  3. Select SAVE CHANGES. It is available once you have changed the list.

Other Settings in the Discovery SETTINGS tab with the empty Ignored Assets field and SAVE CHANGES.

Good to Know

  • Rule switches, Auto Approval and Global Blacklist always ask for confirmation before they change.
  • SAVE CHANGES stays unavailable until you change something in its dialog or form.
  • To dismiss a single candidate rather than keep an asset out for good, you can also ignore it in the Discovery list; see Review discovered assets.

Do This With the API

Last updated